Amazon Linux 2023 Security Advisory: ALAS2023-2026-3110
Advisory Released Date: 2026-09-29
Advisory Updated Date: 2026-09-29
FAQs regarding Amazon Linux ALAS/CVE Severity
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. (CVE-2026-42505)
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5. (CVE-2026-71556)
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue. (CVE-2026-71557)
Affected Packages:
amazon-ssm-agent
Issue Correction:
Run dnf update amazon-ssm-agent --releasever 2023.12.20260928 or dnf update --advisory ALAS2023-2026-3110 --releasever 2023.12.20260928 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
amazon-ssm-agent-3.3.5226.0-1.amzn2023.aarch64
src:
amazon-ssm-agent-3.3.5226.0-1.amzn2023.src
x86_64:
amazon-ssm-agent-3.3.5226.0-1.amzn2023.x86_64