ALAS2-2026-3963


Amazon Linux 2 (EOS) Security Advisory: ALAS2-2026-3963
Advisory Released Date: 2026-10-01
Advisory Updated Date: 2026-10-01
Severity: Critical

Issue Overview:

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. (CVE-2026-42505)

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5. (CVE-2026-71556)

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue. (CVE-2026-71557)

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address.

To remediate this issue, users should upgrade to version 3.3.4851.0 or later. (CVE-2026-89049)


Affected Packages:

amazon-ssm-agent


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update amazon-ssm-agent or yum update --advisory ALAS2-2026-3963 to update your system.

New Packages:
aarch64:
    amazon-ssm-agent-3.3.5226.0-1.amzn2.aarch64

src:
    amazon-ssm-agent-3.3.5226.0-1.amzn2.src

x86_64:
    amazon-ssm-agent-3.3.5226.0-1.amzn2.x86_64