Msrc Cbl2 Fluent-Bit 3.0.6-4 On Cbl Mariner 2.0 vulnerabilities

9 known vulnerabilities affecting msrc/cbl2_fluent-bit_3.0.6-4_on_cbl_mariner_2.0.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM5LOW2

Vulnerabilities

Page 1 of 1
CVE-2025-12977HIGHCVSS 8.32025-11-11
CVE-2025-12977 [CRITICAL] CWE-1287 CVE-2025-12977: CVE-2025-12977 Mariner: Mariner certcc: certcc Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn CVE-2025-12977 Mariner: Mariner certcc: certcc Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2025-12970HIGHCVSS 8.82025-11-11
CVE-2025-12970 [HIGH] CWE-120 CVE-2025-12970: CVE-2025-12970 Mariner: Mariner certcc: certcc Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn CVE-2025-12970 Mariner: Mariner certcc: certcc Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2025-12969MEDIUMCVSS 6.52025-11-11
CVE-2025-12969 [MEDIUM] CWE-306 CVE-2025-12969: CVE-2025-12969 Mariner: Mariner certcc: certcc Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn CVE-2025-12969 Mariner: Mariner certcc: certcc Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2025-64713MEDIUMCVSS 5.12025-11-11
CVE-2025-64713 [MEDIUM] CWE-119 WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode Mariner: Mariner GitHub_M: GitHub_M Customer Action Required: Yes
msrc
CVE-2025-64704MEDIUMCVSS 4.72025-11-11
CVE-2025-64704 [MEDIUM] CWE-754 WebAssembly Micro Runtime vulnerable to a segmentation fault in v128.store instruction WebAssembly Micro Runtime vulnerable to a segmentation fault in v128.store instruction Mariner: Mariner GitHub_M: GitHub_M Customer Action Required: Yes
msrc
CVE-2025-58749MEDIUMCVSS 5.32025-09-09
CVE-2025-58749 [LOW] CWE-822 WAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT mode WAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT mode FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure ver
msrc
CVE-2025-29477LOWCVSS 3.32025-04-08
CVE-2025-29477 [MEDIUM] CWE-400 An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event. An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is th
msrc
CVE-2025-29478LOWCVSS 3.62025-04-08
CVE-2025-29478 [MEDIUM] CWE-400 An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165. An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure
msrc
CVE-2018-14040MEDIUMCVSS 6.12018-07-10
CVE-2018-14040 [MEDIUM] In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attributeIn Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attributeIn Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of
msrc