ALAS2023-2026-2024


Amazon Linux 2023 Security Advisory: ALAS2023-2026-2024
Advisory Released Date: 2026-08-04
Advisory Updated Date: 2026-08-04
Severity: Important

Issue Overview:

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution. (CVE-2026-40034)


Affected Packages:

rust-cargo-c


Issue Correction:
Run dnf update rust-cargo-c --releasever 2023.12.20260803 or dnf update --advisory ALAS2023-2026-2024 --releasever 2023.12.20260803 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    cargo-c-debuginfo-0.10.19-1.amzn2023.0.4.aarch64
    cargo-c-0.10.19-1.amzn2023.0.4.aarch64
    rust-cargo-c-debugsource-0.10.19-1.amzn2023.0.4.aarch64

src:
    rust-cargo-c-0.10.19-1.amzn2023.0.4.src

x86_64:
    cargo-c-debuginfo-0.10.19-1.amzn2023.0.4.x86_64
    cargo-c-0.10.19-1.amzn2023.0.4.x86_64
    rust-cargo-c-debugsource-0.10.19-1.amzn2023.0.4.x86_64