Amazon Linux Updates SSM Agent for Four Vulnerabilities
Quick Answer
Amazon Linux published 1 advisory for Amazon Linux 2023 amazon-ssm-agent packages. Match the installed package stream to the exact advisory, apply its supported fixed build, validate runtime and service health, and retain package and change evidence.
Confirm Scope And Apply The Supported Fix
What to do now: Identify affected Amazon Linux 2023 instances and installed package builds, select only the exact matching advisory, apply its fixed package through supported repositories, validate runtime and workload health, and preserve evidence.
Last verified: 2026-10-01 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | Amazon Linux 2023 amazon-ssm-agent packages |
|---|---|
| Advisory | ALAS2023-2026-3149 |
| CVEs | CVE-2026-42505, CVE-2026-71556, CVE-2026-71557, CVE-2026-89049 |
| Authoritative release date | 2026-09-30 23:33:00 UTC (Amazon Linux RSS) |
| Authority revision date | 2026-09-30 (each cited Amazon Linux advisory) |
| Affected versions | The exact Amazon Linux 2023 package streams enumerated in ALAS2023-2026-3149 before their advisory-listed fixed builds. |
| Fixed version | amazon-ssm-agent-3.3.5226.0-1.amzn2023 |
| CVSS base score | Not provided by the authority |
| CVSS severity | Critical |
| Exploitation status | Not stated by the authority; no exploitation claim is inferred. |
What Changed
AWS released a Critical amazon-ssm-agent package update covering four vulnerabilities in agent and bundled dependency behavior.
What To Validate Now
- Inventory. Locate Amazon Linux 2023 systems using Amazon Linux 2023 amazon-ssm-agent packages; record instance, architecture, repository release, running kernel or service state, installed package NVR, owner, and workload dependencies.
- Establish applicability. Match the exact installed package stream and architecture to the cited Amazon Linux advisory. Do not infer applicability from a CVE, package family, or severity alone.
- Remediate. Apply the exact advisory-listed fixed package through the supported Amazon Linux 2023 repository and normal change control; use the matching advisory identifier rather than a neighboring package stream.
- Validate. Confirm the resulting package NVR, live-patch or service state as applicable, representative workload health, monitoring, and recovery behavior; record exceptions and rollback decisions.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Coordinate kernel, live-patch, and management-agent changes with platform owners. A successful package transaction does not by itself prove the intended runtime state, and AWS severity is not evidence of exploitation.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

