Msrc Cm1 Kernel 5.10.181.1-1 On Cbl Mariner 1.0 vulnerabilities
19 known vulnerabilities affecting msrc/cm1_kernel_5.10.181.1-1_on_cbl_mariner_1.0.
Total CVEs
19
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM13
Vulnerabilities
Page 1 of 1
CVE-2023-32233HIGHCVSS 7.82023-05-09
CVE-2023-32233 [HIGH] CWE-416 In the Linux kernel through 6.3.1 a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged loc
In the Linux kernel through 6.3.1 a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous se
msrc
CVE-2023-33288MEDIUMCVSS 4.72023-05-09
CVE-2023-33288 [MEDIUM] CWE-416 An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system du
An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race condition.
FAQ: Is Azure Linux the only Microsoft prod
msrc
CVE-2023-32269MEDIUMCVSS 6.72023-05-09
CVE-2023-32269 [MEDIUM] CWE-416 An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However in
An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However in order for an attacker to exploit this the system must have netrom r
msrc
CVE-2023-1859MEDIUMCVSS 4.72023-05-09
CVE-2023-1859 [MEDIUM] CWE-416 A use-after-free flaw was found in xen_9pfs_front_removet in net/9p/trans_xen.c in Xen transport for 9pfs in the Linux Kernel. This flaw could allow a local attacker to crash the system due to a race
A use-after-free flaw was found in xen_9pfs_front_removet in net/9p/trans_xen.c in Xen transport for 9pfs in the Linux Kernel. This flaw could allow a local attacker to crash the system due to a race problem possibly leading to a kernel information leak.
FAQ: Is Azur
msrc
CVE-2023-0459MEDIUMCVSS 5.52023-05-09
CVE-2023-0459 [MEDIUM] CWE-763 Copy_from_user Spectre-V1 Gadget in Linux Kernel
Copy_from_user Spectre-V1 Gadget in Linux Kernel
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is
msrc
CVE-2023-2513MEDIUMCVSS 6.72023-05-09
CVE-2023-2513 [MEDIUM] CWE-416 A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes. This flaw could allow a privileged local user to caus
A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes. This flaw could allow a privileged local user to cause a system crash or other undefined behaviors.
FAQ: Is Azure Linux
msrc
CVE-2023-1195MEDIUMCVSS 5.52023-05-09
CVE-2023-1195 [MEDIUM] CWE-416 A use-after-free flaw was found in reconn_set_ipaddr_from_hostname in fs/cifs/connect.c in the Linux kernel. The issue occurs when it forgets to set the free pointer server->hostname to NULL leading t
A use-after-free flaw was found in reconn_set_ipaddr_from_hostname in fs/cifs/connect.c in the Linux kernel. The issue occurs when it forgets to set the free pointer server->hostname to NULL leading to an invalid pointer request.
FAQ: Is Azure Linux the only Microsof
msrc
CVE-2023-33203MEDIUMCVSS 6.42023-05-09
CVE-2023-33203 [MEDIUM] CWE-362 The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device.
The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library a
msrc
CVE-2023-31436HIGHCVSS 7.82023-04-11
CVE-2023-31436 [HIGH] CWE-787 qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.
qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our custom
msrc
CVE-2023-2008HIGHCVSS 7.82023-04-11
CVE-2023-2008 [HIGH] CWE-129 A flaw was found in the Linux kernel's udmabuf device driver. The specific flaw exists within a fault handler. The issue results from the lack of proper validation of user-supplied data which can resu
A flaw was found in the Linux kernel's udmabuf device driver. The specific flaw exists within a fault handler. The issue results from the lack of proper validation of user-supplied data which can result in a memory access past the end of an array. An attacker can levera
msrc
CVE-2023-2006HIGHCVSS 7.02023-04-11
CVE-2023-2006 [HIGH] CWE-362 A race condition was found in the Linux kernel's RxRPC network protocol within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an obje
A race condition was found in the Linux kernel's RxRPC network protocol within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and execute arbi
msrc
CVE-2023-1382MEDIUMCVSS 4.72023-04-11
CVE-2023-1382 [MEDIUM] CWE-476 A data race flaw was found in the Linux kernel between where con is allocated and con->sock is set. This issue leads to a NULL pointer dereference when accessing con->sock->sk in net/tipc/topsrv.c in
A data race flaw was found in the Linux kernel between where con is allocated and con->sock is set. This issue leads to a NULL pointer dereference when accessing con->sock->sk in net/tipc/topsrv.c in the tipc protocol in the Linux kernel.
FAQ: Is Azure Linux the only
msrc
CVE-2023-2194MEDIUMCVSS 6.72023-04-11
CVE-2023-2194 [MEDIUM] CWE-787 An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the siz
An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy possibly writing beyond the end of dma_buffer. This fl
msrc
CVE-2023-2162MEDIUMCVSS 5.52023-04-11
CVE-2023-2162 [MEDIUM] CWE-416 A use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-component in the Linux Kernel. In this flaw an attacker could leak kernel internal infor
A use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-component in the Linux Kernel. In this flaw an attacker could leak kernel internal information.
FAQ: Is Azure Linux the only Microsoft product that include
msrc
CVE-2023-28328MEDIUMCVSS 5.52023-04-11
CVE-2023-28328 [MEDIUM] CWE-476 A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel. The message from user space is not checked properly before transferring into t
A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel. The message from user space is not checked properly before transferring into the device. This flaw allows a local user to crash the system or pot
msrc
CVE-2023-2166MEDIUMCVSS 5.52023-04-11
CVE-2023-2166 [MEDIUM] CWE-476 A null pointer dereference issue was found in can protocol in net/can/af_can.c in the Linux before Linux. ml_priv may not be initialized in the receive path of CAN frames. A local user could use this
A null pointer dereference issue was found in can protocol in net/can/af_can.c in the Linux before Linux. ml_priv may not be initialized in the receive path of CAN frames. A local user could use this flaw to crash the system or potentially cause a denial of service.
msrc
CVE-2023-2177MEDIUMCVSS 5.52023-04-11
CVE-2023-2177 [MEDIUM] CWE-476 A null pointer dereference issue was found in the sctp network protocol in net/sctp/stream_sched.c in Linux Kernel. If stream_in allocation is failed stream_out is freed which would further be accesse
A null pointer dereference issue was found in the sctp network protocol in net/sctp/stream_sched.c in Linux Kernel. If stream_in allocation is failed stream_out is freed which would further be accessed. A local user could use this flaw to crash the system or potential
msrc
CVE-2022-4696HIGHCVSS 7.82023-01-10
CVE-2022-4696 [HIGH] CWE-416 There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag which signals that the ope
There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag which signals that the operation won't use current->nsproxy so its reference counter is not incr
msrc
CVE-2022-39189HIGHCVSS 7.82022-09-13
CVE-2022-39189 [HIGH] An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VC
An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED situations.
FAQ: Is Azure Linux the only Microsoft product that
msrc