What the vendor says is affected
- azl3 application-gateway-kubernetes-ingress 1.7.2-3 on Azure Linux 3.0
- azl3 etcd 3.5.12-2 on Azure Linux 3.0
- azl3 docker-cli 25.0.3-3 on Azure Linux 3.0
- azl3 containerd 1.7.13-8 on Azure Linux 3.0
- azl3 telegraf 1.29.4-1 on Azure Linux 3.0
- azl3 prometheus-node-exporter 1.7.0-3 on Azure Linux 3.0
- azl3 cert-manager 1.11.2-8 on Azure Linux 3.0
- azl3 moby-containerd-cc 1.7.7-9 on Azure Linux 3.0
- azl3 docker-compose 2.24.6-2 on Azure Linux 3.0
- azl3 git-lfs 3.4.1-1 on Azure Linux 3.0
- azl3 flannel 0.24.2-14 on Azure Linux 3.0
- azl3 containerized-data-importer 1.57.0-14 on Azure Linux 3.0
- azl3 prometheus-adapter 0.11.2-1 on Azure Linux 3.0
- azl3 kubevirt 1.2.0-17 on Azure Linux 3.0
- azl3 moby-engine 25.0.3-13 on Azure Linux 3.0
- azl3 influxdb 2.7.5-5 on Azure Linux 3.0
- azl3 cri-tools 1.29.0-1 on Azure Linux 3.0
- azl3 helm 3.13.2-3 on Azure Linux 3.0
- cbl2 packer 1.9.5-5 on CBL Mariner 2.0
- cbl2 kata-containers-cc 3.2.0.azl2-6 on CBL Mariner 2.0
- cbl2 moby-containerd 1.6.26-11 on CBL Mariner 2.0
- cbl2 moby-engine 24.0.9-16 on CBL Mariner 2.0
- cbl2 kubevirt 0.59.0-28 on CBL Mariner 2.0
- cbl2 moby-containerd-cc 1.7.7-11 on CBL Mariner 2.0
Versions the vendor lists as fixed
- 1.7.7-1
- 3.5.18-1
- 25.0.7-1
- 1.7.13-6
- 1.31.0-1
- 1.7.0-2
- 1.12.12-1
- 1.7.7-6
- 2.27.0-1
- 3.6.1-1
- 0.24.2-10
- 1.57.0-11
- 0.12.0-1
- 1.2.0-13
- 25.0.3-10
- 2.7.3-6
- 1.30.1-1
- 3.15.2-1
- 1.10.1-2
- 3.2.0.azl2-1
- 1.6.26-5
- 24.0.9-2
- 0.59.0-16
- 1.7.7-4
What the vendor recommends
CBL-Mariner Releases
Review the complete instructions on the vendor's siteWhen this advisory changed
- Published by Microsoft Security Response Center
The publication date reported by the vendor.
- Updated by Microsoft Security Response Center
The vendor changed the advisory after it was first published.
- Added to SecurityAlert
We collected the advisory from the official source.