Msrc Cbl2 Libssh 0.10.6-5 On Cbl Mariner 2.0 vulnerabilities
3 known vulnerabilities affecting msrc/cbl2_libssh_0.10.6-5_on_cbl_mariner_2.0.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2LOW1
Vulnerabilities
Page 1 of 1
CVE-2026-3731MEDIUMCVSS 5.32026-03-10
CVE-2026-3731 [MEDIUM] CWE-125 libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds
libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds
Mariner: Mariner
VulDB: VulDB
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2025-8277LOWCVSS 3.12025-09-09
CVE-2025-8277 [LOW] CWE-401 Libssh: memory exhaustion via repeated key exchange in libssh
Libssh: memory exhaustion via repeated key exchange in libssh
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries wi
msrc
CVE-2025-8114MEDIUMCVSS 4.72025-07-08
CVE-2025-8114 [MEDIUM] CWE-476 : null pointer dereference in libssh kex session id calculation
: null pointer dereference in libssh kex session id calculation
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libra
msrc