AZLX-23-000130 - Amazon Linux 2023 must be a vendor-supported release.

Information

An operating system release is considered "supported" if the vendor continues to provide security patches for the product. With an unsupported release, it will not be possible to resolve security issues discovered in the system software. Amazon Linux 2023 (AL2023) was released in March 2023 and will be supported until June 30, 2029.

Standard support ends June 30, 2027.
Maintenance (security and critical fixes only) ends June 30, 2029.

To check the support status and dates of individual packages, use the following command:
$ sudo dnf supportinfo --pkg <packagename>

To get information on all currently installed packages, use:
$ sudo dnf supportinfo --show installed

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure Amazon Linux 2023 to be a vendor supported release.

Upgrade to a supported version of Amazon Linux 2023.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Amazon_Linux_2023_V1R2_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2c., CAT|I, CCI|CCI-002605, Rule-ID|SV-273999r1155171_rule, STIG-ID|AZLX-23-000130, Vuln-ID|V-273999

Plugin: Unix

Control ID: ed3e8f0953a895c1b767de840c2375cd4a562012d1ece60a92017ac603cec95d