What the vendor says is affected
- cbl2 cri-o 1.22.3-16 on CBL Mariner 2.0
- azl3 containerized-data-importer 1.57.0-16 on Azure Linux 3.0
- cbl2 msft-golang 1.24.8-1 on CBL Mariner 2.0
- cbl2 skopeo 1.14.2-12 on CBL Mariner 2.0
- azl3 containerized-data-importer 1.57.0-17 on Azure Linux 3.0
- azl3 gh 2.62.0-10 on Azure Linux 3.0
- azl3 golang 1.25.5-1 on Azure Linux 3.0
- azl3 moby-engine 25.0.3-14 on Azure Linux 3.0
- azl3 skopeo 1.14.4-7 on Azure Linux 3.0
- azl3 golang 1.25.6-1 on Azure Linux 3.0
- azl3 golang 1.26.0-1 on Azure Linux 3.0
- azl3 golang 1.25.7-1 on Azure Linux 3.0
- azl3 golang 1.25.8-1 on Azure Linux 3.0
- azl3 golang 1.25.10-1 on Azure Linux 3.0
- cbl2 containerized-data-importer 1.55.0-25 on CBL Mariner 2.0
- cbl2 golang 1.18.8-10 on CBL Mariner 2.0
- cbl2 golang 1.22.7-5 on CBL Mariner 2.0
- cbl2 moby-engine 24.0.9-18 on CBL Mariner 2.0
- azl3 gh 2.62.0-9 on Azure Linux 3.0
- azl3 golang 1.23.12-1 on Azure Linux 3.0
- azl3 golang 1.25.3-1 on Azure Linux 3.0
- azl3 moby-engine 25.0.3-13 on Azure Linux 3.0
- azl3 skopeo 1.14.4-6 on Azure Linux 3.0
- cbl2 containerized-data-importer 1.55.0-26 on CBL Mariner 2.0
Versions the vendor lists as fixed
- 1.22.3-17
- 1.57.0-17
- 1.14.2-13
- 2.62.0-10
- 25.0.3-14
- 1.14.4-7
- 1.55.0-26
- 24.0.9-19
What the vendor recommends
CBL-Mariner Releases
Review the complete instructions on the vendor's siteWhen this advisory changed
- Published by Microsoft Security Response Center
The publication date reported by the vendor.
- Updated by Microsoft Security Response Center
The vendor changed the advisory after it was first published.
- Added to SecurityAlert
We collected the advisory from the official source.