Msrc Azl3 Rust 1.75.0-24 On Azure Linux 3.0 vulnerabilities

10 known vulnerabilities affecting msrc/azl3_rust_1.75.0-24_on_azure_linux_3.0.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM8LOW1

Vulnerabilities

Page 1 of 1
CVE-2025-11563MEDIUMCVSS 4.62026-02-10
CVE-2025-11563 [MEDIUM] wcurl path traversal with percent-encoded slashes wcurl path traversal with percent-encoded slashes Mariner: Mariner curl: curl Customer Action Required: Yes
msrc
CVE-2026-1979MEDIUMCVSS 5.32026-02-10
CVE-2026-1979 [MEDIUM] CWE-416 mruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free mruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free Mariner: Mariner VulDB: VulDB Customer Action Required: Yes
msrc
CVE-2025-68114MEDIUMCVSS 4.82025-12-09
CVE-2025-68114 [MEDIUM] CWE-124 Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow Mariner: Mariner GitHub_M: GitHub_M Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2025-9230HIGHCVSS 7.52025-09-09
CVE-2025-9230 [HIGH] CWE-125 Out-of-bounds read & write in RFC 3211 KEK Unwrap Out-of-bounds read & write in RFC 3211 KEK Unwrap FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is
msrc
CVE-2025-9231MEDIUMCVSS 6.52025-09-09
CVE-2025-9231 [MEDIUM] CWE-385 Timing side-channel in SM2 algorithm on 64 bit ARM Timing side-channel in SM2 algorithm on 64 bit ARM FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro
msrc
CVE-2025-9232MEDIUMCVSS 5.92025-09-09
CVE-2025-9232 [MEDIUM] CWE-125 Out-of-bounds read in HTTP client no_proxy handling Out-of-bounds read in HTTP client no_proxy handling FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the dist
msrc
CVE-2024-58266LOWCVSS 3.22025-07-08
CVE-2024-58266 [LOW] CWE-116 The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection. The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to
msrc
CVE-2025-4432MEDIUMCVSS 5.32025-05-13
CVE-2025-4432 [MEDIUM] CWE-770 Ring: some aes functions may panic when overflow checking is enabled in ring Ring: some aes functions may panic when overflow checking is enabled in ring FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure version
msrc
CVE-2025-4575MEDIUMCVSS 6.52025-05-13
CVE-2025-4575 [MEDIUM] CWE-295 The x509 application adds trusted use instead of rejected use The x509 application adds trusted use instead of rejected use Mariner: Mariner openssl: openssl Customer Action Required: Yes
msrc
CVE-2019-16760MEDIUMCVSS 4.62019-09-10
CVE-2019-16760 [MEDIUM] Cargo prior to Rust 1.26.0 may download the wrong dependency Cargo prior to Rust 1.26.0 may download the wrong dependency Mariner: Mariner GitHub_M: GitHub_M Customer Action Required: Yes
msrc