ALAS2023-2026-3110


Amazon Linux 2023 Security Advisory: ALAS2023-2026-3110
Advisory Released Date: 2026-09-29
Advisory Updated Date: 2026-09-29
Severity: Important

Issue Overview:

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. (CVE-2026-42505)

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5. (CVE-2026-71556)

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue. (CVE-2026-71557)


Affected Packages:

amazon-ssm-agent


Issue Correction:
Run dnf update amazon-ssm-agent --releasever 2023.12.20260928 or dnf update --advisory ALAS2023-2026-3110 --releasever 2023.12.20260928 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    amazon-ssm-agent-3.3.5226.0-1.amzn2023.aarch64

src:
    amazon-ssm-agent-3.3.5226.0-1.amzn2023.src

x86_64:
    amazon-ssm-agent-3.3.5226.0-1.amzn2023.x86_64