VMware response to vulnerabilities (CVE-2023-42667, CVE-2023-49141, CVE-2024-24853, CVE-2024-24980, CVE-2024-25939) found on Tanzu virtual machines.
search cancel

VMware response to vulnerabilities (CVE-2023-42667, CVE-2023-49141, CVE-2024-24853, CVE-2024-24980, CVE-2024-25939) found on Tanzu virtual machines.

book

Article ID: 376664

calendar_today

Updated On:

Products

VMware Tanzu Application Service

Issue/Introduction

A vulnerability scan report reveals the following Common Vulnerabilities and Exposures (CVE's) related to USN-6967-1: Intel Microcode vulnerabilities.

  • CVE-2023-42667
  • CVE-2023-49141
  • CVE-2024-24853
  • CVE-2024-24980
  • CVE-2024-25939

These CVE's are related to hardware level (processors). TAS/TANZU stemcell(s) (Xenial Stemcells -- 621.x) could possibly be effected by this.

 

Resolution

Xenial Stemcells reached EOGS (end of general support) in April 2024 and no new stemcells are planned for Xenial.

The fix is included in the Jammy v1.572 stemcell.  

 

Additional Information

https://docs.vmware.com/en/Stemcells-for-VMware-Tanzu/services/release-notes/stemcells.html#621-line:~:text=ubuntu%2Djammy/v1.613-,1.572,-Release%20Date%3A%20September