ALAS2023-2026-2002


Amazon Linux 2023 Security Advisory: ALAS2023-2026-2002
Advisory Released Date: 2026-08-04
Advisory Updated Date: 2026-08-04
Severity: Important

Issue Overview:

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4. (CVE-2026-54572)

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4. (CVE-2026-59733)


Affected Packages:

rclone


Issue Correction:
Run dnf update rclone --releasever 2023.12.20260803 or dnf update --advisory ALAS2023-2026-2002 --releasever 2023.12.20260803 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    rclone-debuginfo-1.74.3-83.amzn2023.aarch64
    rclone-1.74.3-83.amzn2023.aarch64
    rclone-debugsource-1.74.3-83.amzn2023.aarch64

src:
    rclone-1.74.3-83.amzn2023.src

x86_64:
    rclone-debuginfo-1.74.3-83.amzn2023.x86_64
    rclone-1.74.3-83.amzn2023.x86_64
    rclone-debugsource-1.74.3-83.amzn2023.x86_64