CYBERSECURITYTRACKER
TRACKING3,612 stories653 vuln stories
Patch Day month

October 2025 vulnerabilities

A server-rendered hunting trail for October 2025: 427 returned patch records across 1 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.

427all patches
41critical
3exploitation detected
4in CISA KEV
223tracked here
Microsoft 427

Page 1 of 3 · records 1–200 of 427

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-40082 ↗2026-02-28azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandhfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
CVE-2023-53543 ↗2026-02-25cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandvdpa: Add max vqp attr to vdpa_nl_policy for nlattr length check
CVE-2023-53642 ↗2026-02-18azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandx86: fix clear_user_rep_good() exception handling annotation
CVE-2023-53466 ↗2026-01-21cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandwifi: mt76: mt7915: fix memory leak in mt7915_mcu_exit
CVE-2025-39894 ↗2026-01-18cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnetfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm
CVE-2023-53460 ↗2026-01-18cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandwifi: rtw88: fix memory leak in rtw_usb_probe()
CVE-2022-50467 ↗2026-01-18cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandscsi: lpfc: Fix null ndlp ptr dereference in abnormal exit path for GFT_ID
CVE-2022-50464 ↗2026-01-18cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandmt76: mt7915: Fix PCI device refcount leak in mt7915_pci_init_hif2()
CVE-2022-50461 ↗2026-01-18cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: ethernet: ti: am65-cpsw: Fix PM runtime leakage in am65_cpsw_nuss_ndo_slave_open()
CVE-2025-12105 ↗2025-12-21azl3 libsoup 3.4.4-10 on Azure Linux 3.0ImportantOut-of-bandLibsoup: heap use-after-free in libsoup message queue handling during http/2 read completion
CVE-2025-11494 ↗2025-11-29cbl2 binutils 2.37-19 on CBL Mariner 2.0ModerateOut-of-bandGNU Binutils Linker elfxx-x86.c _bfd_x86_elf_late_size_sections out-of-bounds
CVE-2025-11731 ↗2025-11-21cbl2 libxslt 1.1.34-8 on CBL Mariner 2.0LowOut-of-bandLibxslt: type confusion in exsltfuncresultcompfunction of libxslt
CVE-2025-12464 ↗2025-11-05azl3 qemu 8.2.0-25 on Azure Linux 3.0ModerateOut-of-bandQemu-kvm: stack buffer overflow in e1000 device via short frames in loopback mode
CVE-2025-6075 ↗2025-11-05azl3 python3 3.12.9-5 on Azure Linux 3.0LowOut-of-bandQuadratic complexity in os.path.expandvars() with user-controlled template
CVE-2025-61099 ↗2025-11-05cbl2 frr 8.5.5-4 on CBL Mariner 2.0ImportantOut-of-bandFRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet.
CVE-2025-62230 ↗2025-11-02azl3 xorg-x11-server-Xwayland 24.1.6-2 on Azure Linux 3.0ImportantOut-of-bandXorg: xwayland: use-after-free in xkb client resource removal
CVE-2025-61104 ↗2025-11-02cbl2 frr 8.5.5-3 on CBL Mariner 2.0ImportantOut-of-bandFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-61100 ↗2025-11-02cbl2 frr 8.5.5-3 on CBL Mariner 2.0ImportantOut-of-bandFRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions.
