Amazon Linux 2023 Security Advisory: ALAS2023-2026-1407
Advisory Released Date: 2026-02-18
Advisory Updated Date: 2026-02-18
Severity:
Important
Issue Overview:
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages.
Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python's recursion stack and causing a RecursionError. (CVE-2026-0994)
Affected Packages:
protobuf
Issue Correction:
Run dnf update protobuf --releasever 2023.10.20260216 or dnf update --advisory ALAS2023-2026-1407 --releasever 2023.10.20260216 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
New Packages:
aarch64:
protobuf-debuginfo-3.19.6-1.amzn2023.0.3.aarch64
protobuf-lite-devel-3.19.6-1.amzn2023.0.3.aarch64
protobuf-devel-3.19.6-1.amzn2023.0.3.aarch64
protobuf-compiler-3.19.6-1.amzn2023.0.3.aarch64
protobuf-lite-static-3.19.6-1.amzn2023.0.3.aarch64
protobuf-lite-3.19.6-1.amzn2023.0.3.aarch64
protobuf-compiler-debuginfo-3.19.6-1.amzn2023.0.3.aarch64
protobuf-debugsource-3.19.6-1.amzn2023.0.3.aarch64
protobuf-lite-debuginfo-3.19.6-1.amzn2023.0.3.aarch64
protobuf-static-3.19.6-1.amzn2023.0.3.aarch64
python3-protobuf-debuginfo-3.19.6-1.amzn2023.0.3.aarch64
protobuf-3.19.6-1.amzn2023.0.3.aarch64
python3-protobuf-3.19.6-1.amzn2023.0.3.aarch64
noarch:
protobuf-vim-3.19.6-1.amzn2023.0.3.noarch
protobuf-emacs-3.19.6-1.amzn2023.0.3.noarch
src:
protobuf-3.19.6-1.amzn2023.0.3.src
x86_64:
protobuf-lite-static-3.19.6-1.amzn2023.0.3.x86_64
protobuf-compiler-debuginfo-3.19.6-1.amzn2023.0.3.x86_64
python3-protobuf-debuginfo-3.19.6-1.amzn2023.0.3.x86_64
protobuf-static-3.19.6-1.amzn2023.0.3.x86_64
protobuf-devel-3.19.6-1.amzn2023.0.3.x86_64
protobuf-debuginfo-3.19.6-1.amzn2023.0.3.x86_64
python3-protobuf-3.19.6-1.amzn2023.0.3.x86_64
protobuf-lite-debuginfo-3.19.6-1.amzn2023.0.3.x86_64
protobuf-lite-devel-3.19.6-1.amzn2023.0.3.x86_64
protobuf-compiler-3.19.6-1.amzn2023.0.3.x86_64
protobuf-3.19.6-1.amzn2023.0.3.x86_64
protobuf-debugsource-3.19.6-1.amzn2023.0.3.x86_64
protobuf-lite-3.19.6-1.amzn2023.0.3.x86_64