Azure / Azure/custom-script-extension-linux
CVE-2025-68121 detected on CustomScriptExtension 2.1.19 on AzureLinux V3
- Dominant language
- Go
- Stars
- 113
- Forks
- 46
- Avg merge
- 6d 3h
- Merged PRs (30d)
- 3
Description
CRI 21000001809436
security scanning tool (Orca) identified CVE-2025-68121 on AKS nodes. The vulnerability was detected in the following binaries:
/var/lib/waagent/Microsoft.Azure.Extensions.CustomScript-2.1.19/bin/custom-script-extension
/var/lib/waagent/Microsoft.Azure.Extensions.CustomScript-2.1.19/bin/custom-script-extension-arm64
[CVE Record: CVE-2025-68121](https://www.cve.org/CVERecord?id=CVE-2025-68121)
CSE 2.1.19 seems to be there [CSE 2.1.19 by norakoiralamsft · Pull Request #256 · Azure/custom-script-extension-linux](https://github.com/Azure/custom-script-extension-linux/pull/256)
And it seems to have golang.org/x/crypto version v0.45.0
[golang.org/x/crypto version update by norakoiralamsft · Pull Request #245 · Azure/custom-script-extension-linux](https://github.com/Azure/custom-script-extension-linux/pull/245/changes)
So I'm not sure of the [CVE Record: CVE-2025-68121](https://www.cve.org/CVERecord?id=CVE-2025-68121) which says :
Vendor = Go standard library
Product = crypto/tls
Versions 3 Total
Default Status: unaffected
affected
affectedfrom 0before 1.24.13
affectedfrom 1.25.0-0before 1.25.7
affectedfrom 1.26.0-rc.1before 1.26.0-rc.3
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.