CYBERSECURITYTRACKER
TRACKING3,612 stories653 vuln stories
Patch Day month

December 2025 vulnerabilities

A server-rendered hunting trail for December 2025: 349 returned patch records across 1 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.

349all patches
15critical
1exploitation detected
2in CISA KEV
83tracked here
Microsoft 349

Page 1 of 2 · records 1–200 of 349

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-68251 ↗2026-05-25azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: avoid infinite loops due to corrupted subpage compact indexes
CVE-2023-54207 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandHID: uclogic: Correct devm device reference for hidinput input_dev name
CVE-2025-67873 ↗2026-01-21azl3 rust 1.75.0-22 on Azure Linux 3.0ModerateOut-of-bandCapstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow
CVE-2025-68291 ↗2026-01-13azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandmptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose().
CVE-2025-48637 ↗2026-01-09azl3 hyperv-daemons 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandIn multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-61594 ↗2026-01-03azl3 ruby 3.3.5-6 on Azure Linux 3.0LowOut-of-bandURI Credential Leakage Bypass over CVE-2025-27221
CVE-2025-15284 ↗2026-01-03azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandarrayLimit bypass in bracket notation allows DoS via memory exhaustion
CVE-2025-69277 ↗2026-01-03azl3 libsodium 1.0.19-1 on Azure Linux 3.0ModerateOut-of-bandlibsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.
CVE-2025-11964 ↗2026-01-03azl3 libpcap 1.10.5-1 on Azure Linux 3.0LowOut-of-bandOOBW in utf_16le_to_utf_8_truncated() in libpcap
CVE-2025-11961 ↗2026-01-03cbl2 nmap 7.93-3 on CBL Mariner 2.0LowOut-of-bandOOBR and OOBW in pcap_ether_aton() in libpcap
CVE-2025-34468 ↗2026-01-03azl3 libcap 2.69-10 on Azure Linux 3.0ImportantOut-of-bandlibcoap Stack-Based Buffer Overflow in Address Resolution DoS or Potential RCE
CVE-2025-68973 ↗2025-12-30azl3 gnupg2 2.4.7-1 on Azure Linux 3.0ImportantOut-of-bandIn GnuPG through 2.4.8, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
CVE-2025-14180 ↗2025-12-29cbl2 php 8.1.33-1 on CBL Mariner 2.0ImportantOut-of-bandNULL Pointer Dereference in PDO quoting
CVE-2025-14178 ↗2025-12-29azl3 php 8.3.23-1 on Azure Linux 3.0ModerateOut-of-bandHeap buffer overflow in array_merge()
CVE-2025-14177 ↗2025-12-29azl3 php 8.3.23-1 on Azure Linux 3.0ModerateOut-of-bandInformation Leak of Memory in getimagesize
CVE-2025-68972 ↗2025-12-29cbl2 gnupg2 2.4.0-3 on CBL Mariner 2.0ModerateOut-of-bandIn GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.
CVE-2025-13699 ↗2025-12-27azl3 mariadb 10.11.11-1 on Azure Linux 3.0ImportantOut-of-bandMariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability
CVE-2023-54061 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandx86: fix clear_user_rep_good() exception handling annotation
CVE-2025-68733 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandsmack: fix bug: unprivileged task can create labels
CVE-2025-68374 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandmd: fix rcu protection in md_wakeup_thread
CVE-2025-68724 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id
CVE-2025-68380 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: ath11k: fix peer HE MCS assignment
CVE-2025-68376 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcoresight: ETR: Fix ETR buffer use-after-free issue
CVE-2025-68378 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix stackmap overflow check in __bpf_get_stackid()
CVE-2025-68727 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0LowOut-of-bandntfs3: Fix uninit buffer allocated by __getname()
CVE-2025-68364 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandocfs2: relax BUG() to ocfs2_error() in __ocfs2_move_extent()
CVE-2025-68346 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandALSA: dice: fix buffer overflow in detect_stream_formats()
CVE-2025-68379 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/rxe: Fix null deref on srq->rq.queue after resize failure
CVE-2025-68363 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Check skb->transport_header is set in bpf_skb_check_mtu
CVE-2025-68740 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandima: Handle error code returned by ima_filter_rule_match()
CVE-2023-54082 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandaf_unix: Fix null-ptr-deref in unix_stream_sendpage().