CVE-2025-61101 ↗2025-11-02cbl2 frr 8.5.5-3 on CBL Mariner 2.0ImportantOut-of-bandFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-40106 ↗2025-11-01azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandcomedi: fix divide-by-zero in comedi_buf_munge()
CVE-2025-12060 ↗2025-11-01azl3 keras 3.3.3-4 on Azure Linux 3.0ImportantOut-of-bandKeras keras.utils.get_file Utility Path Traversal Vulnerability
CVE-2025-12441 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12441 Out of bounds read in V8
CVE-2025-12440 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12440 Inappropriate implementation in Autofill
CVE-2025-12439 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12439 Inappropriate implementation in App-Bound Encryption
CVE-2025-12438 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12438 Use after free in Ozone
CVE-2025-12437 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12437 Use after free in PageInfo
CVE-2025-12436 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12436 Policy bypass in Extensions
CVE-2025-12435 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12435 Incorrect security UI in Omnibox
CVE-2025-12434 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12434 Race in Storage
CVE-2025-12036 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band4%Chromium: CVE-2025-12036 Inappropriate implementation in V8
CVE-2025-12433 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12433 Inappropriate implementation in V8
CVE-2025-12432 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12432 Race in V8
CVE-2025-12431 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12431 Inappropriate implementation in Extensions
CVE-2025-12430 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12430 Object lifecycle issue in Media
CVE-2025-12429 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12429 Inappropriate implementation in V8
CVE-2025-12428 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band7%Chromium: CVE-2025-12428 Type Confusion in V8
CVE-2025-12447 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12447 Incorrect security UI in Omnibox
CVE-2025-12446 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12446 Incorrect security UI in SplitView
CVE-2025-12444 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12444 Incorrect security UI in Fullscreen UI
CVE-2025-12445 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12445 Policy bypass in Extensions
CVE-2025-12443 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12433 Inappropriate implementation in V8
CVE-2025-60711 ↗2025-10-31Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-62229 ↗2025-10-31azl3 xorg-x11-server-Xwayland 24.1.6-2 on Azure Linux 3.0ImportantOut-of-bandXorg: xmayland: use-after-free in xpresentnotify structure creation
CVE-2025-62231 ↗2025-10-31azl3 xorg-x11-server-Xwayland 24.1.6-2 on Azure Linux 3.0ImportantOut-of-bandXorg: xmayland: value overflow in xkbsetcompatmap()
CVE-2025-61105 ↗2025-10-31azl3 frr 9.1.1-4 on Azure Linux 3.0ModerateOut-of-bandFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-61102 ↗2025-10-31cbl2 frr 8.5.5-3 on CBL Mariner 2.0ModerateOut-of-bandFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-61107 ↗2025-10-31azl3 frr 9.1.1-3 on Azure Linux 3.0ModerateOut-of-bandFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.
CVE-2025-61106 ↗2025-10-31cbl2 frr 8.5.5-4 on CBL Mariner 2.0ModerateOut-of-bandFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-61103 ↗2025-10-31cbl2 frr 8.5.5-4 on CBL Mariner 2.0ModerateOut-of-bandFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-40099 ↗2025-10-31azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandcifs: parse_dfs_referrals: prevent oob on malformed input
CVE-2025-40094 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: f_acm: Refactor bind path to use __free()
CVE-2025-40092 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: f_ncm: Refactor bind path to use __free()
CVE-2025-40088 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandhfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp()
CVE-2025-40093 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandusb: gadget: f_ecm: Refactor bind path to use __free()
CVE-2025-40105 ↗2025-10-31azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandvfs: Don't leak disconnected dentries on umount
CVE-2025-40090 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandksmbd: fix recursive locking in RPC handle list access
CVE-2025-40100 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandbtrfs: do not assert we found block group item when creating free space tree
CVE-2025-40102 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandKVM: arm64: Prevent access to vCPU events before init
