Amazon Linux

Amazon Linux 2 — nghttp2 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — nghttp2 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2026-3232 Related CVEs: CVE-2026-27135 CVE-2024-28182 CVE-2023-44487 CVE-2023-35945 CVE-2020-11080 CVE-2019-9511 CVE-2019-9513 CVE-2018-1000168 Upstream summary: nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, […]

Read more
Amazon Linux 2023 — ecs-service-connect-agent — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — ecs-service-connect-agent — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1532 Related CVEs: CVE-2026-26308 CVE-2026-26309 CVE-2026-26310 CVE-2026-26311 CVE-2026-26330 CVE-2024-11407 CVE-2024-25176 CVE-2024-25177  +12 more Upstream summary: Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy […]

Read more
Amazon Linux 2023 — golang — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — golang — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1593 Related CVEs: CVE-2026-27140 CVE-2026-27143 CVE-2026-27144 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 CVE-2026-32288  +12 more Upstream summary: SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary […]

Read more
Amazon Linux 2 — kernel-livepatch-4.14.355-275.572 — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-4.14.355-275.572 — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2025-224 Related CVEs: CVE-2024-47757 CVE-2024-49882 CVE-2024-50036 CVE-2024-50264 CVE-2025-21796 CVE-2024-53103 CVE-2025-21753 CVE-2024-49995  +1 more Upstream summary: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential oob read […]

Read more
Amazon Linux 2023 — openexr — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — openexr — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1612 Related CVEs: CVE-2026-34378 CVE-2026-34380 CVE-2026-34588 CVE-2026-27622 CVE-2025-12495 CVE-2025-12839 CVE-2026-34544 CVE-2024-31047  +4 more Upstream summary: OpenEXR provides the specification and reference implementation of the EXR file format, an image storage […]

Read more
Amazon Linux 2023 — openssh — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — openssh — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1604 Related CVEs: CVE-2026-35385 CVE-2024-6387 CVE-2024-6409 CVE-2016-10009 CVE-2023-38408 CVE-2025-26465 CVE-2023-51385 CVE-2023-48795  +3 more Upstream summary: In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, […]

Read more
Amazon Linux 2023 — kernel-livepatch-6.18.25-52.107 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — kernel-livepatch-6.18.25-52.107 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023LIVEPATCH-2026-135 Related CVEs: CVE-2026-43284 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags "Dirty Frag" and other issues […]

Read more
Amazon Linux 2023 — dotnet8.0 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — dotnet8.0 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2025-1230 Related CVEs: CVE-2025-55247 CVE-2025-55248 CVE-2025-55315 CVE-2026-26171 CVE-2026-32178 CVE-2026-32203 CVE-2026-33116 CVE-2026-26130  +12 more Upstream summary: Improper link resolution before file access ('link following') in .NET allows an authorized attacker to […]

Read more
Amazon Linux 2023 — amazon-ssm-agent — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — amazon-ssm-agent — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1499 Related CVEs: CVE-2025-61731 CVE-2025-68119 CVE-2025-22874 CVE-2025-4673 CVE-2025-47912 CVE-2025-58183 CVE-2025-58185 CVE-2025-58186  +12 more Upstream summary: cmd/go: bypass of flag sanitization can lead to arbitrary code execution (CVE-2025-61731) cmd/go: unexpected code […]

Read more
CHAT