ALAS2-2025-2934


Amazon Linux 2 Security Advisory: ALAS2-2025-2934
Advisory Released Date: 2025-07-30
Advisory Updated Date: 2025-07-30
Severity: Medium

Issue Overview:

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources. (CVE-2025-52999)


Affected Packages:

jackson


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update jackson or yum update --advisory ALAS2-2025-2934 to update your system.

New Packages:
noarch:
    jackson-1.9.4-7.amzn2.0.1.noarch
    jackson-javadoc-1.9.4-7.amzn2.0.1.noarch

src:
    jackson-1.9.4-7.amzn2.0.1.src