Amazon Linux 2 Security Advisory: ALAS2-2025-2934
Advisory Released Date: 2025-07-30
Advisory Updated Date: 2025-07-30
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources. (CVE-2025-52999)
Affected Packages:
jackson
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update jackson or yum update --advisory ALAS2-2025-2934 to update your system.
noarch:
jackson-1.9.4-7.amzn2.0.1.noarch
jackson-javadoc-1.9.4-7.amzn2.0.1.noarch
src:
jackson-1.9.4-7.amzn2.0.1.src