ALAS2023-2026-1774


Amazon Linux 2023 Security Advisory: ALAS2023-2026-1774
Advisory Released Date: 2026-06-08
Advisory Updated Date: 2026-06-08
Severity: Medium

Issue Overview:

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations. (CVE-2025-13462)

CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host. (CVE-2026-1502)

The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used to read and write addresses in a privileged process if that process connected to a malicious or "infected" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR. (CVE-2026-5713)

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. (CVE-2026-6019)

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch. (CVE-2026-7210)


Affected Packages:

python3.14


Issue Correction:
Run dnf update python3.14 --releasever 2023.12.20260608 or dnf update --advisory ALAS2023-2026-1774 --releasever 2023.12.20260608 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    python3.14-idle-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-freethreading-idle-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-tkinter-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-debug-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-freethreading-devel-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-freethreading-debug-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-debugsource-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-devel-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-freethreading-tkinter-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-freethreading-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-libs-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-freethreading-libs-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-debuginfo-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-freethreading-test-3.14.5-1.amzn2023.0.1.aarch64
    python3.14-test-3.14.5-1.amzn2023.0.1.aarch64

src:
    python3.14-3.14.5-1.amzn2023.0.1.src

x86_64:
    python3.14-freethreading-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-freethreading-devel-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-idle-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-devel-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-tkinter-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-debugsource-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-freethreading-tkinter-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-debug-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-freethreading-idle-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-freethreading-libs-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-freethreading-debug-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-debuginfo-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-freethreading-test-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-libs-3.14.5-1.amzn2023.0.1.x86_64
    python3.14-test-3.14.5-1.amzn2023.0.1.x86_64