Msrc Cm1 Kernel 5.10.153.1-1 On Cbl Mariner 1.0 vulnerabilities

5 known vulnerabilities affecting msrc/cm1_kernel_5.10.153.1-1_on_cbl_mariner_1.0.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4LOW1

Vulnerabilities

Page 1 of 1
CVE-2022-3586MEDIUMCVSS 5.52022-10-11
CVE-2022-3586 [MEDIUM] CWE-416 A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (a A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (and freed) into a child qdisc. This flaw allows a local unprivileged
msrc
CVE-2022-3594MEDIUMCVSS 5.32022-10-11
CVE-2022-3594 [MEDIUM] CWE-404 Linux Kernel BPF r8152.c intr_callback logging of excessive data Linux Kernel BPF r8152.c intr_callback logging of excessive data FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source lib
msrc
CVE-2022-43750MEDIUMCVSS 6.72022-10-11
CVE-2022-43750 [MEDIUM] CWE-787 drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory. drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability
msrc
CVE-2022-3521LOWCVSS 2.52022-10-11
CVE-2022-3521 [LOW] CWE-362 Linux Kernel kcm kcmsock.c kcm_tx_work race condition Linux Kernel kcm kcmsock.c kcm_tx_work race condition FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the dis
msrc
CVE-2022-41850MEDIUMCVSS 4.72022-09-13
CVE-2022-41850 [MEDIUM] CWE-362 roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a r roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a report->value is in progress. FAQ: Is Azure Linux the only Microsof
msrc