Msrc Cbl2 Golang 1.22.7-3 On Cbl Mariner 2.0 vulnerabilities
21 known vulnerabilities affecting msrc/cbl2_golang_1.22.7-3_on_cbl_mariner_2.0.
Total CVEs
21
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH8MEDIUM11
Vulnerabilities
Page 1 of 2
CVE-2025-0913MEDIUMCVSS 5.52025-06-10
CVE-2025-0913 [MEDIUM] CWE-59 Inconsistent handling of O_CREATE|O_EXCL on Unix and Windows in os in syscall
Inconsistent handling of O_CREATE|O_EXCL on Unix and Windows in os in syscall
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versio
msrc
CVE-2025-22871HIGHCVSS 8.22025-04-08
CVE-2025-22871 [CRITICAL] Request smuggling due to acceptance of invalid chunked data in net/http
Request smuggling due to acceptance of invalid chunked data in net/http
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open s
msrc
CVE-2025-25199HIGHCVSS 7.52025-02-11
CVE-2025-25199 [HIGH] CWE-401 BCryptGenerateSymmetricKey memory leak
BCryptGenerateSymmetricKey memory leak
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2025-25199
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the o
msrc
CVE-2025-22866HIGHCVSS 8.42025-02-11
CVE-2025-22866 [MEDIUM] Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec
Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source librarie
msrc
CVE-2024-9355MEDIUMCVSS 6.52024-10-08
CVE-2024-9355 [MEDIUM] CWE-457 Golang-fips: golang fips zeroed buffer
Golang-fips: golang fips zeroed buffer
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft
msrc
CVE-2024-34158HIGHCVSS 7.52024-09-10
CVE-2024-34158 [HIGH] CWE-674 Stack exhaustion in Parse in go/build/constraint
Stack exhaustion in Parse in go/build/constraint
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is c
msrc
CVE-2024-34156HIGHCVSS 7.52024-09-10
CVE-2024-34156 [HIGH] Stack exhaustion in Decoder.Decode in encoding/gob
Stack exhaustion in Decoder.Decode in encoding/gob
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is compo
msrc
CVE-2024-34155MEDIUMCVSS 4.32024-09-10
CVE-2024-34155 [MEDIUM] Stack exhaustion in all Parse functions in go/parser
Stack exhaustion in all Parse functions in go/parser
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is
msrc
CVE-2023-24531CRITICALCVSS 9.82024-07-09
CVE-2023-24531 [CRITICAL] Output of "go env" does not sanitize values in cmd/go
Output of "go env" does not sanitize values in cmd/go
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distr
msrc
CVE-2024-24791HIGHCVSS 7.52024-07-09
CVE-2024-24791 [HIGH] Denial of service due to improper 100-continue handling in net/http
Denial of service due to improper 100-continue handling in net/http
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source librar
msrc
CVE-2024-24790CRITICALCVSS 9.82024-06-11
CVE-2024-24790 [CRITICAL] Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip
Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versio
msrc
CVE-2024-24789MEDIUMCVSS 5.32024-06-11
CVE-2024-24789 [MEDIUM] Mishandling of corrupt central directory record in archive/zip
Mishandling of corrupt central directory record in archive/zip
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with
msrc
CVE-2024-24788MEDIUMCVSS 5.92024-05-14
CVE-2024-24788 [MEDIUM] CWE-835 Malformed DNS message can cause infinite loop in net
Malformed DNS message can cause infinite loop in net
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the d
msrc
CVE-2024-24787MEDIUMCVSS 6.42024-05-14
CVE-2024-24787 [MEDIUM] Arbitrary code execution during build on Darwin in cmd/go
Arbitrary code execution during build on Darwin in cmd/go
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the
msrc
CVE-2024-24784HIGHCVSS 7.52024-03-12
CVE-2024-24784 [HIGH] Comments in display names are incorrectly handled in net/mail
Comments in display names are incorrectly handled in net/mail
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with whi
msrc
CVE-2023-45289MEDIUMCVSS 4.32024-03-12
CVE-2023-45289 [MEDIUM] Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http
Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure ve
msrc
CVE-2024-24783MEDIUMCVSS 5.92024-03-12
CVE-2024-24783 [MEDIUM] CWE-476 Verify panics on certificates with an unknown public key algorithm in crypto/x509
Verify panics on certificates with an unknown public key algorithm in crypto/x509
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most sec
msrc
CVE-2024-24785MEDIUMCVSS 5.42024-03-12
CVE-2024-24785 [MEDIUM] Errors returned from JSON marshaling may break template escaping in html/template
Errors returned from JSON marshaling may break template escaping in html/template
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure vers
msrc
CVE-2023-45290MEDIUMCVSS 6.52024-03-12
CVE-2023-45290 [MEDIUM] CWE-770 Memory exhaustion in multipart form parsing in net/textproto and net/http
Memory exhaustion in multipart form parsing in net/textproto and net/http
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of
msrc
CVE-2022-41722HIGHCVSS 7.52023-02-14
CVE-2022-41722 [HIGH] CWE-22 Path traversal on Windows in path/filepath
Path traversal on Windows in path/filepath
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Micr
msrc
1 / 2Next →