CVE-2025-40096 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-banddrm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies
CVE-2025-40087 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNFSD: Define a proc_layoutcommit for the FlexFiles layout type
CVE-2025-40103 ↗2025-10-31azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandsmb: client: Fix refcount leak for cifs_sb_tlink
CVE-2025-40104 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandixgbevf: fix mailbox API compatibility by negotiating supported features
CVE-2025-40097 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandALSA: hda: Fix missing pointer check in hda_component_manager_init function
CVE-2025-40095 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: f_rndis: Refactor bind path to use __free()
CVE-2025-58189 ↗2025-10-31cbl2 golang 1.18.8-10 on CBL Mariner 2.0ModerateOut-of-bandALPN negotiation error contains attacker controlled information in crypto/tls
CVE-2025-58188 ↗2025-10-31cbl2 gcc 11.2.0-8 on CBL Mariner 2.0ImportantOut-of-bandPanic when validating certificates with DSA public keys in crypto/x509
CVE-2025-58187 ↗2025-10-31cbl2 gcc 11.2.0-8 on CBL Mariner 2.0ImportantOut-of-bandQuadratic complexity when checking name constraints in crypto/x509
CVE-2025-61723 ↗2025-10-31cbl2 gcc 11.2.0-8 on CBL Mariner 2.0ImportantOut-of-bandQuadratic complexity when parsing some invalid inputs in encoding/pem
CVE-2025-61724 ↗2025-10-31cbl2 msft-golang 1.24.8-1 on CBL Mariner 2.0ModerateOut-of-bandExcessive CPU consumption in Reader.ReadResponse in net/textproto
CVE-2025-58186 ↗2025-10-31cbl2 gcc 11.2.0-8 on CBL Mariner 2.0ModerateOut-of-bandLack of limit when parsing cookies can cause memory exhaustion in net/http
CVE-2025-58185 ↗2025-10-31cbl2 golang 1.18.8-10 on CBL Mariner 2.0ImportantOut-of-bandParsing DER payload can cause memory exhaustion in encoding/asn1
CVE-2025-47912 ↗2025-10-31cbl2 golang 1.18.8-10 on CBL Mariner 2.0ImportantOut-of-bandInsufficient validation of bracketed IPv6 hostnames in net/url
CVE-2025-61725 ↗2025-10-31cbl2 golang 1.22.7-5 on CBL Mariner 2.0ImportantOut-of-bandExcessive CPU consumption in ParseAddress in net/mail
CVE-2025-58183 ↗2025-10-31cbl2 cri-o 1.22.3-16 on CBL Mariner 2.0ModerateOut-of-bandUnbounded allocation when parsing GNU sparse map in archive/tar
CVE-2025-40085 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandALSA: usb-audio: Fix NULL pointer deference in try_to_register_card
CVE-2025-40083 ↗2025-10-31azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet/sched: sch_qfq: Fix null-deref in agg_dequeue
CVE-2025-40084 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandksmbd: transport_ipc: validate payload size before reading handle
CVE-2025-12058 ↗2025-10-31azl3 keras 3.3.3-5 on Azure Linux 3.0ModerateOut-of-bandVulnerability in Keras Model.load_model Leading to Arbitrary Local File Loading and SSRF
CVE-2025-40071 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandtty: n_gsm: Don't block input queue by waiting MSC
CVE-2025-40079 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandriscv, bpf: Sign extend struct ops return values properly
CVE-2025-40068 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandfs: ntfs3: Fix integer overflow in run_unpack()
CVE-2025-40057 ↗2025-10-29azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandptp: Add a upper bound on max_vclocks
CVE-2025-40075 ↗2025-10-29azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandtcp_metrics: use dst_dev_net_rcu()
CVE-2025-40065 ↗2025-10-29azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandRISC-V: KVM: Write hgatp register with valid mode bits
CVE-2025-40027 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0LowOut-of-bandnet/9p: fix double req put in p9_fd_cancelled
CVE-2025-11840 ↗2025-10-29cbl2 binutils 2.37-17 on CBL Mariner 2.0LowOut-of-bandGNU Binutils ldmisc.c vfinfo out-of-bounds
CVE-2025-40049 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandSquashfs: fix uninit-value in squashfs_get_parent
CVE-2025-40081 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandperf: arm_spe: Prevent overflow in PERF_IDX2OFF()
CVE-2025-40048 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-banduio_hv_generic: Let userspace take care of interrupt mask
CVE-2025-40036 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandmisc: fastrpc: fix possible map leak in fastrpc_put_args
CVE-2025-40039 ↗2025-10-29cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandksmbd: Fix race condition in RPC handle list access
CVE-2025-40043 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandnet: nfc: nci: Add parameter validation for packet data
CVE-2025-40064 ↗2025-10-29azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandsmc: Fix use-after-free in __pnet_find_base_ndev().
