Amazon Linux

Amazon Linux 2 — libwebp12 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — libwebp12 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2023-2290 Related CVEs: CVE-2023-4863 Upstream summary: Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187 allowed a remote attacker to perform an out of bounds memory write via […]

Read more
Amazon Linux 2023 — rpm — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — rpm — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2024-573 Related CVEs: CVE-2017-7500 CVE-2017-7501 CVE-2021-35937 CVE-2021-35938 CVE-2021-35939 Upstream summary: A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks […]

Read more
Amazon Linux 2023 — kernel-livepatch-6.1.29-47.49 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — kernel-livepatch-6.1.29-47.49 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023LIVEPATCH-2023-017 Related CVEs: CVE-2023-2156 CVE-2023-3090 CVE-2023-35788 CVE-2022-48425 Upstream summary: A flaw was found in the Linux kernel's networking subsystem within the RPL protocol's handling. This issue results from the improper […]

Read more
Amazon Linux 2 — gtk2 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — gtk2 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2024-2603 Related CVEs: CVE-2024-6655 Upstream summary: gtk3: gtk2: Library injection from CWD (CVE-2024-6655) Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution […]

Read more
Amazon Linux 2 — c-ares — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — c-ares — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2023-2127 Related CVEs: CVE-2023-32067 CVE-2023-31147 CVE-2024-25629 CVE-2021-3672 CVE-2022-4904 CVE-2023-31130 CVE-2023-31124 Upstream summary: Denial of Service. An issue in c-ares was found where a 0-byte UDP payload can cause a Denial […]

Read more
Amazon Linux 2 — haproxy2 — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — haproxy2 — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2HAPROXY2-2023-001 Related CVEs: CVE-2022-0711 CVE-2023-25725 CVE-2018-20102 CVE-2023-0836 CVE-2020-11100 CVE-2023-45539 CVE-2023-0056 CVE-2021-39240  +4 more Upstream summary: A flaw was found in the way HAProxy processed HTTP responses containing the Set-Cookie2 header. […]

Read more
Amazon Linux 2023 — libuv — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — libuv — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2024-540 Related CVEs: CVE-2024-24806 Upstream summary: libuv is a multi-platform support library with a focus on asynchronous I/O. The `uv_getaddrinfo` function in `src/unix/getaddrinfo.c` (and its windows counterpart `src/win/getaddrinfo.c`), truncates hostnames […]

Read more
Amazon Linux 2 — gcc10 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — gcc10 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2023-2244 Related CVEs: CVE-2023-4039 CVE-2021-42574 Upstream summary: An issue was found in a defense in depth feature of the GCC compiler on aarch64 platforms. The stack protector feature (-fstack-protector) did […]

Read more
Amazon Linux 2023 — cuda-sandbox-devel-12-8 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — cuda-sandbox-devel-12-8 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023NVIDIA-2025-041 Related CVEs: CVE-2024-53870 CVE-2024-53871 CVE-2024-53875 Upstream summary: NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by […]

Read more
CHAT