Amazon Linux 2023 Security Advisory: ALAS2023-2026-1782
Advisory Released Date: 2026-06-08
Advisory Updated Date: 2026-06-08
Severity:
Important
Issue Overview:
CVE-2026-46529 is a command injection vulnerability in Evince, Atril, and Xreader caused by missing quoting of shell-like input in ev_spawn() in ev-application.c. (CVE-2026-46529)
An unsoundness issue (RUSTSEC-2026-0097) was also found in the bundled Rust rand crate. ThreadRng methods use unsafe code that can create aliased mutable references when a custom logger accesses rand::rng() or rand::thread_rng() during reseeding, resulting in undefined behavior.
Affected Packages:
papers
Issue Correction:
Run dnf update papers --releasever 2023.12.20260608 or dnf update --advisory ALAS2023-2026-1782 --releasever 2023.12.20260608 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
New Packages:
aarch64:
papers-debuginfo-47.0-12.amzn2023.aarch64
papers-previewer-47.0-12.amzn2023.aarch64
papers-libs-47.0-12.amzn2023.aarch64
papers-previewer-debuginfo-47.0-12.amzn2023.aarch64
papers-libs-debuginfo-47.0-12.amzn2023.aarch64
papers-thumbnailer-47.0-12.amzn2023.aarch64
papers-nautilus-debuginfo-47.0-12.amzn2023.aarch64
papers-thumbnailer-debuginfo-47.0-12.amzn2023.aarch64
papers-nautilus-47.0-12.amzn2023.aarch64
papers-devel-47.0-12.amzn2023.aarch64
papers-debugsource-47.0-12.amzn2023.aarch64
papers-47.0-12.amzn2023.aarch64
src:
papers-47.0-12.amzn2023.src
x86_64:
papers-debuginfo-47.0-12.amzn2023.x86_64
papers-previewer-47.0-12.amzn2023.x86_64
papers-previewer-debuginfo-47.0-12.amzn2023.x86_64
papers-nautilus-debuginfo-47.0-12.amzn2023.x86_64
papers-thumbnailer-debuginfo-47.0-12.amzn2023.x86_64
papers-libs-debuginfo-47.0-12.amzn2023.x86_64
papers-thumbnailer-47.0-12.amzn2023.x86_64
papers-nautilus-47.0-12.amzn2023.x86_64
papers-devel-47.0-12.amzn2023.x86_64
papers-libs-47.0-12.amzn2023.x86_64
papers-debugsource-47.0-12.amzn2023.x86_64
papers-47.0-12.amzn2023.x86_64