CVE-2025-40074 ↗2025-10-29azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandipv4: start using dst_dev_rcu()
CVE-2025-40033 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandremoteproc: pru: Fix potential NULL pointer dereference in pru_rproc_set_ctable()
CVE-2025-40077 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandf2fs: fix to avoid overflow while left shift operation
CVE-2025-40032 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandPCI: endpoint: pci-epf-test: Add NULL check for DMA channels before release
CVE-2025-40080 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandnbd: restrict sockets to TCP and UDP
CVE-2025-40060 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandcoresight: trbe: Return NULL pointer for allocation failures
CVE-2025-40026 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0LowOut-of-bandKVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
CVE-2025-40040 ↗2025-10-29azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandmm/ksm: fix flag-dropping behavior in ksm_madvise
CVE-2025-40056 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandvhost: vringh: Fix copy_to_iter return value check
CVE-2025-40051 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandvhost: vringh: Modify the return value check
CVE-2025-40055 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandocfs2: fix double free in user_cluster_connect()
CVE-2025-40025 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix to do sanity check on node footer for non inode dnode
CVE-2025-40053 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandnet: dlink: handle copy_thresh allocation failure
CVE-2025-40035 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandInput: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak
CVE-2025-40030 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandpinctrl: check the return value of pinmux_ops::get_function_name()
CVE-2025-40052 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandsmb: client: fix crypto buffers in non-linear memory
CVE-2025-40044 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandfs: udf: fix OOB read in lengthAllocDescs handling
CVE-2025-40078 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandbpf: Explicitly check accesses to bpf_sock_addr
CVE-2025-40061 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandRDMA/rxe: Fix race in do_task() when draining
CVE-2025-40029 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandbus: fsl-mc: Check return value of platform_get_resource()
CVE-2025-40042 ↗2025-10-29azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandtracing: Fix race condition in kprobe initialization causing NULL pointer dereference
CVE-2025-40038 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandKVM: SVM: Skip fastpath emulation on VM-Exit if next RIP isn't valid
CVE-2025-40021 ↗2025-10-26azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandtracing: dynevent: Add a missing lockdown check on dynevent
CVE-2025-40020 ↗2025-10-26azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandcan: peak_usb: fix shift-out-of-bounds issue
CVE-2025-40024 ↗2025-10-26azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandvhost: Take a reference on the task in struct vhost_task.
CVE-2025-62518 ↗2025-10-25azl3 kata-containers-cc 3.15.0.aks0-6 on Azure Linux 3.0ImportantOut-of-bandastral-tokio-tar Vulnerable to PAX Header Desynchronization
CVE-2025-59530 ↗2025-10-25azl3 coredns 1.11.4-10 on Azure Linux 3.0ImportantOut-of-bandquic-go has Client Crash Due to Premature HANDSHAKE_DONE Frame
CVE-2025-11839 ↗2025-10-25azl3 binutils 2.41-9 on Azure Linux 3.0LowOut-of-bandGNU Binutils prdbg.c tg_tag_type return value
CVE-2025-40018 ↗2025-10-25azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandipvs: Defer ip_vs_ftp unregister during netns cleanup
CVE-2025-40019 ↗2025-10-25azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandcrypto: essiv - Check ssize for decryption and in-place encryption
CVE-2025-8677 ↗2025-10-25azl3 bind 9.20.15-1 on Azure Linux 3.0ImportantOut-of-bandResource exhaustion via malformed DNSKEY handling
CVE-2025-40780 ↗2025-10-25azl3 bind 9.20.15-1 on Azure Linux 3.0ImportantOut-of-bandCache poisoning due to weak PRNG
CVE-2025-40778 ↗2025-10-25azl3 bind 9.20.15-1 on Azure Linux 3.0ImportantOut-of-bandCache poisoning attacks with unsolicited RRs
CVE-2025-59501 ↗2025-10-24Microsoft Configuration Manager 2403ImportantOut-of-band3%Microsoft Configuration Manager Spoofing Vulnerability
CVE-2025-62813 ↗2025-10-24cbl2 lz4 1.9.4-1 on CBL Mariner 2.0ModerateOut-of-bandLZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in lib/lz4frame.c mishandles NULL checks.
