ALAS2023-2026-3139


Amazon Linux 2023 Security Advisory: ALAS2023-2026-3139
Advisory Released Date: 2026-09-29
Advisory Updated Date: 2026-09-29
Severity: Important
References: CVE-2026-68082  CVE-2026-68159  CVE-2026-74483  CVE-2026-74517  CVE-2026-74582  CVE-2026-74583  CVE-2026-74586  CVE-2026-74587  CVE-2026-74588  CVE-2026-74589  CVE-2026-74591  CVE-2026-74592  CVE-2026-74593  CVE-2026-74594  CVE-2026-74595  CVE-2026-74597  CVE-2026-74598  CVE-2026-74601  CVE-2026-74602  CVE-2026-74606  CVE-2026-74608  CVE-2026-74609  CVE-2026-74610  CVE-2026-74611  CVE-2026-74612  CVE-2026-74613  CVE-2026-74614  CVE-2026-74615  CVE-2026-74616  CVE-2026-74618  CVE-2026-74619  CVE-2026-74620  CVE-2026-74624  CVE-2026-74627  CVE-2026-74630  CVE-2026-74632  CVE-2026-74633  CVE-2026-74634  CVE-2026-74635  CVE-2026-74636  CVE-2026-74637  CVE-2026-74644  CVE-2026-74652  CVE-2026-74653  CVE-2026-74654  CVE-2026-74656  CVE-2026-74657  CVE-2026-74658  CVE-2026-74660  CVE-2026-74662  CVE-2026-74663  CVE-2026-74664  CVE-2026-74665  CVE-2026-74666  CVE-2026-74667  CVE-2026-74668  CVE-2026-74669  CVE-2026-74670  CVE-2026-74671  CVE-2026-74672  CVE-2026-74673  CVE-2026-74675  CVE-2026-74676  CVE-2026-74683  CVE-2026-74684  CVE-2026-74688  CVE-2026-74695  CVE-2026-74696  CVE-2026-74698  CVE-2026-74700  CVE-2026-74701  CVE-2026-74704  CVE-2026-74705  CVE-2026-74707  CVE-2026-74708  CVE-2026-74709  CVE-2026-74710  CVE-2026-74714  CVE-2026-74717  CVE-2026-74718  CVE-2026-74720  CVE-2026-74722  CVE-2026-74724  CVE-2026-74726  CVE-2026-74728  CVE-2026-74730  CVE-2026-74736  CVE-2026-74739  CVE-2026-74740  CVE-2026-74742  CVE-2026-74743  CVE-2026-74744  CVE-2026-74746  CVE-2026-74748  CVE-2026-74753  CVE-2026-80527  CVE-2026-80528  CVE-2026-80529  CVE-2026-80530  CVE-2026-80534  CVE-2026-80536  CVE-2026-80557  CVE-2026-80558  CVE-2026-80561  CVE-2026-80572  CVE-2026-80574  CVE-2026-80578  CVE-2026-80585  CVE-2026-80586  CVE-2026-80587  CVE-2026-80588  CVE-2026-80589  CVE-2026-80590  CVE-2026-80724  CVE-2026-80725  CVE-2026-80726  CVE-2026-80727  CVE-2026-80731  CVE-2026-80733  CVE-2026-80737  CVE-2026-80739  CVE-2026-80742  CVE-2026-80744  CVE-2026-80756  CVE-2026-80757  CVE-2026-80758  CVE-2026-80765  CVE-2026-80775  CVE-2026-80776  CVE-2026-80777  CVE-2026-80778  CVE-2026-80781  CVE-2026-80784  CVE-2026-80792  CVE-2026-80793  CVE-2026-80805  CVE-2026-80806  CVE-2026-80808  CVE-2026-80810  CVE-2026-80811  CVE-2026-80818  CVE-2026-80904  CVE-2026-80905  CVE-2026-80906  CVE-2026-80912  CVE-2026-80913  CVE-2026-80917  CVE-2026-80918 
FAQs regarding Amazon Linux ALAS/CVE Severity

Issue Overview:

In the Linux kernel, the following vulnerability has been resolved:

libceph: fix two unsafe bare decodes in decode_lockers() (CVE-2026-68082)

In the Linux kernel, the following vulnerability has been resolved:

libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (CVE-2026-68159)

