Skip to content

CVE Patching SLA for AWS Deep Learning Containers

AWS is committed to keeping Deep Learning Containers images secure and up to date. As part of the shared responsibility model, AWS monitors published Common Vulnerabilities and Exposures (CVEs) that affect Deep Learning Containers images and remediates them within the service level agreements (SLAs) described on this page.

Patch and release cadence

AWS rebuilds and re-releases every in-support Deep Learning Containers image with the latest available patches on an approximately weekly cadence. Each rebuild incorporates the most recent operating system and package updates available at build time, ensuring that supported images receive routine security maintenance independent of any individual CVE.

Remediation SLAs

In addition to the regular patch cadence, AWS targets the following remediation SLAs for individual vulnerabilities, measured from the date a CVE is published to the date a patched image is released. SLAs are determined by the severity of the vulnerability:

Severity Remediation SLA
Critical 14 days
High 28 days
Medium 180 days

SLA compliance status

An image is considered out of SLA if it contains at least one vulnerability that exceeds the remediation SLA for its severity, as defined above. An image that contains no out-of-SLA vulnerabilities is considered within SLA.