CYBERSECURITYTRACKER
TRACKING7,183 stories in this site build1,510 vulnerability news stories in this site build
Vulnerabilities

October 2025 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 3 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 429 vulnerabilities across 429 returned patch records from 1 vendor. Filter the complete month, or browse the static page trail without JavaScript.

429all patch recordsClear filters41criticalShow these records3Microsoft exploitation detectedShow these records5Microsoft in the Known Exploited Vulnerabilities catalogShow these records225tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 2 of 3 · records 201 to 400 of 429

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-59290 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 5 moreKB5065426KB5065429KB5065431KB5065432KB5065474
Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2025-59294 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows Taskbar Live Preview Information Disclosure Vulnerability
CVE-2025-59295 ↗Windows 11 Version 25H2 for ARM64-based SystemsImportant2%Microsoft rates: Exploitation Less LikelyKB5066586KB5066780
and 13 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066840KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows URL Parsing Remote Code Execution Vulnerability
CVE-2025-59494 ↗Azure Monitor AgentImportant1%Microsoft rates: Exploitation Less LikelyAzure Monitor Agent Elevation of Privilege Vulnerability
CVE-2025-59497 ↗Microsoft Defender for Endpoint for LinuxImportant0%Microsoft rates: Exploitation Less LikelyMicrosoft Defender for Linux Denial of Service Vulnerability
CVE-2025-59489 ↗Avowed ArtbookImportantOut-of-band1%Microsoft rating unavailableMITRE: CVE-2025-59489 Unity Gaming Engine Editor vulnerability
CVE-2025-62725 ↗azl3 docker-compose 2.27.0-12 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableDocker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations
CVE-2025-40082 ↗azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablehfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
CVE-2023-53543 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablevdpa: Add max vqp attr to vdpa_nl_policy for nlattr length check
CVE-2025-12105 ↗azl3 libsoup 3.4.4-10 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableLibsoup: heap use-after-free in libsoup message queue handling during http/2 read completion
CVE-2025-61099 ↗cbl2 frr 8.5.5-4 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableFRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet.
CVE-2025-62230 ↗azl3 xorg-x11-server-Xwayland 24.1.6-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableXorg: xwayland: use-after-free in xkb client resource removal
CVE-2025-61104 ↗cbl2 frr 8.5.5-3 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-61100 ↗cbl2 frr 8.5.5-3 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableFRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions.
CVE-2025-61101 ↗cbl2 frr 8.5.5-3 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-12060 ↗azl3 keras 3.3.3-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableKeras keras.utils.get_file Utility Path Traversal Vulnerability
CVE-2025-62229 ↗azl3 xorg-x11-server-Xwayland 24.1.6-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableXorg: xmayland: use-after-free in xpresentnotify structure creation
CVE-2025-62231 ↗azl3 xorg-x11-server-Xwayland 24.1.6-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableXorg: xmayland: value overflow in xkbsetcompatmap()
CVE-2025-40093 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableusb: gadget: f_ecm: Refactor bind path to use __free()
CVE-2025-40105 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablevfs: Don't leak disconnected dentries on umount
CVE-2025-40090 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableksmbd: fix recursive locking in RPC handle list access
CVE-2025-40102 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableKVM: arm64: Prevent access to vCPU events before init
CVE-2025-40096 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies
CVE-2025-40103 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablesmb: client: Fix refcount leak for cifs_sb_tlink
CVE-2025-58188 ↗cbl2 golang 1.18.8-10 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablePanic when validating certificates with DSA public keys in crypto/x509
CVE-2025-58187 ↗azl3 golang 1.25.5-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableQuadratic complexity when checking name constraints in crypto/x509
CVE-2025-61723 ↗cbl2 msft-golang 1.24.8-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableQuadratic complexity when parsing some invalid inputs in encoding/pem
CVE-2025-58185 ↗cbl2 golang 1.18.8-10 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableParsing DER payload can cause memory exhaustion in encoding/asn1
CVE-2025-47912 ↗cbl2 golang 1.18.8-10 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableInsufficient validation of bracketed IPv6 hostnames in net/url