In the Linux kernel, the following vulnerability has been resolved:

binfmt_misc: don't leak the user namespace when the mount fails (CVE-2026-74483)

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs (CVE-2026-74517)

In the Linux kernel, the following vulnerability has been resolved:

packet: use consistent hard_header_len in non-ring send paths (CVE-2026-74582)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_route: fix fastmap use-after-free on filter (CVE-2026-74583)

In the Linux kernel, the following vulnerability has been resolved:

sctp: clear new_transport when removing a peer (CVE-2026-74586)

In the Linux kernel, the following vulnerability has been resolved:

sctp: fix use-after-free of cached ASCONF chunk (CVE-2026-74587)

In the Linux kernel, the following vulnerability has been resolved:

sctp: keep chunk->transport in step with the list it is queued on (CVE-2026-74588)

In the Linux kernel, the following vulnerability has been resolved:

bpf, sockmap: Fix sk_redir use-after-free in send verdict (CVE-2026-74589)

In the Linux kernel, the following vulnerability has been resolved:

mm/filemap: __filemap_add_folio() restore index before retrying (CVE-2026-74591)

In the Linux kernel, the following vulnerability has been resolved:

ima: Instantiate file_truncate and path_truncate hooks (CVE-2026-74592)

In the Linux kernel, the following vulnerability has been resolved:

sched_ext: Take cgroup_lock() first in scx_cgroup_lock() (CVE-2026-74593)

In the Linux kernel, the following vulnerability has been resolved:

sched/psi: Shut down rtpoll_timer in psi_cgroup_free() (CVE-2026-74594)

In the Linux kernel, the following vulnerability has been resolved:

fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() (CVE-2026-74595)

In the Linux kernel, the following vulnerability has been resolved:

ip6_tunnel: clear skb2->cb[] in ip6ip6_err() (CVE-2026-74597)

In the Linux kernel, the following vulnerability has been resolved:

ipv6: fix Route Information option length validation (CVE-2026-74598)

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Use current_context for safe per-CPU buffer swap (CVE-2026-74601)

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer() (CVE-2026-74602)

In the Linux kernel, the following vulnerability has been resolved:

eventfs: Fix use-after-free in eventfs_remove_rec() (CVE-2026-74606)

In the Linux kernel, the following vulnerability has been resolved:

smb: client: Fix use-after-free in cifs_try_adding_channels() (CVE-2026-74608)

In the Linux kernel, the following vulnerability has been resolved:

tipc: read le->link under the node lock in tipc_node_link_down() (CVE-2026-74609)

In the Linux kernel, the following vulnerability has been resolved:

tls: don't leave a full plaintext sk_msg ring unpushed (CVE-2026-74610)

In the Linux kernel, the following vulnerability has been resolved:

tls: rx: restore msg_iter before TLS 1.3 optimistic retry (CVE-2026-74611)

In the Linux kernel, the following vulnerability has been resolved:

veth: fix skb length accounting after XDP frag adjustment (CVE-2026-74612)

In the Linux kernel, the following vulnerability has been resolved:

vsock/virtio: avoid refilling the RX queue after teardown (CVE-2026-74613)

In the Linux kernel, the following vulnerability has been resolved:

vsock/virtio: read virtqueues under worker locks (CVE-2026-74614)

In the Linux kernel, the following vulnerability has been resolved:

vxlan: do not arm the ageing timer on a device that is down (CVE-2026-74615)

In the Linux kernel, the following vulnerability has been resolved:

xdp: reject clones that overrun skb_shared_info tailroom (CVE-2026-74616)

In the Linux kernel, the following vulnerability has been resolved:

binfmt_misc: don't warn when the mount is completed from another user namespace (CVE-2026-74618)

In the Linux kernel, the following vulnerability has been resolved:

ovl: don't warn when the mount is completed from another user namespace (CVE-2026-74619)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_gact, act_police: range check the fallback control action (CVE-2026-74620)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_conntrack: defer invalid log until after unlock (CVE-2026-74624)

In the Linux kernel, the following vulnerability has been resolved:

net: devmem: prevent net-iov / page mixing (CVE-2026-74627)

In the Linux kernel, the following vulnerability has been resolved:

ipv6: prevent in6_dev_get() from resurrecting inet6_dev (CVE-2026-74630)

