Patch Day month
September 2025 vulnerabilities
A server-rendered hunting trail for September 2025: 401 returned patch records across 1 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.
401all patches
15critical
0exploitation detected
2in CISA KEV
109tracked here
Microsoft 401
Page 1 of 3 · records 1–200 of 401
Microsoft Security Response Center
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-41244 ↗2026-07-24azl3 open-vm-tools 12.3.5-2 on Azure Linux 3.0ImportantOut-of-band8%CISA KEVVulnCheckENISAVMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
CVE-2025-39806 ↗2026-01-18cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-band—HID: multitouch: fix slab out-of-bounds access in mt_report_fixup()
CVE-2025-39782 ↗2026-01-18cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—jbd2: prevent softlockup in jbd2_log_do_checkpoint()
CVE-2025-39770 ↗2026-01-18cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-band—net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM
CVE-2022-50327 ↗2026-01-18cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value
CVE-2025-39734 ↗2026-01-13cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—Revert "fs/ntfs3: Replace inode_trylock with inode_lock"
CVE-2025-38693 ↗2026-01-11cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar
CVE-2025-38683 ↗2026-01-10cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—hv_netvsc: Fix panic during namespace deletion with VF
CVE-2024-58241 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—Bluetooth: hci_core: Disable works on hci_unregister_dev
CVE-2023-53447 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—f2fs: don't reset unchangable mount option in f2fs_remount()
CVE-2023-53376 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—scsi: mpi3mr: Use number of bits to manage bitmap sizes
CVE-2023-53371 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—net/mlx5e: fix memory leak in mlx5e_fs_tt_redirect_any_create
CVE-2023-53370 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—drm/amdgpu: fix memory leak in mes self test
CVE-2022-50418 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—wifi: ath11k: mhi: fix potential memory leak in ath11k_mhi_register()
CVE-2022-50393 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—drm/amdgpu: SDMA update use unlocked iterator
CVE-2022-50390 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—drm/ttm: fix undefined behavior in bit shift for TTM_TT_FLAG_PRIV_POPULATED
CVE-2023-53401 ↗2025-12-13cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—mm: kmem: fix a NULL pointer dereference in obj_stock_flush_required()
CVE-2023-53387 ↗2025-12-13cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—scsi: ufs: core: Fix device management cmd timeout flow
CVE-2023-53383 ↗2025-12-13cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—irqchip/gicv3: Workaround for NVIDIA erratum T241-FABRIC-4
CVE-2023-53367 ↗2025-12-13cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—accel/habanalabs: fix mem leak in capture user mappings
CVE-2023-53366 ↗2025-12-13cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-band—block: be a bit more careful in checking for NULL bdev while polling
CVE-2023-53438 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—x86/MCE: Always save CS register on AMD Zen IF Poison errors
CVE-2023-53429 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—btrfs: don't check PageError in __extent_writepage
CVE-2023-53424 ↗2025-12-12cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-band—clk: mediatek: fix of_iomap memory leak
CVE-2023-53421 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—blk-cgroup: Reinit blkg_iostat_set after clearing in blkcg_reset_stats()
CVE-2023-53410 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—USB: ULPI: fix memory leak with using debugfs_lookup()
CVE-2023-53355 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—staging: pi433: fix memory leak with using debugfs_lookup()
CVE-2023-53353 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—accel/habanalabs: postpone mem_mgr IDR destruction to hpriv_release()
CVE-2023-53348 ↗2025-12-12cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—btrfs: fix deadlock when aborting transaction during relocation with scrub
CVE-2023-53347 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—net/mlx5: Handle pairing of E-switch via uplink un/load APIs
CVE-2022-50407 ↗2025-12-12cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—crypto: hisilicon/qm - increase the memory of local variables
CVE-2022-50406 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-band—iomap: iomap: fix memory corruption when recording errors during writeback