CVE-2025-11411 ↗2025-10-24azl3 unbound 1.19.1-4 on Azure Linux 3.0ModerateOut-of-bandPossible domain hijacking via promiscuous records in the authority section
CVE-2025-59273 ↗2025-10-23Azure Event Grid SystemCriticalOut-of-band0%Azure Event Grid System Elevation of Privilege Vulnerability
CVE-2025-59500 ↗2025-10-23Azure Notification ServiceCriticalOut-of-band1%Azure Notification Service Elevation of Privilege Vulnerability
CVE-2025-59503 ↗2025-10-23Azure Compute Resource ProviderCriticalOut-of-band1%Azure Compute Resource Provider Elevation of Privilege Vulnerability
CVE-2025-53054 ↗2025-10-23azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).
CVE-2025-53045 ↗2025-10-23azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53069 ↗2025-10-23azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53053 ↗2025-10-23azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).
CVE-2025-53062 ↗2025-10-23azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53040 ↗2025-10-23azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53044 ↗2025-10-23azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53042 ↗2025-10-23cbl2 mysql 8.0.43-1 on CBL Mariner 2.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-40010 ↗2025-10-22azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandafs: Fix potential null pointer dereference in afs_put_server
CVE-2025-40011 ↗2025-10-22azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-banddrm/gma500: Fix null dereference in hdmi teardown
CVE-2025-40005 ↗2025-10-22azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandspi: cadence-quadspi: Implement refcount to handle unbind during busy
CVE-2025-40016 ↗2025-10-22azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmedia: uvcvideo: Mark invalid entities with id UVC_INVALID_ENTITY_ID
CVE-2025-40013 ↗2025-10-22azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandASoC: qcom: audioreach: fix potential null pointer dereference
CVE-2025-40001 ↗2025-10-19azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandscsi: mvsas: Fix use-after-free bugs in mvs_work_queue
CVE-2025-40003 ↗2025-10-19azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandnet: mscc: ocelot: Fix use-after-free caused by cyclic delayed work
CVE-2024-31573 ↗2025-10-19cbl2 javapackages-bootstrap 1.5.0-7 on CBL Mariner 2.0ModerateOut-of-bandXMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
CVE-2025-62168 ↗2025-10-19azl3 squid 6.13-1 on Azure Linux 3.0CriticalOut-of-bandSquid vulnerable to information disclosure via authentication credential leakage in error handling
CVE-2025-11756 ↗2025-10-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11756 Use after free in Safe Browsing
CVE-2025-39996 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandmedia: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove
CVE-2025-39986 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandcan: sun4i_can: populate ndo_change_mtu() to prevent buffer overflow
CVE-2025-39977 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandfutex: Prevent use-after-free during requeue-PI
CVE-2025-39982 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandBluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync
CVE-2025-39990 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandbpf: Check the helper function is valid in get_helper_proto
CVE-2025-39987 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandcan: hi311x: populate ndo_change_mtu() to prevent buffer overflow
CVE-2025-40000 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandwifi: rtw89: fix use-after-free in rtw89_core_tx_kick_off_and_wait()
CVE-2025-39994 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandmedia: tuner: xc5000: Fix use-after-free in xc5000_release
CVE-2025-39980 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandnexthop: Forbid FDB status change while nexthop is in a group
CVE-2025-39998 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandscsi: target: target_core_configfs: Add length check to avoid buffer overflow
CVE-2025-39981 ↗2025-10-16azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-bandBluetooth: MGMT: Fix possible UAFs
CVE-2025-39993 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandmedia: rc: fix races with imon_disconnect()
CVE-2025-39973 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandi40e: add validation for ring_len param
CVE-2025-39995 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandmedia: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe
CVE-2025-39969 ↗2025-10-16azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandi40e: fix validation of VF state in get resources
CVE-2025-39978 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandocteontx2-pf: Fix potential use after free in otx2_tc_add_flow()
CVE-2025-39972 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandi40e: fix idx validation in i40e_validate_queue_map
