Microsoft Azure Linux azl3 bug can run code

Published September 11, 2026

Microsoft Azure Linux azl3 has a CERT-Bund advisory for 62 vulnerabilities. A local attacker can exploit multiple vulnerabilities in the Linux kernel to cause a denial of service, disclose information, bypass security restrictions, or potentially execute arbitrary code.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in azl3Fix recorded 3 days ago
Affected versions
affected versions
Affects
Microsoft Azure Linux azl3
Exploited
Not confirmedNo confirmation recorded

How it works

A local attacker can exploit multiple vulnerabilities in the Linux kernel to cause a denial of service, disclose information, bypass security restrictions, or potentially execute arbitrary code.

What to do

Check your Microsoft Azure Linux azl3 version. If it is older than azl3, this advisory applies.

Update Microsoft Azure Linux azl3 to azl3 or newer.

Technical details

CERT-Bund describes Microsoft Azure Linux azl3 as Der Kernel stellt den Kern des Linux Betriebssystems dar. A local attacker can exploit multiple vulnerabilities in the Linux kernel to cause a denial of service, disclose information, bypass security restrictions, or potentially execute arbitrary code. The advisory tracks CVE-2026-43059, CVE-2026-43060, CVE-2026-43061, CVE-2026-43062, CVE-2026-43063, CVE-2026-43064, CVE-2026-43065, CVE-2026-43066.

In CERT-Bund's CSAF data, the fixed version is azl3. Affected operating systems listed by CERT-Bund: Linux.

References