Amazon Linux 2023 — cpio — multiple vulnerabilities (2 CVEs) — patch and remediation guide
🟠 High ⏱ 15–60 min Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read • Source: Amazon Linux advisory ALAS2023-2024-557 Related CVEs: CVE-2015-1197 CVE-2021-38185 Upstream summary: cpio 2.11, when using the –no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in […]