Amazon Linux 2023 Security Advisory: ALAS2023-2026-2024
Advisory Released Date: 2026-08-04
Advisory Updated Date: 2026-08-04
Severity:
Important
Issue Overview:
gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution. (CVE-2026-40034)
Affected Packages:
rust-cargo-c
Issue Correction:
Run dnf update rust-cargo-c --releasever 2023.12.20260803 or dnf update --advisory ALAS2023-2026-2024 --releasever 2023.12.20260803 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
New Packages:
aarch64:
cargo-c-debuginfo-0.10.19-1.amzn2023.0.4.aarch64
cargo-c-0.10.19-1.amzn2023.0.4.aarch64
rust-cargo-c-debugsource-0.10.19-1.amzn2023.0.4.aarch64
src:
rust-cargo-c-0.10.19-1.amzn2023.0.4.src
x86_64:
cargo-c-debuginfo-0.10.19-1.amzn2023.0.4.x86_64
cargo-c-0.10.19-1.amzn2023.0.4.x86_64
rust-cargo-c-debugsource-0.10.19-1.amzn2023.0.4.x86_64