Amazon Linux 2023 Kernel Updates Address CVE-2026-80521

P2 — VALIDATE AND UPDATEImportant · Not provided by the authorityEXPLOITATION: NOT STATED

Quick Answer

Amazon Linux published 3 advisoryies for Amazon Linux 2023 kernel 6.1, 6.12, and 6.18 package streams. Match the installed package stream to the exact advisory, apply its supported fixed build, validate runtime and service health, and retain package and change evidence.

Confirm Scope And Apply The Supported Fix

What to do now: Identify affected Amazon Linux 2023 instances and installed package builds, select only the exact matching advisory, apply its fixed package through supported repositories, validate runtime and workload health, and preserve evidence.

Open the authoritative advisory

Last verified: 2026-10-01 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeAmazon Linux 2023 kernel 6.1, 6.12, and 6.18 package streams
AdvisoryALAS2023-2026-3146 / ALAS2023-2026-3147 / ALAS2023-2026-3148
CVECVE-2026-80521
Authoritative release date2026-09-30 23:33:00 UTC (Amazon Linux RSS)
Authority revision date2026-09-30 (each cited Amazon Linux advisory)
Affected versionsThe exact Amazon Linux 2023 package streams enumerated in ALAS2023-2026-3146 through ALAS2023-2026-3148 before their advisory-listed fixed builds.
Fixed versionkernel-6.1.188-233.386.amzn2023 / kernel-debuginfo-6.1.188-233.386.amzn2023 / kernel-debuginfo-common-aarch64-6.1.188-233.386.amzn2023 / kernel-debuginfo-common-x86_64-6.1.188-233.386.amzn2023 / kernel-devel-6.1.188-233.386.amzn2023 / kernel-headers-6.1.188-233.386.amzn2023 / kernel-livepatch-6.1.188-233.386-1.0-0.amzn2023 / kernel-modules-extra-6.1.188-233.386.amzn2023 / kernel-modules-extra-common-6.1.188-233.386.amzn2023 / kernel-tools-6.1.188-233.386.amzn2023 / kernel-tools-debuginfo-6.1.188-233.386.amzn2023 / kernel-tools-devel-6.1.188-233.386.amzn2023 / kernel6.12-6.12.110-135.202.amzn2023 / kernel6.12-debuginfo-6.12.110-135.202.amzn2023 / kernel6.12-debuginfo-common-aarch64-6.12.110-135.202.amzn2023 / kernel6.12-debuginfo-common-x86_64-6.12.110-135.202.amzn2023 / kernel6.12-devel-6.12.110-135.202.amzn2023 / kernel6.12-headers-6.12.110-135.202.amzn2023 / kernel6.12-modules-extra-6.12.110-135.202.amzn2023 / kernel6.12-modules-extra-common-6.12.110-135.202.amzn2023 / kernel6.12-tools-6.12.110-135.202.amzn2023 / kernel6.12-tools-debuginfo-6.12.110-135.202.amzn2023 / kernel6.12-tools-devel-6.12.110-135.202.amzn2023 / kernel6.18-6.18.51-120.163.amzn2023 / kernel6.18-debuginfo-6.18.51-120.163.amzn2023 / kernel6.18-debuginfo-common-aarch64-6.18.51-120.163.amzn2023 / kernel6.18-debuginfo-common-x86_64-6.18.51-120.163.amzn2023 / kernel6.18-devel-6.18.51-120.163.amzn2023 / kernel6.18-headers-6.18.51-120.163.amzn2023 / kernel6.18-modules-extra-6.18.51-120.163.amzn2023 / kernel6.18-modules-extra-common-6.18.51-120.163.amzn2023 / kernel6.18-tools-6.18.51-120.163.amzn2023 / kernel6.18-tools-debuginfo-6.18.51-120.163.amzn2023 / kernel6.18-tools-devel-6.18.51-120.163.amzn2023
CVSS base scoreNot provided by the authority
CVSS severityImportant
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

AWS released branch-specific kernel builds for CVE-2026-80521 across the supported 6.1, 6.12, and 6.18 Amazon Linux 2023 streams.

What To Validate Now

  1. Inventory. Locate Amazon Linux 2023 systems using Amazon Linux 2023 kernel 6.1, 6.12, and 6.18 package streams; record instance, architecture, repository release, running kernel or service state, installed package NVR, owner, and workload dependencies.
  2. Establish applicability. Match the exact installed package stream and architecture to the cited Amazon Linux advisory. Do not infer applicability from a CVE, package family, or severity alone.
  3. Remediate. Apply the exact advisory-listed fixed package through the supported Amazon Linux 2023 repository and normal change control; use the matching advisory identifier rather than a neighboring package stream.
  4. Validate. Confirm the resulting package NVR, live-patch or service state as applicable, representative workload health, monitoring, and recovery behavior; record exceptions and rollback decisions.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Coordinate kernel, live-patch, and management-agent changes with platform owners. A successful package transaction does not by itself prove the intended runtime state, and AWS severity is not evidence of exploitation.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.