CVE-2025-61725 ↗cbl2 golang 1.22.7-5 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableExcessive CPU consumption in ParseAddress in net/mail
CVE-2025-40068 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablefs: ntfs3: Fix integer overflow in run_unpack()
CVE-2025-40057 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableptp: Add a upper bound on max_vclocks
CVE-2025-40075 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabletcp_metrics: use dst_dev_net_rcu()
CVE-2025-40065 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableRISC-V: KVM: Write hgatp register with valid mode bits
CVE-2025-40081 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableperf: arm_spe: Prevent overflow in PERF_IDX2OFF()
CVE-2025-40048 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableuio_hv_generic: Let userspace take care of interrupt mask
CVE-2025-40036 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemisc: fastrpc: fix possible map leak in fastrpc_put_args
CVE-2025-40074 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableipv4: start using dst_dev_rcu()
CVE-2025-40077 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablef2fs: fix to avoid overflow while left shift operation
CVE-2025-40055 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableocfs2: fix double free in user_cluster_connect()
CVE-2025-40020 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablecan: peak_usb: fix shift-out-of-bounds issue
CVE-2025-62518 ↗azl3 kata-containers-cc 3.15.0.aks0-6 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableastral-tokio-tar Vulnerable to PAX Header Desynchronization
CVE-2025-59530 ↗azl3 coredns 1.11.4-10 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablequic-go has Client Crash Due to Premature HANDSHAKE_DONE Frame
CVE-2025-40018 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableipvs: Defer ip_vs_ftp unregister during netns cleanup
CVE-2025-8677 ↗azl3 bind 9.20.15-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableResource exhaustion via malformed DNSKEY handling
CVE-2025-40780 ↗azl3 bind 9.20.15-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableCache poisoning due to weak PRNG
CVE-2025-40778 ↗azl3 bind 9.20.15-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableCache poisoning attacks with unsolicited RRs
CVE-2025-40001 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablescsi: mvsas: Fix use-after-free bugs in mvs_work_queue
CVE-2025-40003 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenet: mscc: ocelot: Fix use-after-free caused by cyclic delayed work
CVE-2025-39977 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablefutex: Prevent use-after-free during requeue-PI
CVE-2025-39982 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableBluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync
CVE-2025-39987 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablecan: hi311x: populate ndo_change_mtu() to prevent buffer overflow
CVE-2025-39980 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenexthop: Forbid FDB status change while nexthop is in a group
CVE-2025-39998 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablescsi: target: target_core_configfs: Add length check to avoid buffer overflow
CVE-2025-39993 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemedia: rc: fix races with imon_disconnect()
CVE-2025-39995 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemedia: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe
CVE-2025-39988 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablecan: etas_es58x: populate ndo_change_mtu() to prevent buffer overflow
CVE-2025-46817 ↗azl3 valkey 8.0.4-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableLua library commands may lead to integer overflow and potential RCE
CVE-2025-10729 ↗azl3 qtsvg 6.6.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableUse-after-free vulnerability in Qt SVG qsvghandler.cpp allows denial of service via crafted SVG
CVE-2025-10728 ↗azl3 qtsvg 6.6.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableUncontrolled recursion in Qt SVG module
CVE-2025-39944 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableocteontx2-pf: Fix use-after-free bugs in otx2_sync_tstamp()
CVE-2025-39945 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablecnic: Fix use-after-free bugs in cnic_delete_task
CVE-2025-39952 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablewifi: wilc1000: avoid buffer overflow in WID string configuration
CVE-2025-39911 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablei40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path
CVE-2025-39905 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenet: phylink: add lock for serializing concurrent pl->phydev writes with resolver
CVE-2023-53469 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableaf_unix: Fix null-ptr-deref in unix_stream_sendpage().
