<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Amazon Linux</title>
  <link>https://cvedaily.com/pages/tags/amazon-linux.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/amazon-linux.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Amazon Linux</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:08 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2023-35812 – An issue was discovered in the Amazon Linux packages of OpenSSH 7.4 for Amazon L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35812</guid>
    <pubDate>Wed, 03 Apr 2024 17:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-35812</strong></p>
  <p>An issue was discovered in the Amazon Linux packages of OpenSSH 7.4 for Amazon Linux 1 and 2, because of an incomplete fix for CVE-2019-6111 within these specific packages. The fix had only covered cases where an absolute path is passed to scp. When a relative path is used, there is no verification that the name of a file received by the client matches the file requested. Fixed packages are avail…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-34266 – The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34266</guid>
    <pubDate>Tue, 19 Jul 2022 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-34266</strong></p>
  <p>The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a denial of service (application crash), a different vulnerability than CVE-2022-0562. When processing a malicious TIFF file, an invalid range may be passed as an argument to the memset() function within TIFFFetchStripThing() in tif_dirread.c. This will cause TIFFFetchStripThing() to segfault after use…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34266">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
