ALAS2023-2026-3149


Amazon Linux 2023 Security Advisory: ALAS2023-2026-3149
Advisory Released Date: 2026-09-30
Advisory Updated Date: 2026-09-30
Severity: Critical

Issue Overview:

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. (CVE-2026-42505)

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5. (CVE-2026-71556)

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue. (CVE-2026-71557)

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address.

To remediate this issue, users should upgrade to version 3.3.4851.0 or later. (CVE-2026-89049)


Affected Packages:

amazon-ssm-agent


Issue Correction:
Run dnf update amazon-ssm-agent --releasever 2023.12.20260930 or dnf update --advisory ALAS2023-2026-3149 --releasever 2023.12.20260930 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    amazon-ssm-agent-3.3.5226.0-1.amzn2023.aarch64

src:
    amazon-ssm-agent-3.3.5226.0-1.amzn2023.src

x86_64:
    amazon-ssm-agent-3.3.5226.0-1.amzn2023.x86_64