CVE-2023-53332 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—genirq/ipi: Fix NULL pointer deref in irq_data_get_affinity_mask()
CVE-2023-53323 ↗2025-12-12cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—ext2/dax: Fix ext2_setsize when len is page aligned
CVE-2022-50357 ↗2025-12-11cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—usb: dwc3: core: fix some leaks in probe
CVE-2023-53231 ↗2025-12-06cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—erofs: Fix detection of atomic context
CVE-2023-53209 ↗2025-12-06cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—wifi: mac80211_hwsim: Fix possible NULL dereference
CVE-2022-50304 ↗2025-12-06cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—mtd: core: fix possible resource leak in init_mtd()
CVE-2022-50303 ↗2025-12-06cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—drm/amdkfd: Fix double release compute pasid
CVE-2023-53254 ↗2025-12-05cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-band—cacheinfo: Fix shared_cpu_map to handle shared caches at different levels
CVE-2023-53248 ↗2025-12-05cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—drm/amdgpu: install stub fence into potential unused fence pointers
CVE-2023-53247 ↗2025-12-05cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—btrfs: set_page_extent_mapped after read_folio in btrfs_cont_expand
CVE-2023-53240 ↗2025-12-05cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—xsk: check IFF_UP earlier in Tx path
CVE-2023-53221 ↗2025-12-05cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-band—bpf: Fix memleak due to fentry attach failure
CVE-2023-53218 ↗2025-12-05cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-band—rxrpc: Make it so that a waiting process can be aborted
CVE-2022-50316 ↗2025-12-05cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—orangefs: Fix kmemleak in orangefs_sysfs_init()
CVE-2023-53292 ↗2025-12-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—blk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_none
CVE-2023-53261 ↗2025-12-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—coresight: Fix memory leak in acpi_buffer->pointer
CVE-2022-50266 ↗2025-12-04cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—kprobes: Fix check for probe enabled in kill_kprobe()
CVE-2023-53187 ↗2025-12-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-band—btrfs: fix use-after-free of new block group that became unused
CVE-2023-53178 ↗2025-12-03cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-band—mm: fix zswap writeback race condition
CVE-2022-50350 ↗2025-12-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—scsi: target: iscsi: Fix a race condition between login_work and the login thread
CVE-2025-4953 ↗2025-11-29azl3 skopeo 1.14.4-6 on Azure Linux 3.0ModerateOut-of-band—Podman: build context bind mount
CVE-2023-53149 ↗2025-11-27cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—ext4: avoid deadlock in fs reclaim with page writeback
CVE-2022-50260 ↗2025-11-27cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—drm/msm: Make .remove and .shutdown HW shutdown consistent
CVE-2022-50256 ↗2025-11-27cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—drm/meson: remove drm bridges at aggregate driver unbind time
CVE-2023-53152 ↗2025-11-26cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—drm/amdgpu: fix calltrace warning in amddrm_buddy_fini
CVE-2022-50236 ↗2025-11-26cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—iommu/mediatek: Fix crash on isr after kexec()
CVE-2025-55554 ↗2025-10-05cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-band—pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
CVE-2025-55552 ↗2025-10-05azl3 pytorch 2.2.2-7 on Azure Linux 3.0ImportantOut-of-band—pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
CVE-2025-55551 ↗2025-10-05azl3 pytorch 2.2.2-7 on Azure Linux 3.0ImportantOut-of-band—An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
CVE-2025-9648 ↗2025-10-03azl3 ceph 18.2.2-10 on Azure Linux 3.0ImportantOut-of-band—Denial of Service in CivetWeb
CVE-2025-9230 ↗2025-10-02azl3 openssl 3.3.3-3 on Azure Linux 3.0ImportantOut-of-band—Out-of-bounds read & write in RFC 3211 KEK Unwrap
CVE-2025-9232 ↗2025-10-02azl3 openssl 3.3.3-3 on Azure Linux 3.0ModerateOut-of-band—Out-of-bounds read in HTTP client no_proxy handling
CVE-2025-9231 ↗2025-10-02azl3 openssl 3.3.3-3 on Azure Linux 3.0ModerateOut-of-band—Timing side-channel in SM2 algorithm on 64 bit ARM
CVE-2025-55558 ↗2025-10-02cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-band—A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a Denial of Service (DoS).
