ALAS2-2026-3834


Amazon Linux 2 Security Advisory: ALAS2-2026-3834
Advisory Released Date: 2026-08-04
Advisory Updated Date: 2026-08-04
Severity: Important

Issue Overview:

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4. (CVE-2026-54572)

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4. (CVE-2026-59733)


Affected Packages:

rclone


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update rclone or yum update --advisory ALAS2-2026-3834 to update your system.

New Packages:
aarch64:
    rclone-1.55.1-1.amzn2.0.10.aarch64
    rclone-debuginfo-1.55.1-1.amzn2.0.10.aarch64

src:
    rclone-1.55.1-1.amzn2.0.10.src

x86_64:
    rclone-1.55.1-1.amzn2.0.10.x86_64
    rclone-debuginfo-1.55.1-1.amzn2.0.10.x86_64