AWS Security Advisories · December 2023 — AWS Security Advisories
16 advisories 25 CVEs 1 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2023-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

Advisories

ALAS-2023-1892

ALAS · AL1Important2023-12-05

ALAS-2023-1892: xorg-x11-server (important)

CVEs:CVE-2023-5574

Affected products

ProductStatusVendorPackageEcosystem
xorg-x11-server affected Amazon xorg-x11-server
Upstream advisory

ALAS-2023-1888

ALAS · AL1Low2023-12-04

ALAS-2023-1888: containerd (low)

Affected products

ProductStatusVendorPackageEcosystem
containerd affected Amazon containerd
Upstream advisory

ALAS-2023-1889

ALAS · AL1Medium2023-12-04

ALAS-2023-1889: amazon-efs-utils (medium)

CVEs:CVE-2022-46174

Affected products

ProductStatusVendorPackageEcosystem
amazon-efs-utils affected Amazon amazon-efs-utils
Upstream advisory

ALAS-2023-1890

ALAS · AL1Important2023-12-04

ALAS-2023-1890: microcode_ctl (important)

CVEs:CVE-2023-23583

Affected products

ProductStatusVendorPackageEcosystem
microcode_ctl affected Amazon microcode_ctl
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.