CVE-2025-55560 ↗2025-10-02azl3 pytorch 2.2.2-7 on Azure Linux 3.0ModerateOut-of-band—An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.
CVE-2025-46150 ↗2025-10-02azl3 pytorch 2.2.2-7 on Azure Linux 3.0ModerateOut-of-band—In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
CVE-2025-55557 ↗2025-10-02cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ImportantOut-of-band—A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
CVE-2025-46149 ↗2025-10-02cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-band—In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
CVE-2025-46153 ↗2025-10-02azl3 pytorch 2.2.2-7 on Azure Linux 3.0ModerateOut-of-band—PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True.
CVE-2025-11083 ↗2025-10-02azl3 binutils 2.41-7 on Azure Linux 3.0ModerateOut-of-band—GNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflow
CVE-2025-11082 ↗2025-10-02cbl2 crash 8.0.1-4 on CBL Mariner 2.0ModerateOut-of-band—GNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflow
CVE-2025-11081 ↗2025-10-02cbl2 binutils 2.37-16 on CBL Mariner 2.0ModerateOut-of-band—GNU Binutils objdump.c dump_dwarf_section out-of-bounds
CVE-2025-55553 ↗2025-10-01cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ImportantOut-of-band—A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
CVE-2025-46148 ↗2025-09-29cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-band—In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.
CVE-2025-46152 ↗2025-09-29cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-band—In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.
CVE-2025-10911 ↗2025-09-29cbl2 libxslt 1.1.34-8 on CBL Mariner 2.0ModerateOut-of-band—Libxslt: use-after-free with key data stored cross-rvt
CVE-2025-11021 ↗2025-09-29cbl2 libsoup 3.0.4-9 on CBL Mariner 2.0ImportantOut-of-band—Libsoup: out-of-bounds read in cookie date handling of libsoup http library
CVE-2025-60018 ↗2025-09-29azl3 glib-networking 2.78.0-1 on Azure Linux 3.0ModerateOut-of-band—Glib-networking: out of bound reads on glib-networking through tls/openssl/gtlscertificate-openssl.c via "g_tls_certificate_openssl_get_property()"
CVE-2025-60019 ↗2025-09-29cbl2 glib-networking 2.70.0-1 on CBL Mariner 2.0LowOut-of-band—Glib-networking: uninitialized memory dereferences on glib-networking through glib-networking/tls/openssl/gtlsbio.c via g_tls_bio_new_from_iostream() and g_tls_bio_new_from_datagram_based()
CVE-2025-59362 ↗2025-09-28azl3 squid 6.13-1 on Azure Linux 3.0ImportantOut-of-band—Squid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c.