CVE-2025-68358 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix racy bitfield write in btrfs_clear_space_info_full()
CVE-2025-68372 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandnbd: defer config put in recv_work
CVE-2025-68728 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandntfs3: fix uninit memory after failed mi_read in mi_format_new
CVE-2025-68725 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Do not let BPF test infra emit invalid GSO types to stack
CVE-2025-68365 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandfs/ntfs3: Initialize allocated memory before use
CVE-2025-68367 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandmacintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse
CVE-2025-68742 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix invalid prog->stats access when update_effective_progs fails
CVE-2025-68356 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandgfs2: Prevent recursive memory reclaim
CVE-2025-68746 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: tegra210-quad: Fix timeout handling
CVE-2025-68344 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: wavefront: Fix integer overflow in sample size validation
CVE-2025-68347 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events
CVE-2025-68744 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Free special fields when update [lru_,]percpu_hash maps
CVE-2025-68729 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: ath12k: Fix MSDU buffer types handling in RX error path
CVE-2025-68745 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: qla2xxx: Clear cmds after chip reset
CVE-2025-68736 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandlandlock: Fix handling of disconnected directories
CVE-2025-68366 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandnbd: defer config unlock in nbd_genl_connect
CVE-2025-68357 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandiomap: allocate s_dio_done_wq for async reads as well
CVE-2023-54161 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandaf_unix: Fix null-ptr-deref in unix_stream_sendpage().
CVE-2025-68732 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandgpu: host1x: Fix race in syncpt alloc/free
CVE-2025-68741 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: qla2xxx: Fix improper freeing of purex item
CVE-2025-68345 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_hda_read_acpi()
CVE-2025-68362 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: rtl818x: rtl8187: Fix potential buffer underflow in rtl8187_rx_cb()
CVE-2025-68354 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandregulator: core: Protect regulator_supply_alias_list with regulator_list_mutex
CVE-2025-68349 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid
CVE-2025-68371 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: smartpqi: Fix device resources accessed after device removal
CVE-2025-68343 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing header
CVE-2025-68340 ↗2025-12-24cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandteam: Move team device type change at the end of team_port_add
CVE-2025-68342 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing data
CVE-2025-68338 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: dsa: microchip: Don't free uninitialized ksz_irq
CVE-2025-68339 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandatm/fore200e: Fix possible data race in fore200e_open()
CVE-2025-68615 ↗2025-12-24cbl2 net-snmp 5.9.4-1 on CBL Mariner 2.0CriticalOut-of-bandNet-SNMP snmptrapd crash
CVE-2025-68334 ↗2025-12-24azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandplatform/x86/amd/pmc: Add support for Van Gogh SoC
CVE-2025-68328 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandfirmware: stratix10-svc: fix bug in saving controller data
CVE-2025-68330 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandiio: accel: bmc150: Fix irq assumption regression
CVE-2025-68336 ↗2025-12-24azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandlocking/spinlock/debug: Fix data-race in do_raw_write_lock
CVE-2025-68333 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandsched_ext: Fix possible deadlock in the deferred_irq_workfn()
CVE-2025-68327 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: renesas_usbhs: Fix synchronous external abort on unbind
CVE-2025-68335 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcomedi: pcl818: fix null-ptr-deref in pcl818_ai_cancel()
CVE-2025-68332 ↗2025-12-24azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandcomedi: c6xdigio: Fix invalid PNP driver unregistration
CVE-2025-68337 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandjbd2: avoid bug_on in jbd2_journal_get_create_access() when file system corrupted
CVE-2025-68331 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: uas: fix urb unmapping issue when the uas device is remove during ongoing data transfer
CVE-2025-68476 ↗2025-12-24cbl2 keda 2.4.0-30 on CBL Mariner 2.0ImportantOut-of-bandKEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account Credential
CVE-2025-68114 ↗2025-12-21cbl2 qemu 6.2.0-26 on CBL Mariner 2.0ModerateOut-of-bandCapstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow
CVE-2025-68161 ↗2025-12-21azl3 javapackages-bootstrap 1.14.0-3 on Azure Linux 3.0ModerateOut-of-bandApache Log4j Core: Missing TLS hostname verification in Socket appender
