Skip to content

CVE-2026-44605 (HIGH): detected in Lambda Docker Images. #656

Description

@the-lambda-watchdog

CVE Details

CVE ID Severity Affected Package Installed Version Fixed Version Date Published Date of Scan
CVE-2026-44605 HIGH rpm 4.16.1.3-29.amzn2023.0.6 4.16.1.3-29.amzn2023.0.7 2026-08-05T18:17:11.173Z 2026-08-06T10:18:25.669864133Z

Affected Docker Images

Image Name SHA
public.ecr.aws/lambda/provided:latest public.ecr.aws/lambda/provided@sha256:3bf6850fd1a6f94a12b3206ed11bb40122cc757e01c7b13074dcd745d05d898b
public.ecr.aws/lambda/provided:al2023 public.ecr.aws/lambda/provided@sha256:3bf6850fd1a6f94a12b3206ed11bb40122cc757e01c7b13074dcd745d05d898b
public.ecr.aws/lambda/python:latest public.ecr.aws/lambda/python@sha256:b3a2430425b2214e67eb56bc918ae35b7868596a27eea56be48976df2503d8af
public.ecr.aws/lambda/python:3.14 public.ecr.aws/lambda/python@sha256:b3a2430425b2214e67eb56bc918ae35b7868596a27eea56be48976df2503d8af
public.ecr.aws/lambda/python:3.13 public.ecr.aws/lambda/python@sha256:3c98f11dc36b35ba093c1d8ec71ef5f43f6ef8e2636f9bbcdcf8a9592abc5114
public.ecr.aws/lambda/python:3.12 public.ecr.aws/lambda/python@sha256:5e6d93f319f56e00f1cb7ffc8d9859ca5bdf7f9dcbd3df4e6028fe049efe5475
public.ecr.aws/lambda/nodejs:latest public.ecr.aws/lambda/nodejs@sha256:f1ecb2ebd75829399731de5249f8e0eb67c5168fe8d13a8ec7f26aebfd2b9fc0
public.ecr.aws/lambda/nodejs:24 public.ecr.aws/lambda/nodejs@sha256:f1ecb2ebd75829399731de5249f8e0eb67c5168fe8d13a8ec7f26aebfd2b9fc0
public.ecr.aws/lambda/nodejs:22 public.ecr.aws/lambda/nodejs@sha256:70aeb8a6028f93d17fa1155a3d88b9288123f75edd26c3001b16de8bf648b0ad
public.ecr.aws/lambda/java:latest public.ecr.aws/lambda/java@sha256:2ec707e991e621400a4169ba745bfaced02147cd5ddfcdfb3c49d1ed650d2f64
public.ecr.aws/lambda/java:25 public.ecr.aws/lambda/java@sha256:2ec707e991e621400a4169ba745bfaced02147cd5ddfcdfb3c49d1ed650d2f64
public.ecr.aws/lambda/java:21 public.ecr.aws/lambda/java@sha256:70b394af760c47936239269aefc364318ac6b79358c005e6a546bca88aef8dea
public.ecr.aws/lambda/dotnet:latest public.ecr.aws/lambda/dotnet@sha256:b3b87ea18ae28a99af1d1d12ee34a90d7277b1fda705e8dd44c6dfdc4ae8116c
public.ecr.aws/lambda/dotnet:10 public.ecr.aws/lambda/dotnet@sha256:b3b87ea18ae28a99af1d1d12ee34a90d7277b1fda705e8dd44c6dfdc4ae8116c
public.ecr.aws/lambda/dotnet:9 public.ecr.aws/lambda/dotnet@sha256:eae6b29279ff25a73f55b8c87bb43630933a0d1fd9c7ee89fb67ea09396c38d6
public.ecr.aws/lambda/dotnet:8 public.ecr.aws/lambda/dotnet@sha256:0dd916a926bd3c25121bd68e595693bc39f6c1bebeab2a546f43c5f038e07f76
public.ecr.aws/lambda/ruby:latest public.ecr.aws/lambda/ruby@sha256:df52e2717fd88e36d715b4931d75f4be67a5925f962827be6b18d986e59f7bd8
public.ecr.aws/lambda/ruby:4.0 public.ecr.aws/lambda/ruby@sha256:df52e2717fd88e36d715b4931d75f4be67a5925f962827be6b18d986e59f7bd8
public.ecr.aws/lambda/ruby:3.4 public.ecr.aws/lambda/ruby@sha256:8c57b2bdb355f3d3d003a16f2e77842fa7d1551ce533d46a1164d4a9d32e801a
public.ecr.aws/lambda/ruby:3.3 public.ecr.aws/lambda/ruby@sha256:59f92bd12582b2cb844f0ef802d5dd8e30e4ec257dbc6fa22771cd4ca92364fc

Description

A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.


Remediation Steps

  • Update the affected package rpm from version 4.16.1.3-29.amzn2023.0.6 to 4.16.1.3-29.amzn2023.0.7.

About this issue

  • This issue may not contain all the information about the CVE nor the images it affects.
  • This issue will not be updated with new information and the list of affected images may have changed since the creation of this issue.
  • For more, visit Lambda Watchdog.
  • This issue was created automatically by Lambda Watchdog.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions