ALAS-2025-798


Amazon Linux 2023 Security Advisory: ALAS-2025-798
Advisory Release Date: 2025-01-06 19:21 Pacific
Advisory Updated Date: 2025-01-09 13:05 Pacific
Severity: Important

Issue Overview:

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization. (CVE-2022-42004)


Affected Packages:

jackson-databind


Issue Correction:
Run dnf update jackson-databind --releasever 2023.6.20250107 to update your system.

New Packages:
noarch:
    jackson-databind-2.11.4-6.amzn2023.0.3.noarch

src:
    jackson-databind-2.11.4-6.amzn2023.0.3.src