CVE-2025-39901 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablei40e: remove read access to debugfs files
CVE-2025-59288 ↗microsoft/playwrightModerate0%Microsoft rates: Exploitation Less LikelyPlaywright Spoofing Vulnerability
CVE-2025-59502 ↗Windows 10 Version 1809 for 32-bit SystemsModerate1%Microsoft rates: Exploitation More LikelyKB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Remote Procedure Call Denial of Service Vulnerability
CVE-2023-53701 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-53642 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablex86: fix clear_user_rep_good() exception handling annotation
CVE-2023-53466 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mt76: mt7915: fix memory leak in mt7915_mcu_exit
CVE-2025-39894 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm
CVE-2023-53460 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: rtw88: fix memory leak in rtw_usb_probe()
CVE-2022-50467 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: lpfc: Fix null ndlp ptr dereference in abnormal exit path for GFT_ID
CVE-2022-50464 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemt76: mt7915: Fix PCI device refcount leak in mt7915_pci_init_hif2()
CVE-2022-50461 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: ethernet: ti: am65-cpsw: Fix PM runtime leakage in am65_cpsw_nuss_ndo_slave_open()
CVE-2025-11494 ↗cbl2 binutils 2.37-19 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGNU Binutils Linker elfxx-x86.c _bfd_x86_elf_late_size_sections out-of-bounds
CVE-2025-12464 ↗azl3 qemu 8.2.0-25 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableQemu-kvm: stack buffer overflow in e1000 device via short frames in loopback mode
CVE-2025-40106 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecomedi: fix divide-by-zero in comedi_buf_munge()
CVE-2025-61105 ↗azl3 frr 9.1.1-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-61102 ↗cbl2 frr 8.5.5-3 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-61107 ↗azl3 frr 9.1.1-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.
CVE-2025-61106 ↗cbl2 frr 8.5.5-4 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-61103 ↗cbl2 frr 8.5.5-4 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-40099 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecifs: parse_dfs_referrals: prevent oob on malformed input
CVE-2025-40094 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableusb: gadget: f_acm: Refactor bind path to use __free()
CVE-2025-40092 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableusb: gadget: f_ncm: Refactor bind path to use __free()
CVE-2025-40088 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablehfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp()
CVE-2025-40100 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: do not assert we found block group item when creating free space tree
CVE-2025-40087 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNFSD: Define a proc_layoutcommit for the FlexFiles layout type
CVE-2025-40104 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableixgbevf: fix mailbox API compatibility by negotiating supported features
CVE-2025-40097 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: hda: Fix missing pointer check in hda_component_manager_init function
CVE-2025-40095 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableusb: gadget: f_rndis: Refactor bind path to use __free()
CVE-2025-58189 ↗cbl2 golang 1.18.8-10 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALPN negotiation error contains attacker controlled information in crypto/tls
CVE-2025-61724 ↗cbl2 msft-golang 1.24.8-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableExcessive CPU consumption in Reader.ReadResponse in net/textproto
CVE-2025-58186 ↗cbl2 golang 1.18.8-10 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLack of limit when parsing cookies can cause memory exhaustion in net/http
CVE-2025-58183 ↗cbl2 cri-o 1.22.3-16 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableUnbounded allocation when parsing GNU sparse map in archive/tar
CVE-2025-40085 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: usb-audio: Fix NULL pointer deference in try_to_register_card
CVE-2025-40083 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: sch_qfq: Fix null-deref in agg_dequeue
CVE-2025-40084 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: transport_ipc: validate payload size before reading handle
CVE-2025-12058 ↗azl3 keras 3.3.3-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVulnerability in Keras Model.load_model Leading to Arbitrary Local File Loading and SSRF
CVE-2025-40071 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletty: n_gsm: Don't block input queue by waiting MSC
CVE-2025-40079 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableriscv, bpf: Sign extend struct ops return values properly
CVE-2025-40049 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableSquashfs: fix uninit-value in squashfs_get_parent
CVE-2025-40039 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: Fix race condition in RPC handle list access
CVE-2025-40043 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: nfc: nci: Add parameter validation for packet data
CVE-2025-40064 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmc: Fix use-after-free in __pnet_find_base_ndev().
