ALAS2023-2026-1707


Amazon Linux 2023 Security Advisory: ALAS2023-2026-1707
Advisory Released Date: 2026-05-15
Advisory Updated Date: 2026-05-25
Severity: Low

Issue Overview:

A vulnerability, which was classified as problematic, has been found in Khronos Group glslang 15.1.0. Affected by this issue is the function glslang::TIntermediate::isConversionAllowed of the file glslang/MachineIndependent/Intermediate.cpp. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. (CVE-2025-3010)


Affected Packages:

glslang


Issue Correction:
Run dnf update glslang --releasever 2023.11.20260514 or dnf update --advisory ALAS2023-2026-1707 --releasever 2023.11.20260514 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    glslang-devel-15.0.0-88.amzn2023.aarch64
    glslang-debuginfo-15.0.0-88.amzn2023.aarch64
    glslang-15.0.0-88.amzn2023.aarch64
    glslang-debugsource-15.0.0-88.amzn2023.aarch64

src:
    glslang-15.0.0-88.amzn2023.src

x86_64:
    glslang-debuginfo-15.0.0-88.amzn2023.x86_64
    glslang-devel-15.0.0-88.amzn2023.x86_64
    glslang-debugsource-15.0.0-88.amzn2023.x86_64
    glslang-15.0.0-88.amzn2023.x86_64