Msrc Azl3 Libcontainers-Common 20240213-3 On Azure Linux 3.0 vulnerabilities

11 known vulnerabilities affecting msrc/azl3_libcontainers-common_20240213-3_on_azure_linux_3.0.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2025-47913HIGHCVSS 7.52025-11-11
CVE-2025-47913 [HIGH] Potential denial of service in golang.org/x/crypto/ssh/agent Potential denial of service in golang.org/x/crypto/ssh/agent Mariner: Mariner Go: Go Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2025-9566HIGHCVSS 8.12025-09-09
CVE-2025-9566 [HIGH] CWE-22 Podman: podman kube play command may overwrite host files Podman: podman kube play command may overwrite host files FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which
msrc
CVE-2025-6032HIGHCVSS 8.32025-06-10
CVE-2025-6032 [HIGH] CWE-295 Podman: podman missing tls verification Podman: podman missing tls verification FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft
msrc
CVE-2024-9675MEDIUMCVSS 4.42024-10-08
CVE-2024-9675 [HIGH] CWE-22 Buildah: buildah allows arbitrary directory mount Buildah: buildah allows arbitrary directory mount FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is c
msrc
CVE-2024-9407MEDIUMCVSS 4.72024-10-08
CVE-2024-9407 [MEDIUM] CWE-20 Buildah: podman: improper input validation in bind-propagation option of dockerfile run --mount instruction Buildah: podman: improper input validation in bind-propagation option of dockerfile run --mount instruction FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to ke
msrc
CVE-2024-9341MEDIUMCVSS 5.42024-10-08
CVE-2024-9341 [MEDIUM] CWE-59 Podman: buildah: cri-o: fips crypto-policy directory mounting issue in containers/common go library Podman: buildah: cri-o: fips crypto-policy directory mounting issue in containers/common go library FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date
msrc
CVE-2024-9676MEDIUMCVSS 6.52024-10-08
CVE-2024-9676 [MEDIUM] CWE-22 Podman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos) Podman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos) FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linu
msrc
CVE-2024-37298HIGHCVSS 7.52024-07-09
CVE-2024-37298 [HIGH] CWE-770 Potential memory exhaustion attack due to sparse slice deserialization Potential memory exhaustion attack due to sparse slice deserialization FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open
msrc
CVE-2024-3727HIGHCVSS 8.32024-05-14
CVE-2024-3727 [HIGH] CWE-354 Containers/image: digest type does not guarantee valid type Containers/image: digest type does not guarantee valid type FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with
msrc
CVE-2024-1753HIGHCVSS 8.62024-03-12
CVE-2024-1753 [HIGH] CWE-59 Buildah: full container escape at build time Buildah: full container escape at build time FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. M
msrc
CVE-2022-2879HIGHCVSS 7.52022-10-11
CVE-2022-2879 [HIGH] CWE-770 Unbounded memory consumption when reading headers in archive/tar Unbounded memory consumption when reading headers in archive/tar FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libra
msrc