Msrc Azl3 Rust 1.75.0-22 On Azure Linux 3.0 vulnerabilities
14 known vulnerabilities affecting msrc/azl3_rust_1.75.0-22_on_azure_linux_3.0.
Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM12LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-68114MEDIUMCVSS 4.82025-12-09
CVE-2025-68114 [MEDIUM] CWE-124 Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow
Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2025-67873MEDIUMCVSS 4.82025-12-09
CVE-2025-67873 [MEDIUM] CWE-122 Capstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow
Capstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2025-12818MEDIUMCVSS 5.92025-11-11
CVE-2025-12818 [MEDIUM] CWE-190 PostgreSQL libpq undersizes allocations, via integer wraparound
PostgreSQL libpq undersizes allocations, via integer wraparound
Mariner: Mariner
PostgreSQL: PostgreSQL
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2025-62813MEDIUMCVSS 5.92025-10-14
CVE-2025-62813 [MEDIUM] CWE-158 LZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_cr
LZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in lib/lz4frame.c mishandles NULL checks.
FAQ:
msrc
CVE-2025-9230HIGHCVSS 7.52025-09-09
CVE-2025-9230 [HIGH] CWE-125 Out-of-bounds read & write in RFC 3211 KEK Unwrap
Out-of-bounds read & write in RFC 3211 KEK Unwrap
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is
msrc
CVE-2025-9231MEDIUMCVSS 6.52025-09-09
CVE-2025-9231 [MEDIUM] CWE-385 Timing side-channel in SM2 algorithm on 64 bit ARM
Timing side-channel in SM2 algorithm on 64 bit ARM
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro
msrc
CVE-2025-9232MEDIUMCVSS 5.92025-09-09
CVE-2025-9232 [MEDIUM] CWE-125 Out-of-bounds read in HTTP client no_proxy handling
Out-of-bounds read in HTTP client no_proxy handling
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the dist
msrc
CVE-2025-55159MEDIUMCVSS 5.12025-08-12
CVE-2025-55159 [MEDIUM] CWE-119 slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check
slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2024-58266LOWCVSS 3.22025-07-08
CVE-2024-58266 [LOW] CWE-116 The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.
The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to
msrc
CVE-2025-4432MEDIUMCVSS 5.32025-05-13
CVE-2025-4432 [MEDIUM] CWE-770 Ring: some aes functions may panic when overflow checking is enabled in ring
Ring: some aes functions may panic when overflow checking is enabled in ring
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure version
msrc
CVE-2025-4575MEDIUMCVSS 6.52025-05-13
CVE-2025-4575 [MEDIUM] CWE-295 The x509 application adds trusted use instead of rejected use
The x509 application adds trusted use instead of rejected use
Mariner: Mariner
openssl: openssl
Customer Action Required: Yes
msrc
CVE-2025-4207MEDIUMCVSS 5.92025-05-13
CVE-2025-4207 [MEDIUM] CWE-126 PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation
PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitmen
msrc
CVE-2023-29932MEDIUMCVSS 5.52023-05-09
CVE-2023-29932 [MEDIUM] CWE-119 llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand.
llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperandIs Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the
msrc
CVE-2019-16760MEDIUMCVSS 4.62019-09-10
CVE-2019-16760 [MEDIUM] Cargo prior to Rust 1.26.0 may download the wrong dependency
Cargo prior to Rust 1.26.0 may download the wrong dependency
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
msrc