CVE-2025-39971 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandi40e: fix idx validation in config queues msg
CVE-2025-39988 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandcan: etas_es58x: populate ndo_change_mtu() to prevent buffer overflow
CVE-2025-39985 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandcan: mcba_usb: populate ndo_change_mtu() to prevent buffer overflow
CVE-2025-39970 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandi40e: fix input validation logic for action_meta
CVE-2025-39967 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandfbcon: fix integer overflow in fbcon_do_set_font
CVE-2025-39968 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandi40e: add max boundary check for VF filters
CVE-2025-39964 ↗2025-10-15azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandcrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
CVE-2025-39965 ↗2025-10-15azl3 kernel 6.6.104.2-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: xfrm_alloc_spi shouldn't use 0 as SPI
CVE-2016-9535 ↗2025-10-14Microsoft Office for AndroidCritical5%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
MITRE CVE-2016-9535: LibTIFF Heap Buffer Overflow Vulnerability
CVE-2025-24052 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant2%More likelyKB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Agere Modem Driver Elevation of Privilege Vulnerability
CVE-2025-24990 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant6%Exploitation detectedCISA KEVVulnCheckENISAKB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Agere Modem Driver Elevation of Privilege Vulnerability
CVE-2025-25004 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
PowerShell Elevation of Privilege Vulnerability
CVE-2025-2884 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsCritical0%KB5066780KB5066793
and 2 moreKB5066835KB5077179
Cert CC: CVE-2025-2884 Out-of-Bounds read vulnerability in TCG TPM2.0 reference implementation
CVE-2025-47827 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant4%Exploitation detectedCISA KEVVulnCheckENISAKB5066586KB5066780
and 8 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066873KB5066875
MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11
CVE-2025-47979 ↗2025-10-14Windows Server 2025 (Server Core installation)Important1%KB5066780KB5066835Microsoft Failover Cluster Information Disclosure Vulnerability
CVE-2025-47989 ↗2025-10-14Arc Enabled Servers - Azure Connected Machine AgentImportant1%Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2025-48004 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant2%More likelyKB5066780KB5066793
and 1 moreKB5066835
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-48813 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Virtual Secure Mode Spoofing Vulnerability
CVE-2025-49708 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2025-50152 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-50174 ↗2025-10-14Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5066835Windows Device Association Broker Service Elevation of Privilege Vulnerability
CVE-2025-50175 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-53139 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066791KB5066793
and 1 moreKB5066835
Windows Hello Security Feature Bypass Vulnerability
CVE-2025-53150 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 3 moreKB5066791KB5066793KB5066835
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-53717 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066793KB5066835Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
CVE-2025-53768 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066791
and 4 moreKB5066793KB5066835KB5066836KB5066837
Xbox IStorageService Elevation of Privilege Vulnerability
CVE-2025-53782 ↗2025-10-14Microsoft Exchange Server 2019 Cumulative Update 15Important0%KB5066366KB5066367
and 2 moreKB5066368KB5066369
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-54132 ↗2025-10-14Microsoft Visual Studio 2022 version 17.14Important0%GitHub CVE-2025-54132: Arbitrary Image Fetch in Mermaid Diagram Tool
CVE-2025-54957 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant2%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
1 mentionsMITRE CVE-2025-54957: Integer overflow in Dolby Digital Plus audio decoder
CVE-2025-55240 ↗2025-10-14Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)Important0%Visual Studio Elevation of Privilege Vulnerability
CVE-2025-55247 ↗2025-10-14.NET 8.0 installed on LinuxImportant1%KB5068331KB5068332.NET Elevation of Privilege Vulnerability
CVE-2025-55248 ↗2025-10-14.NET 8.0 installed on LinuxImportant1%KB5066128KB5066129
and 14 moreKB5066131KB5066133KB5066136KB5066738KB5066739KB5066740KB5066741KB5066742KB5066743KB5066746KB5066747KB5066836KB5068331KB5068332
.NET, .NET Framework, and Visual Studio Information Disclosure Vulnerability
CVE-2025-55315 ↗2025-10-14ASP.NET Core 8.0Important66%KB5068331KB5068332ASP.NET Security Feature Bypass Vulnerability