ALAS2ECS-2026-138


Amazon Linux 2 (EOS) Security Advisory: ALAS2ECS-2026-138
Advisory Released Date: 2026-09-28
Advisory Updated Date: 2026-09-28
Severity: Medium

Issue Overview:

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root. (CVE-2026-39822)

When setting up the container rootfs, setupPtmx and setupDevSymlinks call os.Remove and os.Symlink with a filepath.Join string which allow an image with /dev as a symlink to trick runc into deleting files called ptmx on the host or creating a hardcoded set of symlinks with specific names and targets in an arbitrary pre-existing host directory. (from https://github.com/opencontainers/runc/security/advisories/GHSA-xjvp-4fhw-gc47) (CVE-2026-41579)

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. (CVE-2026-42505)


Affected Packages:

runc


Note:

This advisory is applicable to Amazon Linux 2 - Ecs Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update runc or yum update --advisory ALAS2ECS-2026-138 to update your system.

New Packages:
aarch64:
    runc-1.3.6-1.amzn2.aarch64
    runc-debuginfo-1.3.6-1.amzn2.aarch64

src:
    runc-1.3.6-1.amzn2.src

x86_64:
    runc-1.3.6-1.amzn2.x86_64
    runc-debuginfo-1.3.6-1.amzn2.x86_64