In the Linux kernel, the following vulnerability has been resolved:

mm/huge_memory: fix huge_zero_pfn race (CVE-2026-74632)

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix NULL pointer dereference in module event cache removal (CVE-2026-74633)

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Prevent subbuf order change when resizing is disabled (CVE-2026-74634)

In the Linux kernel, the following vulnerability has been resolved:

fbdev: bitblit: bound-check glyph index in bit_cursor() (CVE-2026-74635)

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix race between update_event_fields and, event_define_fields (CVE-2026-74636)

In the Linux kernel, the following vulnerability has been resolved:

perf/core: Fix group leader use-after-free after sibling detach (CVE-2026-74637)

In the Linux kernel, the following vulnerability has been resolved:

mm/damon/ops-common: putback folios on invalid migrate nid (CVE-2026-74644)

In the Linux kernel, the following vulnerability has been resolved:

serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ (CVE-2026-74652)

In the Linux kernel, the following vulnerability has been resolved:

serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx (CVE-2026-74653)

In the Linux kernel, the following vulnerability has been resolved:

serial: 8250_dma: Clear stale RX state on shutdown (CVE-2026-74654)

In the Linux kernel, the following vulnerability has been resolved:

ipv4: fix use-after-free in fib_nhc_update_mtu() (CVE-2026-74656)

In the Linux kernel, the following vulnerability has been resolved:

ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops (CVE-2026-74657)

In the Linux kernel, the following vulnerability has been resolved:

futex: Prevent robust futex exit race some more (CVE-2026-74658)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ebt_nflog: pin the NFLOG backend (CVE-2026-74660)

In the Linux kernel, the following vulnerability has been resolved:

inet: frags: publish queues before arming timer (CVE-2026-74662)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: reject overly deep qdisc hierarchies (CVE-2026-74663)

In the Linux kernel, the following vulnerability has been resolved:

net: openvswitch: reallocate update replies for mismatched IDs (CVE-2026-74664)

In the Linux kernel, the following vulnerability has been resolved:

net: fix skb length accounting after generic XDP frag adjustment (CVE-2026-74665)

In the Linux kernel, the following vulnerability has been resolved:

packet: synchronize pressure clearing with ring reconfiguration (CVE-2026-74666)

In the Linux kernel, the following vulnerability has been resolved:

net/packet: reset the MAC header on the packet-socket transmit path (CVE-2026-74667)

In the Linux kernel, the following vulnerability has been resolved:

packet: use consistent hard_header_len in TX_RING send path (CVE-2026-74668)

In the Linux kernel, the following vulnerability has been resolved:

ipvs: clear IPv4 options after rebasing tunnel ICMP errors (CVE-2026-74669)

In the Linux kernel, the following vulnerability has been resolved:

ipvs: stop estimator after disabled calc phase (CVE-2026-74670)

In the Linux kernel, the following vulnerability has been resolved:

ima: fix out-of-bounds read in xattr_verify() (CVE-2026-74671)

In the Linux kernel, the following vulnerability has been resolved:

mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF (CVE-2026-74672)

In the Linux kernel, the following vulnerability has been resolved:

Input: evdev - fix information leak in evdev_pass_values() (CVE-2026-74673)

In the Linux kernel, the following vulnerability has been resolved:

vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (CVE-2026-74675)

In the Linux kernel, the following vulnerability has been resolved:

vt: add permission check for KDSKBMETA ioctl (CVE-2026-74676)

In the Linux kernel, the following vulnerability has been resolved:

Input: evdev - sanitize event type index when fetching event masks (CVE-2026-74683)

In the Linux kernel, the following vulnerability has been resolved:

net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (CVE-2026-74684)

In the Linux kernel, the following vulnerability has been resolved:

sctp: clear control chunk transport if it is being removed (CVE-2026-74688)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (CVE-2026-74695)

In the Linux kernel, the following vulnerability has been resolved:

tcp: fix TFO max_qlen accounting across reuseport migration (CVE-2026-74696)

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: fix BQL reset on SQ re-activation (CVE-2026-74698)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers (CVE-2026-74700)

In the Linux kernel, the following vulnerability has been resolved:

net/openvswitch: check Ethernet header length in key_extract() (CVE-2026-74701)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter (CVE-2026-74704)

In the Linux kernel, the following vulnerability has been resolved:

udp: fix potential use-after-free in tunnel segmentation (CVE-2026-74705)