CVE-2025-59529 ↗2025-12-21cbl2 avahi 0.8-4 on CBL Mariner 2.0ModerateOut-of-bandsimple protocol server ignores accepts unlimited connections and logs failures without limit
CVE-2025-68384 ↗2025-12-20azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandElasticsearch Allocation of Resources Without Limits or Throttling
CVE-2025-68390 ↗2025-12-20azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandElasticsearch Allocation of Resources Without Limits or Throttling
CVE-2025-68324 ↗2025-12-20azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandscsi: imm: Fix use-after-free bug caused by unfinished delayed work
CVE-2025-68146 ↗2025-12-19azl3 python-filelock 3.14.0-1 on Azure Linux 3.0ModerateOut-of-bandfilelock has TOCTOU race condition that allows symlink attacks during lock file creation
CVE-2025-68156 ↗2025-12-19cbl2 coredns 1.11.1-24 on CBL Mariner 2.0ImportantOut-of-bandExpr has Denial of Service via Unbounded Recursion in Builtin Functions
CVE-2025-14766 ↗2025-12-18Microsoft Edge (Chromium-based)N/AOut-of-band3%Chromium: CVE-2025-14766 Use after free in WebGPU
CVE-2025-14765 ↗2025-12-18Microsoft Edge (Chromium-based)N/AOut-of-band3%Chromium: CVE-2025-14765 Out of bounds read and write in V8
CVE-2025-65046 ↗2025-12-18Microsoft Edge for AndroidLowOut-of-band0%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2025-68302 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: sxgbe: fix potential NULL dereference in sxgbe_rx()
CVE-2025-68289 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: f_eem: Fix memory leak in eem_unwrap
CVE-2025-68315 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandf2fs: fix to detect potential corrupted nid in free_nid_list
CVE-2025-68296 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup
CVE-2025-68287 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: dwc3: Fix race condition between concurrent dwc3_remove_requests() call paths
CVE-2025-68308 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: kvaser_usb: leaf: Fix potential infinite loop in command parsers
CVE-2025-68290 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandmost: usb: fix double free on late probe failure
CVE-2025-68318 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandclk: thead: th1520-ap: set all AXI clocks to CLK_IS_CRITICAL
CVE-2025-68301 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: atlantic: fix fragment overflow handling in RX path
CVE-2025-68304 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandBluetooth: hci_core: lookup hci_conn on RX path on protocol side
CVE-2025-68309 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandPCI/AER: Fix NULL pointer access by aer_info
CVE-2025-68317 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandio_uring/zctx: check chained notif contexts
CVE-2025-68311 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandtty: serial: ip22zilog: Use platform device for probing
CVE-2025-68284 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandlibceph: prevent potential out-of-bounds writes in handle_auth_session_key()
CVE-2025-68303 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandplatform/x86: intel: punit_ipc: fix memory corruption
CVE-2025-68288 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: storage: Fix memory leak in USB bulk transport
CVE-2025-68313 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandx86/CPU/AMD: Add RDSEED fix for Zen5
CVE-2025-68295 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb: client: fix memory leak in cifs_construct_tcon()
CVE-2025-68286 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Check NULL before accessing
CVE-2025-68307 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandcan: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs
CVE-2025-68322 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandparisc: Avoid crash due to unaligned access in unwinder
CVE-2025-68297 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandceph: fix crash in process_v2_sparse_read() for encrypted directories
CVE-2025-68283 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandlibceph: replace BUG_ON with bounds check for map->max_osd
CVE-2025-68285 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandlibceph: fix potential use-after-free in have_mon_and_osd_map()
CVE-2025-68282 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: udc: fix use-after-free in usb_gadget_state_work
CVE-2025-64663 ↗2025-12-18Azure Cognitive Service for LanguageCriticalOut-of-band1%Custom Question Answering Elevation of Privilege Vulnerability
CVE-2025-64675 ↗2025-12-18Azure Cosmos DBCriticalOut-of-band1%Azure Cosmos DB Spoofing Vulnerability
CVE-2025-64676 ↗2025-12-18Microsoft PurviewCriticalOut-of-band1%Microsoft Purview eDiscovery Remote Code Execution Vulnerability
CVE-2025-64677 ↗2025-12-18Office Out-of-Box ExperienceCriticalOut-of-band0%Office Out-of-Box Experience Spoofing Vulnerability
CVE-2025-65037 ↗2025-12-18Azure Container AppsCriticalOut-of-band1%Azure Container Apps Remote Code Execution Vulnerability
CVE-2025-65041 ↗2025-12-18Microsoft Partner CenterCriticalOut-of-band1%Microsoft Partner Center Elevation of Privilege Vulnerability
CVE-2025-13912 ↗2025-12-17cbl2 mariadb 10.6.24-1 on CBL Mariner 2.0LowOut-of-bandPotential non-constant time compiled code with Clang LLVM
CVE-2025-67897 ↗2025-12-17azl3 kata-containers-cc 3.15.0.aks0-6 on Azure Linux 3.0ModerateOut-of-bandIn Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.
