Scope
What the vendor says is affected
- azl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0
- azl3 rust 1.75.0-30 on Azure Linux 3.0
- azl3 cloud-hypervisor 51.1.101-2 on Azure Linux 3.0
- azl3 openssl 3.3.7-4 on Azure Linux 3.0
- azl3 rust 1.90.0-10 on Azure Linux 3.0
- azl3 openvmm 0.1.0-1 on Azure Linux 3.0
Update history
What changed in later vendor updates
SecurityAlert records field-level changes from the point we begin following a bulletin. Earlier vendor changes may not have a field-by-field record.
- Severity changed from Medium to Critical.
- CVSS changed from 7.4 to 9.8.
- Added affected products: azl3 openvmm 0.1.0-1 on Azure Linux 3.0.
- The vendor changed its remediation guidance.
Timeline
When this advisory changed
Published by Microsoft Security Response CenterThe publication date reported by the vendor.
Added to SecurityAlertWe collected the advisory from the official source.
Updated by Microsoft Security Response CenterThe vendor changed the advisory after it was first published.
Confirmed at the sourceOur collector saw this advisory during a later source check.
Vulnerabilities
CVEs named in this advisory