Alibaba Security Advisories · May 2023 — Alibaba Security Advisories
5 advisories 49 CVEs 2 EXPLOITED

Alibaba Cloud Linux 2 advisories and cross-source Alibaba/Aliyun CVEs for 2023-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALINUX2-SA-2023:0021

ALINUX 2ExploitedCISA KEV listedMEDIUM2023-05-04

ALINUX2-SA-2023:0021: cloud-kernel bugfix, enhancement and security update (Important)

CVEs:CVE-2020-14331CVE-2020-25670CVE-2020-25671CVE-2020-25672CVE-2021-3759CVE-2021-3923CVE-2022-1975CVE-2022-20566CVE-2022-2964CVE-2022-3107CVE-2022-3108CVE-2022-3111CVE-2022-3239CVE-2022-33741CVE-2022-3524CVE-2022-3535CVE-2022-3564CVE-2022-3566CVE-2022-41218CVE-2022-4129CVE-2022-41858CVE-2022-42328CVE-2022-42703CVE-2022-42896CVE-2022-45934CVE-2022-4662CVE-2022-47929CVE-2023-0030CVE-2023-0266CVE-2023-0394CVE-2023-0461CVE-2023-0590CVE-2023-0597CVE-2023-1074CVE-2023-1095CVE-2023-1118CVE-2023-1281CVE-2023-1611CVE-2023-1838CVE-2023-23454CVE-2023-23455CVE-2023-23559CVE-2023-26545CVE-2023-28772

Affected products

ProductStatusVendorPackageEcosystem
kernel affected Alibaba Cloud kernel —
Upstream advisory

ALINUX2-SA-2023:0025

ALINUX 2ExploitedVulnCheck KEV listedHIGH2023-05-25

ALINUX2-SA-2023:0025: cloud-kernel bugfix, enhancement and security update (Important)

CVEs:CVE-2023-32233

Affected products

ProductStatusVendorPackageEcosystem
kernel affected Alibaba Cloud kernel —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.