ALAS2023-2026-1782


Amazon Linux 2023 Security Advisory: ALAS2023-2026-1782
Advisory Released Date: 2026-06-08
Advisory Updated Date: 2026-06-08
Severity: Important

Issue Overview:

CVE-2026-46529 is a command injection vulnerability in Evince, Atril, and Xreader caused by missing quoting of shell-like input in ev_spawn() in ev-application.c. (CVE-2026-46529)

An unsoundness issue (RUSTSEC-2026-0097) was also found in the bundled Rust rand crate. ThreadRng methods use unsafe code that can create aliased mutable references when a custom logger accesses rand::rng() or rand::thread_rng() during reseeding, resulting in undefined behavior.


Affected Packages:

papers


Issue Correction:
Run dnf update papers --releasever 2023.12.20260608 or dnf update --advisory ALAS2023-2026-1782 --releasever 2023.12.20260608 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    papers-debuginfo-47.0-12.amzn2023.aarch64
    papers-previewer-47.0-12.amzn2023.aarch64
    papers-libs-47.0-12.amzn2023.aarch64
    papers-previewer-debuginfo-47.0-12.amzn2023.aarch64
    papers-libs-debuginfo-47.0-12.amzn2023.aarch64
    papers-thumbnailer-47.0-12.amzn2023.aarch64
    papers-nautilus-debuginfo-47.0-12.amzn2023.aarch64
    papers-thumbnailer-debuginfo-47.0-12.amzn2023.aarch64
    papers-nautilus-47.0-12.amzn2023.aarch64
    papers-devel-47.0-12.amzn2023.aarch64
    papers-debugsource-47.0-12.amzn2023.aarch64
    papers-47.0-12.amzn2023.aarch64

src:
    papers-47.0-12.amzn2023.src

x86_64:
    papers-debuginfo-47.0-12.amzn2023.x86_64
    papers-previewer-47.0-12.amzn2023.x86_64
    papers-previewer-debuginfo-47.0-12.amzn2023.x86_64
    papers-nautilus-debuginfo-47.0-12.amzn2023.x86_64
    papers-thumbnailer-debuginfo-47.0-12.amzn2023.x86_64
    papers-libs-debuginfo-47.0-12.amzn2023.x86_64
    papers-thumbnailer-47.0-12.amzn2023.x86_64
    papers-nautilus-47.0-12.amzn2023.x86_64
    papers-devel-47.0-12.amzn2023.x86_64
    papers-libs-47.0-12.amzn2023.x86_64
    papers-debugsource-47.0-12.amzn2023.x86_64
    papers-47.0-12.amzn2023.x86_64