CVE-2025-59825 ↗2025-09-27azl3 kata-containers-cc 3.15.0.aks0-6 on Azure Linux 3.0ModerateOut-of-band—astral-tokio-tar has a path traversal in tar extraction
CVE-2025-9900 ↗2025-09-27cbl2 libtiff 4.6.0-8 on CBL Mariner 2.0ImportantOut-of-band—Libtiff: libtiff write-what-where
CVE-2025-8869 ↗2025-09-27azl3 python-pip 24.2-3 on Azure Linux 3.0ModerateOut-of-band—Fallback tar extraction in pip doesn't check symbolic links point to extraction directory
CVE-2025-58354 ↗2025-09-25azl3 kata-containers 3.19.1.kata2-1 on Azure Linux 3.0ModerateOut-of-band—Kata Containers coco-tdx malicious host can circumvent initdata verification
CVE-2025-10892 ↗2025-09-25Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-10892 Integer overflow in V8
CVE-2025-10891 ↗2025-09-25Microsoft Edge (Chromium-based)N/AOut-of-band7%Chromium: CVE-2025-10891 Integer overflow in V8
CVE-2025-10890 ↗2025-09-25Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-10890 Side-channel information leakage in V8
CVE-2025-59251 ↗2025-09-25Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-39880 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—libceph: fix invalid accesses to ceph_connection_v1_info
CVE-2025-39876 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable()
CVE-2025-39883 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory
CVE-2025-39869 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—dmaengine: ti: edma: Fix memory allocation size for queue_priority_map
CVE-2025-39873 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—can: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB
CVE-2025-39867 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—netfilter: nft_set_pipapo: fix null deref for empty set
CVE-2025-39886 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—bpf: Tell memcg to use allow_spinning=false path in bpf_timer_init()
CVE-2025-39877 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—mm/damon/sysfs: fix use-after-free in state_show()
CVE-2025-39881 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—kernfs: Fix UAF in polling when open file is released
CVE-2025-39885 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—ocfs2: fix recursive semaphore deadlock in fiemap call
CVE-2025-10824 ↗2025-09-24azl3 fio 3.37-2 on Azure Linux 3.0ModerateOut-of-band—axboe fio init.c __parse_jobs_ini use after free
CVE-2025-10823 ↗2025-09-24azl3 fio 3.37-2 on Azure Linux 3.0ModerateOut-of-band—axboe fio options.c str_buffer_pattern_cb null pointer dereference
CVE-2025-55322 ↗2025-09-24OmniParserImportantOut-of-band0%OmniParser Remote Code Execution Vulnerability
CVE-2025-58767 ↗2025-09-21azl3 ruby 3.3.5-6 on Azure Linux 3.0LowOut-of-band—REXML has a DoS condition when parsing malformed XML file
CVE-2025-58749 ↗2025-09-21cbl2 fluent-bit 3.0.6-4 on CBL Mariner 2.0LowOut-of-band—WAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT mode
CVE-2025-39838 ↗2025-09-21azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—cifs: prevent NULL pointer dereference in UTF16 conversion
CVE-2025-39846 ↗2025-09-21cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region()
CVE-2025-39848 ↗2025-09-21azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-band—ax25: properly unshare skbs in ax25_kiss_rcv()
CVE-2025-39866 ↗2025-09-21azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—fs: writeback: fix use-after-free in __mark_inode_dirty()
CVE-2025-39864 ↗2025-09-21azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—wifi: cfg80211: fix use-after-free in cmp_bss()
CVE-2025-39861 ↗2025-09-21azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-band—Bluetooth: vhci: Prevent use-after-free by removing debugfs files early
CVE-2025-39859 ↗2025-09-21azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-band—ptp: ocp: fix use-after-free bugs causing by ptp_ocp_watchdog
CVE-2025-39850 ↗2025-09-21azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-band—vxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop objects
CVE-2025-39863 ↗2025-09-21cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-band—wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work
CVE-2025-39860 ↗2025-09-21azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen()
CVE-2025-39844 ↗2025-09-21cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—mm: move page table sync declarations to linux/pgtable.h
CVE-2025-39847 ↗2025-09-21cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—ppp: fix memory leak in pad_compress_skb
CVE-2025-39865 ↗2025-09-21azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—tee: fix NULL pointer dereference in tee_shm_put
CVE-2025-39862 ↗2025-09-21azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—wifi: mt76: mt7915: fix list corruption after hardware restart
CVE-2025-39841 ↗2025-09-21cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-band—scsi: lpfc: Fix buffer free/clear order in deferred receive path
CVE-2025-39851 ↗2025-09-21azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-band—vxlan: Fix NPD when refreshing an FDB entry with a nexthop object
