Amazon Linux

Amazon Linux 2023 — ngtcp2 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — ngtcp2 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1633 Related CVEs: CVE-2026-40170 Upstream summary: ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte […]

Read more
Amazon Linux 2023 — kernel6.18 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — kernel6.18 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1709 Related CVEs: CVE-2026-46300 CVE-2025-71239 CVE-2025-71265 CVE-2025-71266 CVE-2025-71267 CVE-2025-71295 CVE-2025-71298 CVE-2025-71301  +12 more Upstream summary: In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker […]

Read more
Amazon Linux 2 — apache-commons-vfs — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — apache-commons-vfs — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-2819 Related CVEs: CVE-2025-30474 CVE-2025-27553 Upstream summary: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file […]

Read more
Amazon Linux 2023 — perl-JSON-XS — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — perl-JSON-XS — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2025-1200 Related CVEs: CVE-2025-40928 Upstream summary: JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified […]

Read more
Amazon Linux 2023 — ecs-init — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — ecs-init — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1552 Related CVEs: CVE-2026-25679 CVE-2026-27139 CVE-2026-27142 CVE-2026-33186 CVE-2025-65637 CVE-2025-47912 CVE-2025-58183 CVE-2025-58185  +12 more Upstream summary: url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. (CVE-2026-25679) On Unix platforms, […]

Read more
Amazon Linux 2023 — perl-CryptX — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — perl-CryptX — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1641 Related CVEs: CVE-2026-41564 CVE-2023-36328 CVE-2025-40914 Upstream summary: NOTE: https://lists.security.metacpan.org/cve-announce/msg/39209500/ NOTE: https://github.com/DCIT/perl-CryptX/security/advisories/GHSA-24c2-gp6c-24c6 NOTE: Fixed by: https://github.com/DCIT/perl-CryptX/commit/9a1dd3e0c27d68e32450be5538b864c2b115ee15 (v0.088) (CVE-2026-41564) Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis […]

Read more
Amazon Linux 2023 — kernel-livepatch-6.12.83-111.159 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — kernel-livepatch-6.12.83-111.159 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023LIVEPATCH-2026-140 Related CVEs: CVE-2026-43284 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags "Dirty Frag" and other issues […]

Read more
Amazon Linux 2023 — soci-snapshotter — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — soci-snapshotter — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1573 Related CVEs: CVE-2026-25679 CVE-2026-27139 CVE-2026-27142 CVE-2026-33186 CVE-2025-47912 CVE-2025-58183 CVE-2025-58185 CVE-2025-58186  +12 more Upstream summary: url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. (CVE-2026-25679) On Unix platforms, […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.236-227.928 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.236-227.928 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2025-249 Related CVEs: CVE-2025-38037 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: vxlan: Annotate FDB data races (CVE-2025-38037) Table of contents Symptom & Impact Environment & […]

Read more
Amazon Linux 2 — python-pyasn1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — python-pyasn1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2026-3148 Related CVEs: CVE-2026-23490 CVE-2026-30922 Upstream summary: pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from […]

Read more
CHAT