Msrc Cbl2 Kernel 5.15.143.1-1 On Cbl Mariner 2.0 vulnerabilities

6 known vulnerabilities affecting msrc/cbl2_kernel_5.15.143.1-1_on_cbl_mariner_2.0.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-6931HIGHCVSS 7.02023-12-12
CVE-2023-6931 [HIGH] CWE-787 Out-of-bounds write in Linux kernel's Performance Events system component Out-of-bounds write in Linux kernel's Performance Events system component FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the
msrc
CVE-2023-6932HIGHCVSS 7.02023-12-12
CVE-2023-6932 [HIGH] CWE-416 Use-after-free in Linux kernel's ipv4: igmp component Use-after-free in Linux kernel's ipv4: igmp component FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the di
msrc
CVE-2023-6622MEDIUMCVSS 5.52023-12-12
CVE-2023-6622 [MEDIUM] CWE-476 Kernel: null pointer dereference vulnerability in nft_dynset_init() Kernel: null pointer dereference vulnerability in nft_dynset_init() FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open sour
msrc
CVE-2023-1194HIGHCVSS 8.12023-11-14
CVE-2023-1194 [HIGH] CWE-125 Use-after-free in parse_lease_state() Use-after-free in parse_lease_state() FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is c
msrc
CVE-2023-1193MEDIUMCVSS 6.52023-11-14
CVE-2023-1193 [MEDIUM] CWE-416 Use-after-free in setup_async_work() Use-after-free in setup_async_work() FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is c
msrc
CVE-2023-46862MEDIUMCVSS 4.72023-10-10
CVE-2023-46862 [MEDIUM] CWE-476 An issue was discovered in the Linux kernel through 6.5.9. During a race with SQ thread exit an io_uring/fdinfo.c io_uring_show_fdinfo NULL pointer dereference can occur. An issue was discovered in the Linux kernel through 6.5.9. During a race with SQ thread exit an io_uring/fdinfo.c io_uring_show_fdinfo NULL pointer dereference can occur. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected b
msrc