Msrc Cbl2 Kata-Containers 3.2.0.Azl2-6 On Cbl Mariner 2.0 vulnerabilities
6 known vulnerabilities affecting msrc/cbl2_kata-containers_3.2.0.azl2-6_on_cbl_mariner_2.0.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM3LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-53605MEDIUMCVSS 5.92025-07-08
CVE-2025-53605 [MEDIUM] CWE-674 The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefor
msrc
CVE-2024-58266LOWCVSS 3.22025-07-08
CVE-2024-58266 [LOW] CWE-116 The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.
The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to
msrc
CVE-2025-5791HIGHCVSS 7.12025-06-10
CVE-2025-5791 [HIGH] CWE-266 Users: `root` appended to group listings
Users: `root` appended to group listings
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsof
msrc
CVE-2024-43806MEDIUMCVSS 6.52024-08-13
CVE-2024-43806 [MEDIUM] CWE-400 `rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosion
`rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosion
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most s
msrc
CVE-2024-27308HIGHCVSS 7.52024-03-12
CVE-2024-27308 [HIGH] CWE-416 Mio's tokens for named pipes may be delivered after deregistration
Mio's tokens for named pipes may be delivered after deregistration
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source
msrc
CVE-2023-50711MEDIUMCVSS 5.72024-01-09
CVE-2023-50711 [MEDIUM] CWE-787 `serde` deserialization for `FamStructWrapper` lacks bound checks that could potentially lead to out-of-bounds memory access
`serde` deserialization for `FamStructWrapper` lacks bound checks that could potentially lead to out-of-bounds memory access
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure
msrc