Amazon Linux 2023 Security Advisory: ALAS2023-2025-1117
Advisory Released Date: 2025-08-08
Advisory Updated Date: 2025-08-08
Severity:
Important
Issue Overview:
In Jakarta Mail 2.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages. (CVE-2025-7962)
Affected Packages:
jakarta-mail
Issue Correction:
Run dnf update jakarta-mail --releasever 2023.8.20250808 or dnf update --advisory ALAS2023-2025-1117 --releasever 2023.8.20250808 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
New Packages:
noarch:
jakarta-mail-1.6.5-8.amzn2023.0.2.noarch
src:
jakarta-mail-1.6.5-8.amzn2023.0.2.src