Amazon Linux 2023 Security Advisory: ALAS2023-2023-044
Advisory Released Date: 2023-03-22
Advisory Updated Date: 2023-03-22
                            Severity:
                            
                                
                                    
                                
                            
                            Medium
                        
                        
                        
                            Issue Overview:
                            
                                
                        An out-of-bounds read/write vulnerability was found in e2fsprogs. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem. (CVE-2022-1304)
Affected Packages:
e2fsprogs
Issue Correction:
Run dnf update e2fsprogs --releasever 2023.0.20230322 or dnf update --advisory ALAS2023-2023-044 --releasever 2023.0.20230322 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
                            New Packages:
aarch64:
libcom_err-debuginfo-1.46.5-2.amzn2023.0.2.aarch64
e2fsprogs-libs-debuginfo-1.46.5-2.amzn2023.0.2.aarch64
libss-debuginfo-1.46.5-2.amzn2023.0.2.aarch64
e2fsprogs-static-1.46.5-2.amzn2023.0.2.aarch64
e2fsprogs-debuginfo-1.46.5-2.amzn2023.0.2.aarch64
libss-1.46.5-2.amzn2023.0.2.aarch64
e2fsprogs-libs-1.46.5-2.amzn2023.0.2.aarch64
libcom_err-devel-1.46.5-2.amzn2023.0.2.aarch64
e2fsprogs-devel-1.46.5-2.amzn2023.0.2.aarch64
e2fsprogs-debugsource-1.46.5-2.amzn2023.0.2.aarch64
e2scrub-1.46.5-2.amzn2023.0.2.aarch64
libss-devel-1.46.5-2.amzn2023.0.2.aarch64
e2fsprogs-1.46.5-2.amzn2023.0.2.aarch64
libcom_err-1.46.5-2.amzn2023.0.2.aarch64
src:
e2fsprogs-1.46.5-2.amzn2023.0.2.src
x86_64:
libss-1.46.5-2.amzn2023.0.2.x86_64
libcom_err-devel-1.46.5-2.amzn2023.0.2.x86_64
libss-debuginfo-1.46.5-2.amzn2023.0.2.x86_64
libss-devel-1.46.5-2.amzn2023.0.2.x86_64
libcom_err-1.46.5-2.amzn2023.0.2.x86_64
e2fsprogs-1.46.5-2.amzn2023.0.2.x86_64
e2fsprogs-static-1.46.5-2.amzn2023.0.2.x86_64
libcom_err-debuginfo-1.46.5-2.amzn2023.0.2.x86_64
e2scrub-1.46.5-2.amzn2023.0.2.x86_64
e2fsprogs-libs-debuginfo-1.46.5-2.amzn2023.0.2.x86_64
e2fsprogs-libs-1.46.5-2.amzn2023.0.2.x86_64
e2fsprogs-devel-1.46.5-2.amzn2023.0.2.x86_64
e2fsprogs-debugsource-1.46.5-2.amzn2023.0.2.x86_64
e2fsprogs-debuginfo-1.46.5-2.amzn2023.0.2.x86_64