CVE-2025-40033 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableremoteproc: pru: Fix potential NULL pointer dereference in pru_rproc_set_ctable()
CVE-2025-40032 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePCI: endpoint: pci-epf-test: Add NULL check for DMA channels before release
CVE-2025-40080 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenbd: restrict sockets to TCP and UDP
CVE-2025-40060 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecoresight: trbe: Return NULL pointer for allocation failures
CVE-2025-40040 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm/ksm: fix flag-dropping behavior in ksm_madvise
CVE-2025-40056 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevhost: vringh: Fix copy_to_iter return value check
CVE-2025-40051 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevhost: vringh: Modify the return value check
CVE-2025-40025 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablef2fs: fix to do sanity check on node footer for non inode dnode
CVE-2025-40053 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: dlink: handle copy_thresh allocation failure
CVE-2025-40035 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableInput: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak
CVE-2025-40030 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepinctrl: check the return value of pinmux_ops::get_function_name()
CVE-2025-40052 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb: client: fix crypto buffers in non-linear memory
CVE-2025-40044 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefs: udf: fix OOB read in lengthAllocDescs handling
CVE-2025-40078 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Explicitly check accesses to bpf_sock_addr
CVE-2025-40061 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/rxe: Fix race in do_task() when draining
CVE-2025-40029 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebus: fsl-mc: Check return value of platform_get_resource()
CVE-2025-40042 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletracing: Fix race condition in kprobe initialization causing NULL pointer dereference
CVE-2025-40038 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableKVM: SVM: Skip fastpath emulation on VM-Exit if next RIP isn't valid
CVE-2025-40021 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletracing: dynevent: Add a missing lockdown check on dynevent
CVE-2025-40024 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevhost: Take a reference on the task in struct vhost_task.
CVE-2025-40019 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecrypto: essiv - Check ssize for decryption and in-place encryption
CVE-2025-62813 ↗cbl2 lz4 1.9.4-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in lib/lz4frame.c mishandles NULL checks.
CVE-2025-11411 ↗azl3 unbound 1.19.1-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePossible domain hijacking via promiscuous records in the authority section
CVE-2025-53054 ↗azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).
CVE-2025-53045 ↗azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53069 ↗azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53053 ↗azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).
CVE-2025-53062 ↗azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53040 ↗azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53044 ↗azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53042 ↗cbl2 mysql 8.0.43-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-40010 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableafs: Fix potential null pointer dereference in afs_put_server
CVE-2025-40011 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/gma500: Fix null dereference in hdmi teardown
CVE-2025-40005 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablespi: cadence-quadspi: Implement refcount to handle unbind during busy
CVE-2025-40016 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemedia: uvcvideo: Mark invalid entities with id UVC_INVALID_ENTITY_ID
CVE-2025-40013 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableASoC: qcom: audioreach: fix potential null pointer dereference
CVE-2024-31573 ↗cbl2 javapackages-bootstrap 1.5.0-7 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableXMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
CVE-2025-39990 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Check the helper function is valid in get_helper_proto
CVE-2025-39969 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablei40e: fix validation of VF state in get resources
CVE-2025-39965 ↗azl3 kernel 6.6.104.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablexfrm: xfrm_alloc_spi shouldn't use 0 as SPI
CVE-2025-37727 ↗cbl2 rubygem-elasticsearch 8.3.0-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableElasticsearch Insertion of sensitive information in log file
CVE-2025-11412 ↗cbl2 binutils 2.37-17 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGNU Binutils Linker elflink.c bfd_elf_gc_record_vtentry out-of-bounds
CVE-2025-11414 ↗cbl2 binutils 2.37-17 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGNU Binutils Linker elflink.c get_link_hash_entry out-of-bounds
CVE-2025-11413 ↗cbl2 binutils 2.37-16 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGNU Binutils Linker elflink.c elf_link_add_object_symbols out-of-bounds
CVE-2025-11495 ↗cbl2 binutils 2.37-16 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGNU Binutils Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflow
CVE-2025-39961 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableiommu/amd/pgtbl: Fix possible race while increase page table level
CVE-2025-46819 ↗azl3 valkey 8.0.4-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRedis is vulnerable to DoS via specially crafted LUA scripts
CVE-2025-46818 ↗azl3 valkey 8.0.4-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRedis: Authenticated users can execute LUA scripts as a different user
CVE-2025-39955 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect().
