ALAS2-2025-2988


Amazon Linux 2 Security Advisory: ALAS2-2025-2988
Advisory Released Date: 2025-09-04
Advisory Updated Date: 2025-09-04
Severity: Important

Issue Overview:

In the Linux kernel, the following vulnerability has been resolved:

scsi: lpfc: Prevent buffer overflow crashes in debugfs with malformed user input (CVE-2022-50030)

In the Linux kernel, the following vulnerability has been resolved:

iavf: Fix adminq error handling (CVE-2022-50055)

In the Linux kernel, the following vulnerability has been resolved:

nfs: handle failure of nfs_get_lock_context in unlock path (CVE-2025-38023)

In the Linux kernel, the following vulnerability has been resolved:

calipso: Fix null-ptr-deref in calipso_req_{set,del}attr(). (CVE-2025-38181)

In the Linux kernel, the following vulnerability has been resolved:

ipc: fix to protect IPCS lookups using RCU (CVE-2025-38212)

In the Linux kernel, the following vulnerability has been resolved:

fbdev: Fix do_register_framebuffer to prevent null-ptr-deref in fb_videomode_to_var (CVE-2025-38215)

In the Linux kernel, the following vulnerability has been resolved:

posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() (CVE-2025-38352)


Affected Packages:

kernel


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update kernel or yum update --advisory ALAS2-2025-2988 to update your system.
System reboot is required in order to complete this update.

New Packages:
aarch64:
    kernel-4.14.355-280.679.amzn2.aarch64
    kernel-headers-4.14.355-280.679.amzn2.aarch64
    kernel-debuginfo-common-aarch64-4.14.355-280.679.amzn2.aarch64
    perf-4.14.355-280.679.amzn2.aarch64
    perf-debuginfo-4.14.355-280.679.amzn2.aarch64
    python-perf-4.14.355-280.679.amzn2.aarch64
    python-perf-debuginfo-4.14.355-280.679.amzn2.aarch64
    kernel-tools-4.14.355-280.679.amzn2.aarch64
    kernel-tools-devel-4.14.355-280.679.amzn2.aarch64
    kernel-tools-debuginfo-4.14.355-280.679.amzn2.aarch64
    kernel-devel-4.14.355-280.679.amzn2.aarch64
    kernel-debuginfo-4.14.355-280.679.amzn2.aarch64

i686:
    kernel-headers-4.14.355-280.679.amzn2.i686

src:
    kernel-4.14.355-280.679.amzn2.src

x86_64:
    kernel-4.14.355-280.679.amzn2.x86_64
    kernel-headers-4.14.355-280.679.amzn2.x86_64
    kernel-debuginfo-common-x86_64-4.14.355-280.679.amzn2.x86_64
    perf-4.14.355-280.679.amzn2.x86_64
    perf-debuginfo-4.14.355-280.679.amzn2.x86_64
    python-perf-4.14.355-280.679.amzn2.x86_64
    python-perf-debuginfo-4.14.355-280.679.amzn2.x86_64
    kernel-tools-4.14.355-280.679.amzn2.x86_64
    kernel-tools-devel-4.14.355-280.679.amzn2.x86_64
    kernel-tools-debuginfo-4.14.355-280.679.amzn2.x86_64
    kernel-devel-4.14.355-280.679.amzn2.x86_64
    kernel-debuginfo-4.14.355-280.679.amzn2.x86_64
    kernel-livepatch-4.14.355-280.679-1.0-0.amzn2.x86_64