CVE-2025-2296 ↗2025-12-17azl3 edk2 20240524git3e722403cd16-10 on Azure Linux 3.0ImportantOut-of-bandUn-verified kernel bypass Secure Boot mechanism in direct boot mode
CVE-2025-68258 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandcomedi: multiq3: sanitize config options in multiq3_attach()
CVE-2025-68188 ↗2025-12-17azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandtcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check()
CVE-2025-68217 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandInput: pegasus-notetaker - fix potential out-of-bounds access
CVE-2025-68281 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandASoC: SDCA: bug fix while parsing mipi-sdca-control-cn-list
CVE-2025-68233 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/tegra: Add call to put_pid()
CVE-2025-68222 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandpinctrl: s32cc: fix uninitialized memory in s32_pinctrl_desc
CVE-2025-68220 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: ethernet: ti: netcp: Standardize knav_dma_open_channel to return NULL on error
CVE-2025-68237 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandmtdchar: fix integer overflow in read/write ioctls
CVE-2025-68209 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandmlx5: Fix default values in create CQ
CVE-2025-68254 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandstaging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE parsing
CVE-2025-68256 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandstaging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser
CVE-2025-68206 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0CriticalOut-of-bandnetfilter: nft_ct: add seqadj extension for natted connections
CVE-2025-68257 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcomedi: check device's attached status in compat ioctls
CVE-2025-68227 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandmptcp: Fix proto fallback detection with BPF
CVE-2025-68239 ↗2025-12-17azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandbinfmt_misc: restore write access before closing files opened by open_exec()
CVE-2025-68259 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: SVM: Don't skip unrelated instruction if INT3/INTO is replaced
CVE-2025-68236 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: ufs: ufs-qcom: Fix UFS OCP issue during UFS power down (PC=3)
CVE-2025-68265 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandnvme: fix admin request_queue lifetime
CVE-2025-40355 ↗2025-12-17azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandsysfs: check visibility before changing group attribute ownership
CVE-2025-68175 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandmedia: nxp: imx8-isi: Fix streaming cleanup on release
CVE-2025-68204 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandpmdomain: arm: scmi: Fix genpd leak on provider registration failure
CVE-2025-68174 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandamd/amdkfd: enhance kfd process check in switch partition
CVE-2025-68214 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandtimers: Fix NULL function pointer race in timer_shutdown_sync()
CVE-2025-40353 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0LowOut-of-bandarm64: mte: Do not warn if the page is already tagged in copy_highpage()
CVE-2025-68261 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandext4: add i_data_sem protection in ext4_destroy_inline_data_nolock()
CVE-2025-68229 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: target: tcm_loop: Fix segfault in tcm_loop_tpg_address_show()
CVE-2025-68219 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcifs: fix memory leak in smb3_fs_context_parse_param error path
CVE-2025-68235 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandnouveau/firmware: Add missing kfree() of nvkm_falcon_fw::boot
CVE-2025-68231 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandmm/mempool: fix poisoning order>0 pages with HIGHMEM
CVE-2025-68264 ↗2025-12-17azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandext4: refresh inline data size before write operations
CVE-2025-68230 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: fix gpu page fault after hibernation on PF passthrough
CVE-2025-68263 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: ipc: fix use-after-free in ipc_msg_send_request
CVE-2025-40354 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: increase max link count and fix link->enc NULL pointer access
CVE-2025-68198 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcrash: fix crashkernel resource shrink
CVE-2025-68266 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandbfs: Reconstruct file type when loading from disk
CVE-2025-40362 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandceph: fix multifs mds auth caps issue
CVE-2025-68201 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: remove two invalid BUG_ON()s
CVE-2025-68196 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amd/display: Cache streams targeting link when performing LT automation
CVE-2025-68203 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: fix lock warning in amdgpu_userq_fence_driver_process
CVE-2025-68223 ↗2025-12-17azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-banddrm/radeon: delete radeon_fence_process in is_signaled, no deadlock
CVE-2025-68255 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandstaging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing
