Amazon Linux

Amazon Linux 2023 — kernel-livepatch-6.1.134-150.224 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — kernel-livepatch-6.1.134-150.224 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023LIVEPATCH-2025-057 Related CVEs: CVE-2025-38000 CVE-2025-38003 CVE-2025-21927 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() (CVE-2025-38000) In […]

Read more
Amazon Linux 2023 — gnupg2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — gnupg2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1427 Related CVEs: CVE-2026-24882 CVE-2025-68973 CVE-2022-34903 CVE-2025-30258 Upstream summary: In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and […]

Read more
Amazon Linux 2023 — gstreamer1-plugins-bad-free — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — gstreamer1-plugins-bad-free — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1521 Related CVEs: CVE-2026-2923 CVE-2026-3082 Upstream summary: Various out-of-bounds reads and writes in the DVB subtitle decoder that can cause crashes for certain input files. (CVE-2026-2923) GStreamer JPEG Parser Heap-based […]

Read more
Amazon Linux 2 — java-1.8.0-amazon-corretto — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — java-1.8.0-amazon-corretto — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2CORRETTO8-2021-001 Related CVEs: CVE-2021-44228 CVE-2021-45046 CVE-2026-22007 CVE-2026-22016 CVE-2026-21925 CVE-2026-21932 CVE-2026-21933 CVE-2026-21945  +12 more Upstream summary: No versions of an Amazon Linux Java Virtual Machine (JVM) are affected by CVE-2021-44228 or […]

Read more
Amazon Linux 2023 — cairo — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — cairo — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2025-1172 Related CVEs: CVE-2025-50422 Upstream summary: An issue was discovered in freedesktop poppler v25.04.0. The heap memory containing PDF stream objects is not cleared upon program exit, allowing attackers to […]

Read more
Amazon Linux 2023 — amazon-efs-utils — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — amazon-efs-utils — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1564 Related CVEs: CVE-2026-25727 CVE-2026-3336 CVE-2026-3337 CVE-2026-3338 CVE-2026-4428 CVE-2022-24713 CVE-2025-3416 CVE-2022-46174 Upstream summary: time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.252-250.1016 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.252-250.1016 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2026-291 Related CVEs: CVE-2026-43284 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags "Dirty Frag" and other issues […]

Read more
Amazon Linux 2023 — python3.14-pip — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — python3.14-pip — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1653 Related CVEs: CVE-2026-6357 Upstream summary: pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.245-245.983 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.245-245.983 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2026-284 Related CVEs: CVE-2025-68192 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup (CVE-2025-68192) Table of contents Symptom […]

Read more
Amazon Linux 2023 — jpegxl — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — jpegxl — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1459 Related CVEs: CVE-2025-12474 CVE-2026-1837 Upstream summary: A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the […]

Read more
CHAT