Amazon Linux 2 Security Advisory: ALAS-2021-1595
Advisory Release Date: 2021-02-08 19:10 Pacific
Advisory Updated Date: 2021-02-19 22:07 Pacific
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'. (CVE-2019-0816)
Affected Packages:
cloud-init
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update cloud-init to update your system.
noarch:
cloud-init-19.3-2.amzn2.noarch
src:
cloud-init-19.3-2.amzn2.src