CVE-2025-68211 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandksm: use range-walk function to jump over holes in scan_get_next_rmap_item
CVE-2025-68190 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked()
CVE-2025-68193 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0CriticalOut-of-banddrm/xe/guc: Add devm release action to safely tear down CT
CVE-2025-68224 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandscsi: core: Fix a regression triggered by scsi_host_busy()
CVE-2025-37731 ↗2025-12-16azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandElasticsearch Improper Authentication
CVE-2025-13281 ↗2025-12-16azl3 kubernetes 1.30.10-18 on Azure Linux 3.0ModerateOut-of-bandPortworx Half-Blind SSRF in kube-controller-manager
CVE-2025-14174 ↗2025-12-15Microsoft Edge (Chromium-based)N/AOut-of-band23%CISA KEVVulnCheckENISAChromium: CVE-2025-14174 Out of bounds memory access in ANGLE
CVE-2025-40345 ↗2025-12-14azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: storage: sddr55: Reject out-of-bound new_pba
CVE-2025-14104 ↗2025-12-13cbl2 util-linux 2.37.4-9 on CBL Mariner 2.0ModerateOut-of-bandUtil-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames
CVE-2025-14523 ↗2025-12-13azl3 libsoup 3.4.4-10 on Azure Linux 3.0ImportantOut-of-bandLibsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)
CVE-2025-14512 ↗2025-12-13cbl2 glib 2.71.0-8 on CBL Mariner 2.0ModerateOut-of-bandGlib: integer overflow in glib gio attribute escaping causes heap buffer overflow
CVE-2025-14087 ↗2025-12-13azl3 glib 2.78.6-5 on Azure Linux 3.0ModerateOut-of-bandGlib: glib: buffer underflow in gvariant parser leads to heap corruption
CVE-2025-14373 ↗2025-12-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-14373 Inappropriate implementation in Toolbar
CVE-2025-14372 ↗2025-12-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-14372 Use after free in Password Manager
CVE-2025-55753 ↗2025-12-11cbl2 httpd 2.4.65-1 on CBL Mariner 2.0ModerateOut-of-bandApache HTTP Server: mod_md (ACME), unintended retry intervals
CVE-2025-58098 ↗2025-12-11azl3 httpd 2.4.65-1 on Azure Linux 3.0ImportantOut-of-bandApache HTTP Server: Server Side Includes adds query string to #exec cmd=...
CVE-2025-62408 ↗2025-12-11azl3 fluent-bit 3.1.10-2 on Azure Linux 3.0ModerateOut-of-bandc-ares has a Use After Free vulnerability when connection is cleaned up after error
CVE-2025-66471 ↗2025-12-10cbl2 python-urllib3 1.26.19-2 on CBL Mariner 2.0ImportantOut-of-bandurllib3 Streaming API improperly handles highly compressed data
CVE-2025-66418 ↗2025-12-10cbl2 python-urllib3 1.26.19-2 on CBL Mariner 2.0ImportantOut-of-bandurllib3 allows an unbounded number of links in the decompression chain
CVE-2025-40334 ↗2025-12-10azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: validate userq buffer virtual address and size
CVE-2025-40337 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: stmmac: Correctly handle Rx checksum offload errors
CVE-2025-40338 ↗2025-12-10azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandASoC: Intel: avs: Do not share the name pointer between components
CVE-2025-40340 ↗2025-12-10azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/xe: Fix oops in xe_gem_fault when running core_hotunplug test.
CVE-2025-40333 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix infinite loop in __insert_extent_tree()
CVE-2025-40329 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/sched: Fix deadlock in drm_sched_entity_kill_jobs_cb
CVE-2025-40342 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnvme-fc: use lock accessing port_state and rport state
CVE-2025-40332 ↗2025-12-10azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: Fix mmap write lock not release
CVE-2025-40336 ↗2025-12-10azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/gpusvm: fix hmm_pfn_to_map_order() usage
CVE-2025-40328 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandsmb: client: fix potential UAF in smb2_close_cached_fid()
CVE-2025-40339 ↗2025-12-10azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: fix nullptr err of vm_handle_moved
CVE-2025-40335 ↗2025-12-10azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: validate userq input args
CVE-2025-40331 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandsctp: Prevent TOCTOU out-of-bounds write
CVE-2025-40343 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnvmet-fc: avoid scheduling association deletion twice
CVE-2025-40341 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandfutex: Don't leak robust_list pointer on exec race
CVE-2025-64669 ↗2025-12-09Windows Admin CenterImportant0%Windows Admin Center Elevation of Privilege Vulnerability
CVE-2025-40324 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateNFSD: Fix crash in nfsd4_read_release()
CVE-2025-40303 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderatebtrfs: ensure no dirty metadata is written back for an fs with errors
CVE-2025-40297 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderatenet: bridge: fix use-after-free due to MST port state bypass
CVE-2025-40322 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderatefbdev: bitblit: bound-check glyph index in bit_putcs*
CVE-2025-40311 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderateaccel/habanalabs: support mapping cb with vmalloc-backed coherent memory
CVE-2025-40323 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderatefbcon: Set fb_display[i]->mode to NULL when the mode is released