Amazon Linux

Amazon Linux 2 — kernel-livepatch-4.14.327-246.539 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-4.14.327-246.539 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2024-162 Related CVEs: CVE-2023-6040 CVE-2023-6606 CVE-2023-6932 Upstream summary: An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a […]

Read more
Amazon Linux 2 — python38-setuptools — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — python38-setuptools — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2PYTHON3.8-2024-012 Related CVEs: CVE-2024-6345 CVE-2022-40897 Upstream summary: A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, […]

Read more
Amazon Linux 2023 — xmlunit — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — xmlunit — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2025-1260 Related CVEs: CVE-2024-31573 Upstream summary: XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT […]

Read more
Amazon Linux 2 — libglvnd — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — libglvnd — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-2782 Related CVEs: CVE-2023-45924 Upstream summary: libglxproto.c in OpenGL libglvnd bb06db5a was discovered to contain a segmentation violation via the function glXGetDrawableScreen(). NOTE: this is disputed because there are no […]

Read more
Amazon Linux 2023 — dbus — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — dbus — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2023-213 Related CVEs: CVE-2023-34969 CVE-2022-42010 CVE-2022-42011 CVE-2022-42012 Upstream summary: D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using […]

Read more
Amazon Linux 2 — kernel-livepatch-4.14.355-280.695 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-4.14.355-280.695 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2025-271 Related CVEs: CVE-2023-53530 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Use raw_smp_processor_id() instead of smp_processor_id() (CVE-2023-53530) Table of contents Symptom & Impact […]

Read more
Amazon Linux 2023 — socat — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — socat — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1701 Related CVEs: CVE-2024-54661 Upstream summary: readline.sh in socat through 1.8.0.1 relies on the /tmp/$USER/stderr2 file. (CVE-2024-54661) Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick […]

Read more
Amazon Linux 2023 — libmicrohttpd — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — libmicrohttpd — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2025-1133 Related CVEs: CVE-2023-27371 Upstream summary: GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.218-206.860 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.218-206.860 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2024-187 Related CVEs: CVE-2022-48666 CVE-2024-41090 CVE-2024-41091 CVE-2024-39480 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a use-after-free (CVE-2022-48666) kernel: virtio-net: tap: mlx5_core short […]

Read more
Amazon Linux 2023 — kernel-livepatch-6.1.55-75.123 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — kernel-livepatch-6.1.55-75.123 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023LIVEPATCH-2023-023 Related CVEs: CVE-2023-5090 CVE-2023-5197 CVE-2023-5717 Upstream summary: x86: KVM: SVM: always update the x2avic msr interception (CVE-2023-5090) A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be […]

Read more
CHAT