CVE-2025-8291 ↗azl3 python3 3.12.9-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableZIP64 End of Central Directory (EOCD) Locator record offset not checked
CVE-2025-61985 ↗azl3 openssh 9.8p1-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablessh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
CVE-2025-11234 ↗azl3 qemu 8.2.0-19 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableQemu-kvm: vnc websocket handshake use-after-free
CVE-2022-50502 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm: /proc/pid/smaps_rollup: fix no vma's null-deref
CVE-2025-39947 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5e: Harden uplink netdev access against device unbind
CVE-2025-39931 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecrypto: af_alg - Set merge to zero early in af_alg_sendmsg
CVE-2025-39940 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm-stripe: fix a possible integer overflow
CVE-2025-39933 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb: client: let recv_done verify data_offset, data_length and remaining_data_length
CVE-2025-39953 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecgroup: split cgroup_destroy_wq into 3 workqueues
CVE-2025-39949 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableqed: Don't collect too many protection override GRC elements
CVE-2025-39932 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work)
CVE-2025-39937 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer
CVE-2025-39951 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableum: virtio_uml: Fix use-after-free after put_device in probe
CVE-2025-39946 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletls: make sure to abort the stream if headers are bogus
CVE-2025-39942 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: smbdirect: verify remaining_data_length respects max_fragmented_recv_size
CVE-2025-39938 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableASoC: qcom: q6apm-lpass-dais: Fix NULL pointer dereference if source graph failed
CVE-2025-39929 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path
CVE-2025-39934 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm: bridge: anx7625: Fix NULL pointer dereference with early IRQ
CVE-2025-39913 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork.
CVE-2025-39920 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepcmcia: Add error handling for add_interval() in do_validate_mem()
CVE-2025-39914 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletracing: Silence warning when chunk allocation fails in trace_pid_write
CVE-2025-39923 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees
CVE-2025-39916 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm/damon/reclaim: avoid divide-by-zero in damon_reclaim_apply_parameters()
CVE-2025-39902 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm/slub: avoid accessing metadata when pointer is invalid in object_err()
CVE-2025-39909 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm/damon/lru_sort: avoid divide-by-zero in damon_lru_sort_apply_parameters()
CVE-2025-39891 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mwifiex: Initialize the chan_stats array to zero
CVE-2025-39895 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesched: Fix sched_numa_find_nth_cpu() if mask offline
CVE-2025-39927 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableceph: fix race condition validating r_parent before applying state
CVE-2025-11840 ↗cbl2 binutils 2.37-17 on CBL Mariner 2.0LowOut-of-band0%Microsoft rating unavailableGNU Binutils ldmisc.c vfinfo out-of-bounds
CVE-2025-11731 ↗cbl2 libxslt 1.1.34-8 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailableLibxslt: type confusion in exsltfuncresultcompfunction of libxslt
CVE-2025-6075 ↗azl3 python3 3.12.9-5 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableQuadratic complexity in os.path.expandvars() with user-controlled template
CVE-2025-40027 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablenet/9p: fix double req put in p9_fd_cancelled
CVE-2025-40026 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableKVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
CVE-2025-11839 ↗azl3 binutils 2.41-9 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableGNU Binutils prdbg.c tg_tag_type return value
CVE-2025-39957 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablewifi: mac80211: increase scan_ies_len for S1G
CVE-2025-39958 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableiommu/s390: Make attach succeed when the device was surprise removed
CVE-2025-61984 ↗azl3 openssh 9.8p1-4 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablessh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)
CVE-2025-12441 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2025-12441 Out of bounds read in V8
CVE-2025-12440 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2025-12440 Inappropriate implementation in Autofill
CVE-2025-12439 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2025-12439 Inappropriate implementation in App-Bound Encryption
CVE-2025-12438 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2025-12438 Use after free in Ozone
CVE-2025-12437 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2025-12437 Use after free in PageInfo
CVE-2025-12436 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2025-12436 Policy bypass in Extensions

Glossary