OCImendby CloudTrace

Image reports › ocimend.io/mcr.microsoft.com/azurelinux/base/core

ocimend.io/mcr.microsoft.com/azurelinux/base/core — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/mcr.microsoft.com/azurelinux/base/core · Microsoft Azure Linux 3.0

Latest: ocimend.io/mcr.microsoft.com/azurelinux/base/core:3.0.20260909-fips · checked 2026-09-27

Not FIPS-ready

No. core:3.0.20260909-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade C: 30 known vulnerabilities

30 known vulnerabilities in 6 packages (6 high); 30 can be fixed by upgrading 6 packages. Start with libpcre2-16-0: upgrade 10.42-3.azl3 → 10.48-1 (fixes 5). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full report → Get a fixed image Get a FIPS image Scan your own image

Fix plan for 3.0.20260909-fips

PackageInstalledUpgrade toFixes
libpcre2-16-010.42-3.azl310.48-15
libpcre2-32-010.42-3.azl310.48-15
libpcre2-8-010.42-3.azl310.48-15
libpcre2-posix210.42-3.azl310.48-15
pcre210.42-3.azl310.48-15
pcre2-tools10.42-3.azl310.48-15

Critical, high and exploited vulnerabilities in 3.0.20260909-fips

SeverityIDPackageFixed inSummary
highAZL-99726libpcre2-16-0 10.42-3.azl310.48-1CVE-2026-86145 affecting package pcre2 for versions less than 10.48-1
highAZL-99726libpcre2-32-0 10.42-3.azl310.48-1CVE-2026-86145 affecting package pcre2 for versions less than 10.48-1
highAZL-99726libpcre2-8-0 10.42-3.azl310.48-1CVE-2026-86145 affecting package pcre2 for versions less than 10.48-1
highAZL-99726libpcre2-posix2 10.42-3.azl310.48-1CVE-2026-86145 affecting package pcre2 for versions less than 10.48-1
highAZL-99726pcre2 10.42-3.azl310.48-1CVE-2026-86145 affecting package pcre2 for versions less than 10.48-1
highAZL-99726pcre2-tools 10.42-3.azl310.48-1CVE-2026-86145 affecting package pcre2 for versions less than 10.48-1

All checked tags

TagFIPSKnown vulnerabilitiesChecked
3.0.20260909-fipsNot FIPS-readyC 302026-09-27ReportFix