What the vendor says is affected
- azl3 skopeo 1.14.4-5 on Azure Linux 3.0
- cbl2 influxdb 2.6.1-22 on CBL Mariner 2.0
- azl3 ig 0.37.0-4 on Azure Linux 3.0
- cbl2 kube-vip-cloud-provider 0.0.2-22 on CBL Mariner 2.0
- azl3 cert-manager 1.12.15-3 on Azure Linux 3.0
- azl3 influxdb 2.7.5-5 on Azure Linux 3.0
- azl3 containerized-data-importer 1.57.0-14 on Azure Linux 3.0
- azl3 containerd2 2.0.0-9 on Azure Linux 3.0
- cbl2 cert-manager 1.11.2-22 on CBL Mariner 2.0
- cbl2 packer 1.9.5-13 on CBL Mariner 2.0
- azl3 telegraf 1.31.0-10 on Azure Linux 3.0
- cbl2 telegraf 1.29.4-16 on CBL Mariner 2.0
- cbl2 containerized-data-importer 1.55.0-23 on CBL Mariner 2.0
- cbl2 kubernetes 1.28.4-18 on CBL Mariner 2.0
- cbl2 skopeo 1.14.2-10 on CBL Mariner 2.0
- cbl2 rook 1.6.2-26 on CBL Mariner 2.0
- cbl2 moby-containerd-cc 1.7.7-11 on CBL Mariner 2.0
- cbl2 dcos-cli 1.2.0-21 on CBL Mariner 2.0
- cbl2 keda 2.4.0-29 on CBL-Mariner 2.0
- cbl2 cri-o 1.22.3-14 on CBL-Mariner 2.0
- cbl2 dcos-cli 1.2.0-20 on CBL Mariner 2.0
- cbl2 rook 1.6.2-25 on CBL Mariner 2.0
- cbl2 cri-o 1.22.3-12 on CBL Mariner 2.0
- cbl2 kubernetes 1.28.4-15 on CBL Mariner 2.0
Versions the vendor lists as fixed
- 1.14.4-4
- 2.6.1-21
- 0.37.0-2
- 0.0.2-20
- 1.12.15-2
- 2.7.5-2
- 1.57.0-13
- 2.0.0-6
- 1.11.2-19
- 1.9.5-9
- 1.31.0-8
- 1.29.4-12
- 1.55.0-23
- 1.28.4-15
- 1.14.2-10
- 1.6.2-25
- 1.7.7-11
- 1.2.0-20
- 2.4.0-27
- 1.22.3-12
- 1.6.26-10
- 1.9.5-6
- 2.14.1-3
- 1.7.13-7
What the vendor recommends
CBL-Mariner Releases
Review the complete instructions on the vendor's siteWhen this advisory changed
- Published by Microsoft Security Response Center
The publication date reported by the vendor.
- Updated by Microsoft Security Response Center
The vendor changed the advisory after it was first published.
- Added to SecurityAlert
We collected the advisory from the official source.
- Confirmed at the source
Our collector saw this advisory during a later source check.