Msrc Azure Linux 3.0 Arm vulnerabilities
1,294 known vulnerabilities affecting msrc/azure_linux_3.0_arm.
Total CVEs
1,294
CISA KEV
3
actively exploited
Public exploits
13
Exploited in wild
6
Severity breakdown
CRITICAL72HIGH496MEDIUM697LOW28UNKNOWN1
Vulnerabilities
Page 27 of 65
CVE-2024-40960MEDIUMCVSS 5.52024-07-09
CVE-2024-40960 [MEDIUM] CWE-476 ipv6: prevent possible NULL dereference in rt6_probe()
ipv6: prevent possible NULL dereference in rt6_probe()
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which t
msrc
CVE-2024-21160MEDIUMCVSS 4.92024-07-09
CVE-2024-21160 [MEDIUM] Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compro
msrc
CVE-2024-21157MEDIUMCVSS 4.92024-07-09
CVE-2024-21157 [MEDIUM] Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compro
msrc
CVE-2024-41006MEDIUMCVSS 5.52024-07-09
CVE-2024-41006 [MEDIUM] CWE-401 netrom: Fix a memory leak in nr_heartbeat_expiry()
netrom: Fix a memory leak in nr_heartbeat_expiry()
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distr
msrc
CVE-2024-21129MEDIUMCVSS 4.92024-07-09
CVE-2024-21129 [MEDIUM] Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability al
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to c
msrc
CVE-2024-6874MEDIUMCVSS 4.32024-07-09
CVE-2024-6874 [MEDIUM] CWE-125 macidn punycode buffer overread
macidn punycode buffer overread
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed t
msrc
CVE-2024-41094MEDIUMCVSS 5.52024-07-09
CVE-2024-41094 [MEDIUM] drm/fbdev-dma: Only set smem_start is enable per module option
drm/fbdev-dma: Only set smem_start is enable per module option
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with
msrc
CVE-2024-42085MEDIUMCVSS 5.52024-07-09
CVE-2024-42085 [MEDIUM] CWE-667 usb: dwc3: core: remove lock of otg mode during gadget suspend/resume to avoid deadlock
usb: dwc3: core: remove lock of otg mode during gadget suspend/resume to avoid deadlock
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent
msrc
CVE-2024-39473MEDIUMCVSS 5.52024-07-09
CVE-2024-39473 [MEDIUM] CWE-476 ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension
ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most r
msrc
CVE-2024-42154MEDIUMCVSS 4.42024-07-09
CVE-2024-42154 [MEDIUM] CWE-754 tcp_metrics: validate source addr length
tcp_metrics: validate source addr length
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Micro
msrc
CVE-2024-42083MEDIUMCVSS 5.52024-07-09
CVE-2024-42083 [MEDIUM] CWE-476 ionic: fix kernel panic due to multi-buffer handling
ionic: fix kernel panic due to multi-buffer handling
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the d
msrc
CVE-2024-41001MEDIUMCVSS 5.52024-07-09
CVE-2024-41001 [MEDIUM] CWE-401 io_uring/sqpoll: work around a potential audit memory leak
io_uring/sqpoll: work around a potential audit memory leak
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with
msrc
CVE-2024-39472MEDIUMCVSS 5.52024-07-09
CVE-2024-39472 [MEDIUM] CWE-770 xfs: fix log recovery buffer allocation for the legacy h_size fixup
xfs: fix log recovery buffer allocation for the legacy h_size fixup
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open sou
msrc
CVE-2024-39481MEDIUMCVSS 5.52024-07-09
CVE-2024-39481 [MEDIUM] media: mc: Fix graph walk in media_pipeline_start
media: mc: Fix graph walk in media_pipeline_start
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is compo
msrc
CVE-2024-21125MEDIUMCVSS 4.92024-07-09
CVE-2024-21125 [MEDIUM] Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability al
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to c
msrc
CVE-2024-42078MEDIUMCVSS 5.52024-07-09
CVE-2024-42078 [MEDIUM] CWE-665 nfsd: initialise nfsd_info.mutex early.
nfsd: initialise nfsd_info.mutex early.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microso
msrc
CVE-2024-39489MEDIUMCVSS 5.52024-07-09
CVE-2024-39489 [MEDIUM] CWE-401 ipv6: sr: fix memleak in seg6_hmac_init_algo
ipv6: sr: fix memleak in seg6_hmac_init_algo
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is compose
msrc
CVE-2024-21171MEDIUMCVSS 6.52024-07-09
CVE-2024-21171 [MEDIUM] Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerabil
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols
msrc
CVE-2024-21159MEDIUMCVSS 4.92024-07-09
CVE-2024-21159 [MEDIUM] Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compro
msrc
CVE-2024-41054MEDIUMCVSS 5.52024-07-09
CVE-2024-41054 [MEDIUM] CWE-476 scsi: ufs: core: Fix ufshcd_clear_cmd racing issue
scsi: ufs: core: Fix ufshcd_clear_cmd racing issue
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distr
msrc