ALAS2-2026-3933


Amazon Linux 2 (EOS) Security Advisory: ALAS2-2026-3933
Advisory Released Date: 2026-09-28
Advisory Updated Date: 2026-09-28
Severity: Important

Issue Overview:

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. (CVE-2026-42505)

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5. (CVE-2026-71556)

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue. (CVE-2026-71557)


Affected Packages:

amazon-ssm-agent


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update amazon-ssm-agent or yum update --advisory ALAS2-2026-3933 to update your system.

New Packages:
aarch64:
    amazon-ssm-agent-3.3.5226.0-1.amzn2.aarch64

src:
    amazon-ssm-agent-3.3.5226.0-1.amzn2.src

x86_64:
    amazon-ssm-agent-3.3.5226.0-1.amzn2.x86_64