ALAS2-2026-3179


Amazon Linux 2 Security Advisory: ALAS2-2026-3179
Advisory Released Date: 2026-03-06
Advisory Updated Date: 2026-03-06
Severity: Medium

Issue Overview:

The Evolution backend server exposes the D-Bus service org.gnome.evolution.dataserver.AddressBook, that can be used in order to manage contacts. A Flatpak application with access to this D-Bus service can exploit this issue in order to gain arbitrary file deletion on the host filesystem. (CVE-2026-2604)


Affected Packages:

evolution-data-server


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update evolution-data-server or yum update --advisory ALAS2-2026-3179 to update your system.

New Packages:
aarch64:
    evolution-data-server-3.28.5-4.amzn2.0.2.aarch64
    evolution-data-server-devel-3.28.5-4.amzn2.0.2.aarch64
    evolution-data-server-perl-3.28.5-4.amzn2.0.2.aarch64
    evolution-data-server-tests-3.28.5-4.amzn2.0.2.aarch64
    evolution-data-server-debuginfo-3.28.5-4.amzn2.0.2.aarch64

i686:
    evolution-data-server-3.28.5-4.amzn2.0.2.i686
    evolution-data-server-devel-3.28.5-4.amzn2.0.2.i686
    evolution-data-server-perl-3.28.5-4.amzn2.0.2.i686
    evolution-data-server-tests-3.28.5-4.amzn2.0.2.i686
    evolution-data-server-debuginfo-3.28.5-4.amzn2.0.2.i686

noarch:
    evolution-data-server-langpacks-3.28.5-4.amzn2.0.2.noarch
    evolution-data-server-doc-3.28.5-4.amzn2.0.2.noarch

src:
    evolution-data-server-3.28.5-4.amzn2.0.2.src

x86_64:
    evolution-data-server-3.28.5-4.amzn2.0.2.x86_64
    evolution-data-server-devel-3.28.5-4.amzn2.0.2.x86_64
    evolution-data-server-perl-3.28.5-4.amzn2.0.2.x86_64
    evolution-data-server-tests-3.28.5-4.amzn2.0.2.x86_64
    evolution-data-server-debuginfo-3.28.5-4.amzn2.0.2.x86_64