https://alas.aws.amazon.com//AL2023/ALAS2023-2026-1509.html
Severity: Medium
ID: 304580
File Name: al2023_ALAS2023-2026-1509.nasl
Version: 1.1
Type: Local
Agent: unix
Published: 4/1/2026
Updated: 4/1/2026
Supported Sensors: Nessus Agent, Continuous Assessment, Nessus
Risk Factor: Low
Score: 2.9
Risk Factor: Low
Base Score: 1.7
Temporal Score: 1.3
Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:P
CVSS Score Source: CVE-2026-3949
Risk Factor: Low
Base Score: 3.3
Temporal Score: 2.9
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Risk Factor: Medium
Base Score: 4.8
Threat Score: 1.1
Threat Vector: CVSS:4.0/E:U
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CPE: p-cpe:/a:amazon:linux:libheif-debuginfo, p-cpe:/a:amazon:linux:libheif-debugsource, p-cpe:/a:amazon:linux:libheif, p-cpe:/a:amazon:linux:libheif-devel, p-cpe:/a:amazon:linux:libheif-tools-debuginfo, p-cpe:/a:amazon:linux:libheif-tools, p-cpe:/a:amazon:linux:heif-pixbuf-loader-debuginfo, p-cpe:/a:amazon:linux:heif-pixbuf-loader, cpe:/o:amazon:linux:2023
Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list
Exploit Ease: No known exploits are available
Patch Publication Date: 4/1/2026
Vulnerability Publication Date: 3/11/2026
CVE: CVE-2026-3949