ALAS2023-2026-1657


Amazon Linux 2023 Security Advisory: ALAS2023-2026-1657
Advisory Released Date: 2026-05-14
Advisory Updated Date: 2026-05-14
Severity: Medium

Issue Overview:

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication. (CVE-2026-41254)


Affected Packages:

lcms2


Issue Correction:
Run dnf update lcms2 --releasever 2023.11.20260511 or dnf update --advisory ALAS2023-2026-1657 --releasever 2023.11.20260511 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    lcms2-debugsource-2.19-75.amzn2023.0.1.aarch64
    lcms2-debuginfo-2.19-75.amzn2023.0.1.aarch64
    lcms2-devel-2.19-75.amzn2023.0.1.aarch64
    lcms2-utils-2.19-75.amzn2023.0.1.aarch64
    lcms2-2.19-75.amzn2023.0.1.aarch64
    lcms2-utils-debuginfo-2.19-75.amzn2023.0.1.aarch64

src:
    lcms2-2.19-75.amzn2023.0.1.src

x86_64:
    lcms2-debugsource-2.19-75.amzn2023.0.1.x86_64
    lcms2-utils-debuginfo-2.19-75.amzn2023.0.1.x86_64
    lcms2-2.19-75.amzn2023.0.1.x86_64
    lcms2-debuginfo-2.19-75.amzn2023.0.1.x86_64
    lcms2-devel-2.19-75.amzn2023.0.1.x86_64
    lcms2-utils-2.19-75.amzn2023.0.1.x86_64