CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-84784: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 (exact versions not specified); +17 more affected products

CVE-2026-84784 affects azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0. CVSS 3.1 base score 7.5 (Microsoft Security Response Center). EPSS 0.00403 (percentile 0.32289), scored 2026-10-05. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0.

Affected technology

azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft

azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft

azl3 openssl 3.3.7-6 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft

azl3 openvmm 0.1.0-1 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft

azl3 rust 1.75.0-31 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft

azl3 rust 1.96.1-2 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft

libcrypto3 · Exact affected versions not specified by the source
Vendor not specified by the source

libssl3 · Exact affected versions not specified by the source
Vendor not specified by the source

openssl · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-dbg · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-dev · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-doc · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-engine-afalg · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-engine-capi · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-engine-loader-attic · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-engine-padlock · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-fips-config · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-provider-legacy · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (Microsoft Security Response Center, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Microsoft Security Response Center’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

Product
azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0
CCR priority
30.1 /100 (P4)
CVSS 3.1
7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · Microsoft Security Response Center
EPSS
0.00403 · percentile 0.32289 · 2026-10-05
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-84784.html