Amazon Linux 2023 Security Advisory: ALAS2023-2026-3133
Advisory Released Date: 2026-09-29
Advisory Updated Date: 2026-09-29
Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) may allow other local users on the same host to read credentials written by certain CLI subcommands (aws codeartifact login, aws iam create-virtual-mfa-device, aws deploy register).
To remediate this issue, users should upgrade to AWS CLI 1.44.78 (v1) or 2.34.29 (v2) or later. (CVE-2026-13769)
Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint.
To remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later. (CVE-2026-18654)
Affected Packages:
awscli-2
Issue Correction:
Run dnf update awscli-2 --releasever 2023.12.20260928 or dnf update --advisory ALAS2023-2026-3133 --releasever 2023.12.20260928 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
noarch:
awscli-2-2.36.47-4.amzn2023.0.1.noarch
src:
awscli-2-2.36.47-4.amzn2023.0.1.src