In the Linux kernel, the following vulnerability has been resolved:

xsk: validate metadata when processing requests (CVE-2026-74707)

In the Linux kernel, the following vulnerability has been resolved:

xsk: validate launch-time metadata size (CVE-2026-74708)

In the Linux kernel, the following vulnerability has been resolved:

xsk: clear metadata pointer when no timestamp is requested (CVE-2026-74709)

In the Linux kernel, the following vulnerability has been resolved:

xsk: require at least 16 bytes of TX metadata (CVE-2026-74710)

In the Linux kernel, the following vulnerability has been resolved:

bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() (CVE-2026-74714)

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5: fw_tracer, return NULL on create error (CVE-2026-74717)

In the Linux kernel, the following vulnerability has been resolved:

devlink: fix net namespace reference leak in reload (CVE-2026-74718)

In the Linux kernel, the following vulnerability has been resolved:

bpf: Preserve pointer state for commuted arithmetic (CVE-2026-74720)

In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix memory leak in btrfs_do_encoded_write() (CVE-2026-74722)

In the Linux kernel, the following vulnerability has been resolved:

ipvs: avoid out-of-bounds write in ip_vs_nat_icmp (CVE-2026-74724)

In the Linux kernel, the following vulnerability has been resolved:

bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor (CVE-2026-74726)

In the Linux kernel, the following vulnerability has been resolved:

xfs: handle NULL b_addr in xfs_buf_free (CVE-2026-74728)

In the Linux kernel, the following vulnerability has been resolved:

NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (CVE-2026-74730)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_bpf: reject dev-bound programs bound to a different device (CVE-2026-74736)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_u32: skip hash tables in u32_bind_class() (CVE-2026-74739)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain (CVE-2026-74740)

In the Linux kernel, the following vulnerability has been resolved:

veth: fix queue index used to wake the peer txq in veth_poll (CVE-2026-74742)

In the Linux kernel, the following vulnerability has been resolved:

macvlan: inherit needed_headroom and needed_tailroom from lowerdev (CVE-2026-74743)

In the Linux kernel, the following vulnerability has been resolved:

ipvlan: inherit needed_headroom and needed_tailroom from phy_dev (CVE-2026-74744)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: publish GC-visible tuple last (CVE-2026-74746)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: fix refcount race between list:set GC and swap (CVE-2026-74748)

In the Linux kernel, the following vulnerability has been resolved:

perf: Reject exited events as group leaders (CVE-2026-74753)

In the Linux kernel, the following vulnerability has been resolved:

ceph: fix hanging __ceph_get_caps() with stale mds_wanted (CVE-2026-80527)

In the Linux kernel, the following vulnerability has been resolved:

ceph: avoid fs reclaim while using current->journal_info (CVE-2026-80528)

In the Linux kernel, the following vulnerability has been resolved:

xfs: don't swallow dquot recovery verification errors (CVE-2026-80529)

In the Linux kernel, the following vulnerability has been resolved:

xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN (CVE-2026-80530)

In the Linux kernel, the following vulnerability has been resolved:

xfs: fix ilock leak on error in xfs_dq_get_next_id (CVE-2026-80534)

In the Linux kernel, the following vulnerability has been resolved:

xfs: bounds-check buffer log item's dirty bitmap (CVE-2026-80536)

In the Linux kernel, the following vulnerability has been resolved:

libceph: fix OOB read in decode_watchers() via missing bounds check (CVE-2026-80557)

In the Linux kernel, the following vulnerability has been resolved:

libceph: Avoid using invalid osd indices from primary_temp (CVE-2026-80558)

In the Linux kernel, the following vulnerability has been resolved:

libceph: fix multiple unsafe decodes in decode_locker() (CVE-2026-80561)

In the Linux kernel, the following vulnerability has been resolved:

Input: byd - synchronize timer deletion before freeing private data (CVE-2026-80572)

In the Linux kernel, the following vulnerability has been resolved:

Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (CVE-2026-80574)

In the Linux kernel, the following vulnerability has been resolved:

fbdev: core: Fix pointer desynchronization in fb_io_read() (CVE-2026-80578)

In the Linux kernel, the following vulnerability has been resolved:

mptcp: fastopen: only mark MPTFO subflows with SYN data (CVE-2026-80585)

