Azure HIGH CVE identified for Linux VMs caused by CVE-2021-38649
search cancel

Azure HIGH CVE identified for Linux VMs caused by CVE-2021-38649

book

Article ID: 298309

calendar_today

Updated On:

Products

VMware Tanzu Application Service for VMs

Issue/Introduction

Your security team was notified that a HIGH CVE had been identified, making their PCF VMs vulnerable.

Will a new stemcell be available to patch this CVE?

For more information on this CVE, refer to CVE-2021-38649 - Security Update Guide - Microsoft - Open Management Infrastructure Elevation of Privilege Vulnerability.


Environment

Product Version: 2.11

Resolution

CVE-2021-38649 describes a vulnerability in the omiagent used on Azure. It is not a part of Tanzu stemcells.

However, a customer can update their VMs with the latest Tanzu Azure stemcell to trigger side-loading of the patched omiagent from Azure.

For more information from the vendor Microsoft, see this bulletin: