Amazon Linux 2023 Security Advisory: ALAS2023-2026-2031
Advisory Released Date: 2026-08-04
Advisory Updated Date: 2026-08-04
FAQs regarding Amazon Linux ALAS/CVE Severity
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS). (CVE-2026-55653)
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session. (CVE-2026-55655)
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. (CVE-2026-59996)
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) (CVE-2026-60002)
Affected Packages:
openssh
Issue Correction:
Run dnf update openssh --releasever 2023.12.20260803 or dnf update --advisory ALAS2023-2026-2031 --releasever 2023.12.20260803 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
openssh-sk-dummy-debuginfo-9.9p1-10.amzn2023.0.1.aarch64
openssh-debuginfo-9.9p1-10.amzn2023.0.1.aarch64
openssh-debugsource-9.9p1-10.amzn2023.0.1.aarch64
openssh-keycat-9.9p1-10.amzn2023.0.1.aarch64
openssh-keycat-debuginfo-9.9p1-10.amzn2023.0.1.aarch64
openssh-clients-debuginfo-9.9p1-10.amzn2023.0.1.aarch64
openssh-server-9.9p1-10.amzn2023.0.1.aarch64
openssh-server-debuginfo-9.9p1-10.amzn2023.0.1.aarch64
openssh-9.9p1-10.amzn2023.0.1.aarch64
openssh-sk-dummy-9.9p1-10.amzn2023.0.1.aarch64
openssh-clients-9.9p1-10.amzn2023.0.1.aarch64
pam_ssh_agent_auth-0.10.4-9.10.amzn2023.0.1.aarch64
pam_ssh_agent_auth-debuginfo-0.10.4-9.10.amzn2023.0.1.aarch64
src:
openssh-9.9p1-10.amzn2023.0.1.src
x86_64:
openssh-clients-debuginfo-9.9p1-10.amzn2023.0.1.x86_64
openssh-keycat-debuginfo-9.9p1-10.amzn2023.0.1.x86_64
openssh-server-debuginfo-9.9p1-10.amzn2023.0.1.x86_64
openssh-debuginfo-9.9p1-10.amzn2023.0.1.x86_64
pam_ssh_agent_auth-debuginfo-0.10.4-9.10.amzn2023.0.1.x86_64
openssh-sk-dummy-debuginfo-9.9p1-10.amzn2023.0.1.x86_64
openssh-keycat-9.9p1-10.amzn2023.0.1.x86_64
openssh-clients-9.9p1-10.amzn2023.0.1.x86_64
pam_ssh_agent_auth-0.10.4-9.10.amzn2023.0.1.x86_64
openssh-sk-dummy-9.9p1-10.amzn2023.0.1.x86_64
openssh-debugsource-9.9p1-10.amzn2023.0.1.x86_64
openssh-server-9.9p1-10.amzn2023.0.1.x86_64
openssh-9.9p1-10.amzn2023.0.1.x86_64