CVE-2025-39857 ↗2025-09-21azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-band—net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync()
CVE-2025-39842 ↗2025-09-21azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—ocfs2: prevent release journal inode after journal shutdown
CVE-2025-39845 ↗2025-09-21azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-band—x86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings()
CVE-2025-39853 ↗2025-09-21cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-band—i40e: Fix potential invalid access when MAC list is empty
CVE-2025-39849 ↗2025-09-21azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-band—wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result()
CVE-2025-39843 ↗2025-09-21azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—mm: slub: avoid wake up kswapd in set_track_prepare
CVE-2025-39839 ↗2025-09-21azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-band—batman-adv: fix OOB read/write in network-coding decode
CVE-2025-39824 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—HID: asus: fix UAF via HID_CLAIMED_INPUT validation
CVE-2025-39823 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—KVM: x86: use array_index_nospec with indices that come from guest
CVE-2025-39833 ↗2025-09-20azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-band—mISDN: hfcpci: Fix warning when deleting uninitialized timer
CVE-2025-39812 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—sctp: initialize more fields in sctp_v6_from_sk()
CVE-2025-39808 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version()
CVE-2025-39832 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—net/mlx5: Fix lockdep assertion on sync reset unload event
CVE-2025-39805 ↗2025-09-20azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—net: macb: fix unregister_netdev call order in macb_remove()
CVE-2025-39829 ↗2025-09-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—trace/fgraph: Fix the warning caused by missing unregister notifier
CVE-2025-39817 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
CVE-2025-39827 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—net: rose: include node references in rose_neigh refcount
CVE-2025-39828 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control().
CVE-2025-39825 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—smb: client: fix race with concurrent opens in rename(2)
CVE-2025-39813 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—ftrace: Fix potential warning in trace_printk_seq during ftrace_dump
CVE-2025-39835 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—xfs: do not propagate ENODATA disk errors into xattr code
CVE-2025-39819 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—fs/smb: Fix inconsistent refcnt update
CVE-2025-9906 ↗2025-09-20azl3 keras 3.3.3-3 on Azure Linux 3.0ImportantOut-of-band—Arbitrary Code execution in Keras Safe Mode
CVE-2025-9905 ↗2025-09-20azl3 keras 3.3.3-3 on Azure Linux 3.0ImportantOut-of-band—Arbitary Code execution in Keras load_model()
CVE-2022-50380 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—mm: /proc/pid/smaps_rollup: fix no vma's null-deref
CVE-2025-39826 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—net: rose: convert 'use' field to refcount_t
CVE-2025-39810 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—bnxt_en: Fix memory corruption when FW resources change during ifdown
CVE-2025-10501 ↗2025-09-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-10501 Use after free in WebRTC
CVE-2025-10502 ↗2025-09-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-10502 Heap buffer overflow in ANGLE
CVE-2025-10500 ↗2025-09-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-10500 Use after free in Dawn
CVE-2025-10585 ↗2025-09-19Microsoft Edge (Chromium-based)N/AOut-of-band5%CISA KEVVulnCheckENISAChromium: CVE-2025-10585 Type Confusion in V8
CVE-2025-59215 ↗2025-09-18Windows Server 2025 (Server Core installation)ImportantOut-of-band0%KB5065426KB5065474Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-59216 ↗2025-09-18Windows Server 2025 (Server Core installation)ImportantOut-of-band0%KB5065426KB5065474Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-59220 ↗2025-09-18Windows Server 2022ImportantOut-of-band0%KB5065306KB5065425Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2025-58754 ↗2025-09-16azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-band—Axios is vulnerable to DoS attack through lack of data size check
CVE-2025-39794 ↗2025-09-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—ARM: tegra: Use I/O memcpy to write to IRAM
CVE-2025-39799 ↗2025-09-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-band—ACPI: processor: perflib: Move problematic pr->performance check
CVE-2025-39801 ↗2025-09-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—usb: dwc3: Remove WARN_ON for device endpoint command timeouts
CVE-2025-39800 ↗2025-09-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—btrfs: abort transaction on unexpected eb generation at btrfs_copy_root()
