Amazon Linux 2 Security Advisory: ALAS-2023-2357
Advisory Release Date: 2023-11-29 22:19 Pacific
Advisory Updated Date: 2023-12-04 21:44 Pacific
A heap out-of-bounds read flaw was found in builtin.c in the gawk package which may result in a crash of the software. (CVE-2023-4156)
Affected Packages:
gawk
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update gawk to update your system.
aarch64:
gawk-4.0.2-4.amzn2.1.3.aarch64
gawk-debuginfo-4.0.2-4.amzn2.1.3.aarch64
i686:
gawk-4.0.2-4.amzn2.1.3.i686
gawk-debuginfo-4.0.2-4.amzn2.1.3.i686
src:
gawk-4.0.2-4.amzn2.1.3.src
x86_64:
gawk-4.0.2-4.amzn2.1.3.x86_64
gawk-debuginfo-4.0.2-4.amzn2.1.3.x86_64