Amazon Linux 2023 Security Advisory: ALAS2023-2026-1692
Advisory Released Date: 2026-05-09
Advisory Updated Date: 2026-05-11
Severity:
Low
Issue Overview:
A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered lost. (CVE-2024-0217)
Affected Packages:
PackageKit
Issue Correction:
Run dnf update PackageKit --releasever 2023.11.20260509 or dnf update --advisory ALAS2023-2026-1692 --releasever 2023.11.20260509 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
New Packages:
aarch64:
PackageKit-gtk3-module-debuginfo-1.2.8-2.amzn2023.0.1.aarch64
PackageKit-command-not-found-debuginfo-1.2.8-2.amzn2023.0.1.aarch64
PackageKit-glib-debuginfo-1.2.8-2.amzn2023.0.1.aarch64
PackageKit-glib-devel-1.2.8-2.amzn2023.0.1.aarch64
PackageKit-cron-1.2.8-2.amzn2023.0.1.aarch64
PackageKit-debuginfo-1.2.8-2.amzn2023.0.1.aarch64
PackageKit-glib-1.2.8-2.amzn2023.0.1.aarch64
PackageKit-command-not-found-1.2.8-2.amzn2023.0.1.aarch64
PackageKit-gtk3-module-1.2.8-2.amzn2023.0.1.aarch64
PackageKit-debugsource-1.2.8-2.amzn2023.0.1.aarch64
PackageKit-1.2.8-2.amzn2023.0.1.aarch64
src:
PackageKit-1.2.8-2.amzn2023.0.1.src
x86_64:
PackageKit-glib-devel-1.2.8-2.amzn2023.0.1.x86_64
PackageKit-command-not-found-debuginfo-1.2.8-2.amzn2023.0.1.x86_64
PackageKit-glib-debuginfo-1.2.8-2.amzn2023.0.1.x86_64
PackageKit-gtk3-module-debuginfo-1.2.8-2.amzn2023.0.1.x86_64
PackageKit-debugsource-1.2.8-2.amzn2023.0.1.x86_64
PackageKit-debuginfo-1.2.8-2.amzn2023.0.1.x86_64
PackageKit-cron-1.2.8-2.amzn2023.0.1.x86_64
PackageKit-command-not-found-1.2.8-2.amzn2023.0.1.x86_64
PackageKit-gtk3-module-1.2.8-2.amzn2023.0.1.x86_64
PackageKit-glib-1.2.8-2.amzn2023.0.1.x86_64
PackageKit-1.2.8-2.amzn2023.0.1.x86_64