CVE-2025-39795 ↗2025-09-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—block: avoid possible overflow for chunk_sectors check in blk_stack_limits()
CVE-2025-39797 ↗2025-09-16cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—xfrm: Duplicate SPI Handling
CVE-2025-39798 ↗2025-09-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—NFS: Fix the setting of capabilities when automounting a new filesystem
CVE-2025-59375 ↗2025-09-16cbl2 expat 2.6.4-2 on CBL Mariner 2.0ModerateOut-of-band—libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
CVE-2025-47967 ↗2025-09-16Microsoft Edge (Chromium-based)LowOut-of-band0%Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2025-49728 ↗2025-09-16Microsoft PC ManagerImportantOut-of-band0%Microsoft PC Manager Security Feature Bypass Vulnerability
CVE-2025-48040 ↗2025-09-13cbl2 erlang 25.3.2.21-2 on CBL Mariner 2.0ModerateOut-of-band—Malicious Key Exchange Messages may Lead to Excessive Resource Consumption
CVE-2025-9086 ↗2025-09-13azl3 curl 8.11.1-3 on Azure Linux 3.0ModerateOut-of-band—Out of bounds read for cookie path
CVE-2025-39744 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—rcu: Fix rcu_read_unlock() deadloop due to IRQ work
CVE-2025-39737 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup()
CVE-2025-39776 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—mm/debug_vm_pgtable: clear page table entries at destroy_args()
CVE-2025-39738 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—btrfs: do not allow relocation of partially dropped subvolumes
CVE-2025-39772 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—drm/hisilicon/hibmc: fix the hibmc loaded failed bug
CVE-2025-40300 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—x86/vmscape: Add conditional IBPB mitigation
CVE-2025-39790 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—bus: mhi: host: Detect events pointing to unexpected TREs
CVE-2025-39766 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit
CVE-2025-39757 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—ALSA: usb-audio: Validate UAC3 cluster segment descriptors
CVE-2025-39743 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-band—jfs: truncate good inode pages when hard link is 0
CVE-2025-39742 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask()
CVE-2025-39761 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—wifi: ath12k: Decrement TID on RX peer frag setup error handling
CVE-2025-39763 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—ACPI: APEI: send SIGBUS to current task if synchronous memory error not recovered
CVE-2025-39752 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—ARM: rockchip: fix kernel hang during smp initialization
CVE-2025-39787 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—soc: qcom: mdt_loader: Ensure we don't read past the ELF header
CVE-2025-39748 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—bpf: Forget ranges when refining tnum after JSET
CVE-2025-39759 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—btrfs: qgroup: fix race between quota disable and quota rescan ioctl
CVE-2025-39789 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—crypto: x86/aegis - Add missing error checks
CVE-2025-39747 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—drm/msm: Add error handling for krealloc in metadata setup
CVE-2025-39751 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control
CVE-2025-39767 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—LoongArch: Optimize module load time by optimizing PLT/GOT counting
CVE-2025-39746 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—wifi: ath10k: shutdown driver when hardware is unreliable
CVE-2025-39750 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—wifi: ath12k: Correct tid cleanup when tid setup fails
CVE-2025-39773 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—net: bridge: fix soft lockup in br_multicast_query_expired()
CVE-2025-39739 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—iommu/arm-smmu-qcom: Add SM6115 MDSS compatible
CVE-2025-39762 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—drm/amd/display: add null check
CVE-2025-39754 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—mm/smaps: fix race between smaps_hugetlb_range and migration
CVE-2025-39736 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock
CVE-2025-39779 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—btrfs: subpage: keep TOWRITE tag until folio is cleaned
CVE-2025-39749 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—rcu: Protect ->defer_qs_iw_pending from data race
CVE-2025-39753 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—gfs2: Set .migrate_folio in gfs2_{rgrp,meta}_aops
CVE-2025-39764 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—netfilter: ctnetlink: remove refcounting in expectation dumpers
The next page could not be added in place. The ordinary page link remains available; try it again to navigate normally.