Amazon Linux 2 Security Advisory: ALAS2-2026-3179
Advisory Released Date: 2026-03-06
Advisory Updated Date: 2026-03-06
The Evolution backend server exposes the D-Bus service org.gnome.evolution.dataserver.AddressBook, that can be used in order to manage contacts. A Flatpak application with access to this D-Bus service can exploit this issue in order to gain arbitrary file deletion on the host filesystem. (CVE-2026-2604)
Affected Packages:
evolution-data-server
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update evolution-data-server or yum update --advisory ALAS2-2026-3179 to update your system.
aarch64:
evolution-data-server-3.28.5-4.amzn2.0.2.aarch64
evolution-data-server-devel-3.28.5-4.amzn2.0.2.aarch64
evolution-data-server-perl-3.28.5-4.amzn2.0.2.aarch64
evolution-data-server-tests-3.28.5-4.amzn2.0.2.aarch64
evolution-data-server-debuginfo-3.28.5-4.amzn2.0.2.aarch64
i686:
evolution-data-server-3.28.5-4.amzn2.0.2.i686
evolution-data-server-devel-3.28.5-4.amzn2.0.2.i686
evolution-data-server-perl-3.28.5-4.amzn2.0.2.i686
evolution-data-server-tests-3.28.5-4.amzn2.0.2.i686
evolution-data-server-debuginfo-3.28.5-4.amzn2.0.2.i686
noarch:
evolution-data-server-langpacks-3.28.5-4.amzn2.0.2.noarch
evolution-data-server-doc-3.28.5-4.amzn2.0.2.noarch
src:
evolution-data-server-3.28.5-4.amzn2.0.2.src
x86_64:
evolution-data-server-3.28.5-4.amzn2.0.2.x86_64
evolution-data-server-devel-3.28.5-4.amzn2.0.2.x86_64
evolution-data-server-perl-3.28.5-4.amzn2.0.2.x86_64
evolution-data-server-tests-3.28.5-4.amzn2.0.2.x86_64
evolution-data-server-debuginfo-3.28.5-4.amzn2.0.2.x86_64