What the vendor says is affected
- cbl2 cri-o 1.22.3-9 on CBL Mariner 2.0
- cbl2 keda 2.4.0-25 on CBL Mariner 2.0
- cbl2 telegraf 1.29.4-10 on CBL Mariner 2.0
- cbl2 application-gateway-kubernetes-ingress 1.4.0-24 on CBL Mariner 2.0
- cbl2 cf-cli 8.4.0-23 on CBL Mariner 2.0
- cbl2 cni-plugins 1.3.0-7 on CBL Mariner 2.0
- cbl2 helm 3.14.2-5 on CBL Mariner 2.0
- cbl2 kubevirt 0.59.0-23 on CBL Mariner 2.0
- cbl2 containerized-data-importer 1.55.0-22 on CBL Mariner 2.0
- cbl2 influxdb 2.6.1-19 on CBL Mariner 2.0
- cbl2 prometheus-adapter 0.10.0-16 on CBL Mariner 2.0
- cbl2 sriov-network-device-plugin 3.6.2-7 on CBL Mariner 2.0
- cbl2 terraform 1.3.2-21 on CBL Mariner 2.0
- cbl2 packer 1.9.5-6 on CBL Mariner 2.0
- cbl2 vitess 17.0.7-3 on CBL Mariner 2.0
- cbl2 kubernetes 1.28.4-13 on CBL Mariner 2.0
- cbl2 cert-manager 1.11.2-17 on CBL Mariner 2.0
- azl3 containerd2 2.0.0-3 on Azure Linux 3.0
- azl3 cf-cli 8.7.3-5 on Azure Linux 3.0
- azl3 cni-plugins 1.4.0-2 on Azure Linux 3.0
- azl3 cni 1.1.2-4 on Azure Linux 3.0
- azl3 sriov-network-device-plugin 3.7.0-2 on Azure Linux 3.0
- azl3 cri-tools 1.30.1-2 on Azure Linux 3.0
- azl3 multus 4.0.2-4 on Azure Linux 3.0
Versions the vendor lists as fixed
- 1.22.3-9
- 2.4.0-25
- 1.29.4-10
- 1.4.0-24
- 8.4.0-23
- 1.3.0-7
- 3.14.2-5
- 0.59.0-23
- 1.55.0-22
- 2.6.1-19
- 0.10.0-16
- 3.6.2-7
- 1.3.2-21
- 1.9.5-6
- 17.0.7-3
- 1.28.4-13
- 1.11.2-17
- 2.0.0-3
- 8.7.3-5
- 1.4.0-2
- 1.1.2-4
- 3.7.0-2
- 1.30.1-2
- 4.0.2-4
What the vendor recommends
CBL-Mariner Releases
Review the complete instructions on the vendor's siteWhen this advisory changed
- Published by Microsoft Security Response Center
The publication date reported by the vendor.
- Updated by Microsoft Security Response Center
The vendor changed the advisory after it was first published.
- Added to SecurityAlert
We collected the advisory from the official source.