Msrc Azl3 Gcc 13.2.0-7 On Azure Linux 3.0 vulnerabilities
66 known vulnerabilities affecting msrc/azl3_gcc_13.2.0-7_on_azure_linux_3.0.
Total CVEs
66
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH35MEDIUM23LOW1
Vulnerabilities
Page 1 of 4
CVE-2026-4746CRITICALCVSS 10.02026-03-10
CVE-2026-4746 [CRITICAL] CWE-787 Heap Buffer Over-Write Vulenrabilty in timeplus-io/proton
Heap Buffer Over-Write Vulenrabilty in timeplus-io/proton
Mariner: Mariner
GovTech CSG: GovTech CSG
Customer Action Required: Yes
msrc
CVE-2026-27142HIGHCVSS 7.52026-03-10
CVE-2026-27142 [MEDIUM] URLs in meta content attribute actions are not escaped in html/template
URLs in meta content attribute actions are not escaped in html/template
Mariner: Mariner
Go: Go
Customer Action Required: Yes
msrc
CVE-2025-61727MEDIUMCVSS 6.52025-12-09
CVE-2025-61727 [MEDIUM] Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509
Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509
Mariner: Mariner
Go: Go
Customer Action Required: Yes
msrc
CVE-2025-47912HIGHCVSS 7.72025-10-14
CVE-2025-47912 [MEDIUM] Insufficient validation of bracketed IPv6 hostnames in net/url
Insufficient validation of bracketed IPv6 hostnames in net/url
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with
msrc
CVE-2025-58189HIGHCVSS 7.52025-10-14
CVE-2025-58189 [MEDIUM] ALPN negotiation error contains attacker controlled information in crypto/tls
ALPN negotiation error contains attacker controlled information in crypto/tls
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of
msrc
CVE-2025-58185HIGHCVSS 7.52025-10-14
CVE-2025-58185 [MEDIUM] Parsing DER payload can cause memory exhaustion in encoding/asn1
Parsing DER payload can cause memory exhaustion in encoding/asn1
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries
msrc
CVE-2025-61723HIGHCVSS 7.52025-10-14
CVE-2025-61723 [HIGH] Quadratic complexity when parsing some invalid inputs in encoding/pem
Quadratic complexity when parsing some invalid inputs in encoding/pem
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source li
msrc
CVE-2025-61725MEDIUMCVSS 6.52025-10-14
CVE-2025-61725 [HIGH] Excessive CPU consumption in ParseAddress in net/mail
Excessive CPU consumption in ParseAddress in net/mail
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is
msrc
CVE-2025-58187MEDIUMCVSS 5.32025-10-14
CVE-2025-58187 [HIGH] Quadratic complexity when checking name constraints in crypto/x509
Quadratic complexity when checking name constraints in crypto/x509
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source librarie
msrc
CVE-2025-22874HIGHCVSS 7.52025-06-10
CVE-2025-22874 [HIGH] Usage of ExtKeyUsageAny disables policy validation in crypto/x509
Usage of ExtKeyUsageAny disables policy validation in crypto/x509
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries
msrc
CVE-2025-4673MEDIUMCVSS 6.82025-06-10
CVE-2025-4673 [MEDIUM] Sensitive headers not cleared on cross-origin redirect in net/http
Sensitive headers not cleared on cross-origin redirect in net/http
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source librari
msrc
CVE-2025-22871HIGHCVSS 8.22025-04-08
CVE-2025-22871 [CRITICAL] Request smuggling due to acceptance of invalid chunked data in net/http
Request smuggling due to acceptance of invalid chunked data in net/http
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open s
msrc
CVE-2024-34158HIGHCVSS 7.52024-09-10
CVE-2024-34158 [HIGH] CWE-674 Stack exhaustion in Parse in go/build/constraint
Stack exhaustion in Parse in go/build/constraint
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is c
msrc
CVE-2024-34156HIGHCVSS 7.52024-09-10
CVE-2024-34156 [HIGH] Stack exhaustion in Decoder.Decode in encoding/gob
Stack exhaustion in Decoder.Decode in encoding/gob
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is compo
msrc
CVE-2024-34155MEDIUMCVSS 4.32024-09-10
CVE-2024-34155 [MEDIUM] Stack exhaustion in all Parse functions in go/parser
Stack exhaustion in all Parse functions in go/parser
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is
msrc
CVE-2023-24531CRITICALCVSS 9.82024-07-09
CVE-2023-24531 [CRITICAL] Output of "go env" does not sanitize values in cmd/go
Output of "go env" does not sanitize values in cmd/go
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distr
msrc
CVE-2024-24791HIGHCVSS 7.52024-07-09
CVE-2024-24791 [HIGH] Denial of service due to improper 100-continue handling in net/http
Denial of service due to improper 100-continue handling in net/http
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source librar
msrc
CVE-2024-24790CRITICALCVSS 9.82024-06-11
CVE-2024-24790 [CRITICAL] Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip
Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versio
msrc
CVE-2024-24789MEDIUMCVSS 5.32024-06-11
CVE-2024-24789 [MEDIUM] Mishandling of corrupt central directory record in archive/zip
Mishandling of corrupt central directory record in archive/zip
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with
msrc
CVE-2024-24787MEDIUMCVSS 6.42024-05-14
CVE-2024-24787 [MEDIUM] Arbitrary code execution during build on Darwin in cmd/go
Arbitrary code execution during build on Darwin in cmd/go
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the
msrc
1 / 4Next →