Azure
CVE-2019-0804 — Azure Linux Agent Information Disclosure Vulnerability
Executive Summary
An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks. An authenticated attacker who successfully exploited this vulnerability could view data in swap that is normally hidden. None of the Azure endorsed distros are vulnerable to this issue by default, but this can occur on customer customized or modified images when swapfile is created by the Azure linux agent and python3 is enabled as the default python version. This update addresses this vulnerability by preventing how the swap information is accessed.
Overview
Important
MS Severity
Not Exploited
MS Exploit Status
Not Found
MS Exploit Likelihood
EPSS Score
0.05255
probability of exploitation in the next 30 days
0.91478 percentile - updated 2026-06-20
View on FIRST.org
Affected Products
1 affected product
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Azure Linux Guest Agent | Release Notes (Security Update) |
Important | Information Disclosure | Maybe |
Patches
1 patch
| Article | Type | Restart |
|---|---|---|
Release Notes |
Security Update | Maybe |
Known Exploits
No known exploits have been linked for this CVE yet. When available, exploit references will be sourced from public repositories and may be unverified, incomplete, or non-functional. Always review code carefully before use in any environment.
Acknowledgments
Francis McBratney with Destinatech Limited
References
On This Page