Msrc Azl3 Libcontainers-Common 20240213-3 On Azure Linux 3.0 vulnerabilities
11 known vulnerabilities affecting msrc/azl3_libcontainers-common_20240213-3_on_azure_linux_3.0.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2025-47913HIGHCVSS 7.52025-11-11
CVE-2025-47913 [HIGH] Potential denial of service in golang.org/x/crypto/ssh/agent
Potential denial of service in golang.org/x/crypto/ssh/agent
Mariner: Mariner
Go: Go
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2025-9566HIGHCVSS 8.12025-09-09
CVE-2025-9566 [HIGH] CWE-22 Podman: podman kube play command may overwrite host files
Podman: podman kube play command may overwrite host files
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which
msrc
CVE-2025-6032HIGHCVSS 8.32025-06-10
CVE-2025-6032 [HIGH] CWE-295 Podman: podman missing tls verification
Podman: podman missing tls verification
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft
msrc
CVE-2024-9675MEDIUMCVSS 4.42024-10-08
CVE-2024-9675 [HIGH] CWE-22 Buildah: buildah allows arbitrary directory mount
Buildah: buildah allows arbitrary directory mount
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is c
msrc
CVE-2024-9407MEDIUMCVSS 4.72024-10-08
CVE-2024-9407 [MEDIUM] CWE-20 Buildah: podman: improper input validation in bind-propagation option of dockerfile run --mount instruction
Buildah: podman: improper input validation in bind-propagation option of dockerfile run --mount instruction
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to ke
msrc
CVE-2024-9341MEDIUMCVSS 5.42024-10-08
CVE-2024-9341 [MEDIUM] CWE-59 Podman: buildah: cri-o: fips crypto-policy directory mounting issue in containers/common go library
Podman: buildah: cri-o: fips crypto-policy directory mounting issue in containers/common go library
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date
msrc
CVE-2024-9676MEDIUMCVSS 6.52024-10-08
CVE-2024-9676 [MEDIUM] CWE-22 Podman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos)
Podman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos)
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linu
msrc
CVE-2024-37298HIGHCVSS 7.52024-07-09
CVE-2024-37298 [HIGH] CWE-770 Potential memory exhaustion attack due to sparse slice deserialization
Potential memory exhaustion attack due to sparse slice deserialization
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open
msrc
CVE-2024-3727HIGHCVSS 8.32024-05-14
CVE-2024-3727 [HIGH] CWE-354 Containers/image: digest type does not guarantee valid type
Containers/image: digest type does not guarantee valid type
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with
msrc
CVE-2024-1753HIGHCVSS 8.62024-03-12
CVE-2024-1753 [HIGH] CWE-59 Buildah: full container escape at build time
Buildah: full container escape at build time
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. M
msrc
CVE-2022-2879HIGHCVSS 7.52022-10-11
CVE-2022-2879 [HIGH] CWE-770 Unbounded memory consumption when reading headers in archive/tar
Unbounded memory consumption when reading headers in archive/tar
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libra
msrc