Amazon Linux 2 Security Advisory: ALAS2-2026-3834
Advisory Released Date: 2026-08-04
Advisory Updated Date: 2026-08-04
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4. (CVE-2026-54572)
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4. (CVE-2026-59733)
Affected Packages:
rclone
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update rclone or yum update --advisory ALAS2-2026-3834 to update your system.
aarch64:
rclone-1.55.1-1.amzn2.0.10.aarch64
rclone-debuginfo-1.55.1-1.amzn2.0.10.aarch64
src:
rclone-1.55.1-1.amzn2.0.10.src
x86_64:
rclone-1.55.1-1.amzn2.0.10.x86_64
rclone-debuginfo-1.55.1-1.amzn2.0.10.x86_64