In the Linux kernel, the following vulnerability has been resolved:

mptcp: options: reset DSS fields in case of unexpected size (CVE-2026-80586)

In the Linux kernel, the following vulnerability has been resolved:

mptcp: avoid combining some incoming suboptions (CVE-2026-80587)

In the Linux kernel, the following vulnerability has been resolved:

mptcp: reclaim forward-allocated memory on RX path errors (CVE-2026-80588)

In the Linux kernel, the following vulnerability has been resolved:

block: stop the timeout timer when releasing a never added disk (CVE-2026-80589)

In the Linux kernel, the following vulnerability has been resolved:

inet: frags: strip GSO state from fragments before reassembly (CVE-2026-80590)

In the Linux kernel, the following vulnerability has been resolved:

ptp: vmclock: prevent read-only mappings from becoming writable (CVE-2026-80724)

In the Linux kernel, the following vulnerability has been resolved:

net: gro: properly validate BIG TCP aggregation criteria (CVE-2026-80725)

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (CVE-2026-80726)

In the Linux kernel, the following vulnerability has been resolved:

x86/mce: Set up the polling timer before CMCI discovery (CVE-2026-80727)

In the Linux kernel, the following vulnerability has been resolved:

net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (CVE-2026-80731)

In the Linux kernel, the following vulnerability has been resolved:

net: remove WARN_ON_ONCE() from sk_mc_loop() (CVE-2026-80733)

In the Linux kernel, the following vulnerability has been resolved:

serial: amba-pl011: synchronize DMA teardown (CVE-2026-80737)

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock (CVE-2026-80739)

In the Linux kernel, the following vulnerability has been resolved:

af_packet: Don't send zero-byte data in tpacket_snd(). (CVE-2026-80742)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path (CVE-2026-80744)

In the Linux kernel, the following vulnerability has been resolved:

selinux: do not cancel a policy conversion that never started (CVE-2026-80756)

In the Linux kernel, the following vulnerability has been resolved:

selinux: reject a class permission count below its inherited common (CVE-2026-80757)

In the Linux kernel, the following vulnerability has been resolved:

futex: Avoid private hash use-after-free on final put (CVE-2026-80758)

In the Linux kernel, the following vulnerability has been resolved:

HID: hyperv: validate initial device info bounds (CVE-2026-80765)

In the Linux kernel, the following vulnerability has been resolved:

futex: Fix race on the initial mm->futex.phash.ref allocation (CVE-2026-80775)

In the Linux kernel, the following vulnerability has been resolved:

futex: Fix race in futex_pivot_pending() during private hash resize (CVE-2026-80776)

In the Linux kernel, the following vulnerability has been resolved:

futex/pi: Plug private futex exec() race (CVE-2026-80777)

In the Linux kernel, the following vulnerability has been resolved:

futex/pi: Reject cross-mm private futex owners (CVE-2026-80778)

In the Linux kernel, the following vulnerability has been resolved:

HID: core: fix OOB read of field->usage in hid_set_field() (CVE-2026-80781)

In the Linux kernel, the following vulnerability has been resolved:

mptcp: pm: fix memory leak from alloc-during-teardown race (CVE-2026-80784)

In the Linux kernel, the following vulnerability has been resolved:

ipv6: fix use-after-free in ip6_finish_output2() (CVE-2026-80792)

In the Linux kernel, the following vulnerability has been resolved:

ipv4: reject undersized MTUs in ip_do_fragment() (CVE-2026-80793)

In the Linux kernel, the following vulnerability has been resolved:

xfs: validate attr entry pointer before field access (CVE-2026-80805)

In the Linux kernel, the following vulnerability has been resolved:

ext4: don't enable DAX on new encrypted files (CVE-2026-80806)

In the Linux kernel, the following vulnerability has been resolved:

ext4: stop retrying saturated xattr cache entries (CVE-2026-80808)

In the Linux kernel, the following vulnerability has been resolved:

io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec() (CVE-2026-80810)

In the Linux kernel, the following vulnerability has been resolved:

io_uring/cmd: fix iovec leak when the async cmd is not recycled (CVE-2026-80811)

In the Linux kernel, the following vulnerability has been resolved:

iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown (CVE-2026-80818)

