Microsoft’s statement that “Azure Linux includes this open‑source library and is therefore potentially affected” is accurate as a product‑level attestation, but it is not a categorical guarantee that no other Microsoft product can or does include the same vulnerable Linux kernel code.
Background...
A recently published Linux-kernel vulnerability, tracked as CVE-2025-22108, patches an out-of-range handling bug in the Broadcom NetXtreme driver (bnxt_en) that can corrupt transmit descriptors and lead to packet transmission timeouts; Microsoft’s advisory currently lists Azure Linux as the only...