ALAS2-2021-1595


Amazon Linux 2 Security Advisory: ALAS-2021-1595
Advisory Release Date: 2021-02-08 19:10 Pacific
Advisory Updated Date: 2021-02-19 22:07 Pacific
Severity: Medium

Issue Overview:

A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'. (CVE-2019-0816)


Affected Packages:

cloud-init


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update cloud-init to update your system.

New Packages:
noarch:
    cloud-init-19.3-2.amzn2.noarch

src:
    cloud-init-19.3-2.amzn2.src