In the Linux kernel, the following vulnerability has been resolved:

net/tls: Fail tls_sw_splice_read() after a failed async decrypt (CVE-2026-80904)

In the Linux kernel, the following vulnerability has been resolved:

net: tap: fix wrong transport_header when sending VLAN-tagged frame (CVE-2026-80905)

In the Linux kernel, the following vulnerability has been resolved:

net: packet: fix wrong transport_header when sending VLAN-tagged frame (CVE-2026-80906)

In the Linux kernel, the following vulnerability has been resolved:

selinux: reject an unclaimed class value in security_get_classes() (CVE-2026-80912)

In the Linux kernel, the following vulnerability has been resolved:

selinux: require every boolean value to be defined (CVE-2026-80913)

In the Linux kernel, the following vulnerability has been resolved:

PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems (CVE-2026-80917)

In the Linux kernel, the following vulnerability has been resolved:

HID: core: fix number/pointer type confusion on long items (CVE-2026-80918)


Affected Packages:

kernel6.18


Issue Correction:
Run dnf update kernel6.18 --releasever 2023.12.20260928 or dnf update --advisory ALAS2023-2026-3139 --releasever 2023.12.20260928 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    bpftool6.18-debuginfo-6.18.48-107.148.amzn2023.aarch64
    bpftool6.18-6.18.48-107.148.amzn2023.aarch64
    kernel6.18-modules-extra-6.18.48-107.148.amzn2023.aarch64
    kernel-livepatch-6.18.48-107.148-1.0-0.amzn2023.aarch64
    perf6.18-debuginfo-6.18.48-107.148.amzn2023.aarch64
    python3-perf6.18-debuginfo-6.18.48-107.148.amzn2023.aarch64
    kernel6.18-tools-debuginfo-6.18.48-107.148.amzn2023.aarch64
    microvm-kernel6.18-6.18.48-107.148.amzn2023.aarch64
    kernel6.18-modules-extra-common-6.18.48-107.148.amzn2023.aarch64
    python3-perf6.18-6.18.48-107.148.amzn2023.aarch64
    kernel6.18-tools-devel-6.18.48-107.148.amzn2023.aarch64
    kernel6.18-tools-6.18.48-107.148.amzn2023.aarch64
    kernel6.18-headers-6.18.48-107.148.amzn2023.aarch64
    perf6.18-6.18.48-107.148.amzn2023.aarch64
    kernel6.18-6.18.48-107.148.amzn2023.aarch64
    kernel6.18-debuginfo-6.18.48-107.148.amzn2023.aarch64
    kernel6.18-debuginfo-common-aarch64-6.18.48-107.148.amzn2023.aarch64
    kernel6.18-devel-6.18.48-107.148.amzn2023.aarch64

src:
    kernel6.18-6.18.48-107.148.amzn2023.src

x86_64:
    bpftool6.18-6.18.48-107.148.amzn2023.x86_64
    kernel6.18-headers-6.18.48-107.148.amzn2023.x86_64
    microvm-kernel6.18-6.18.48-107.148.amzn2023.x86_64
    kernel6.18-modules-extra-common-6.18.48-107.148.amzn2023.x86_64
    kernel6.18-modules-extra-6.18.48-107.148.amzn2023.x86_64
    bpftool6.18-debuginfo-6.18.48-107.148.amzn2023.x86_64
    python3-perf6.18-debuginfo-6.18.48-107.148.amzn2023.x86_64
    kernel-livepatch-6.18.48-107.148-1.0-0.amzn2023.x86_64
    perf6.18-debuginfo-6.18.48-107.148.amzn2023.x86_64
    kernel6.18-tools-devel-6.18.48-107.148.amzn2023.x86_64
    kernel6.18-tools-debuginfo-6.18.48-107.148.amzn2023.x86_64
    kernel6.18-debuginfo-6.18.48-107.148.amzn2023.x86_64
    kernel6.18-tools-6.18.48-107.148.amzn2023.x86_64
    python3-perf6.18-6.18.48-107.148.amzn2023.x86_64
    perf6.18-6.18.48-107.148.amzn2023.x86_64
    kernel6.18-6.18.48-107.148.amzn2023.x86_64
    kernel6.18-debuginfo-common-x86_64-6.18.48-107.148.amzn2023.x86_64
    kernel6.18-devel-6.18.48-107.148.amzn2023.x86_64