Patch Day month
December 2025 vulnerabilities
A server-rendered hunting trail for December 2025: 349 returned patch records across 1 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.
349all patches
15critical
1exploitation detected
2in CISA KEV
83tracked here
Microsoft 349
Page 2 of 2 · records 201–349 of 349
Microsoft Security Response Center
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-40310 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderate—amd/amdkfd: resolve a race in amdgpu_amdkfd_device_fini_sw
CVE-2025-40294 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderate—Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern()
CVE-2025-40313 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderate—ntfs3: pretend $Extend records as regular files
CVE-2025-40304 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderate—fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds
CVE-2025-40301 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderate—Bluetooth: hci_event: validate skb length for unknown CC opcode
CVE-2025-40321 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderate—wifi: brcmfmac: fix crash while sending Action Frames in standalone AP Mode
CVE-2025-40317 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderate—regmap: slimbus: fix bus_context pointer in regmap init calls
CVE-2025-40314 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Important—usb: cdns3: gadget: Use-after-free during failed initialization and exit of cdnsp gadget
CVE-2025-40315 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderate—usb: gadget: f_fs: Fix epfile null pointer access after ep enable.
CVE-2025-40312 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Important—jfs: Verify inode mode when loading from disk
CVE-2025-40319 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Important—bpf: Sync pending IRQ work before freeing ring buffer
CVE-2025-40306 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderate—orangefs: fix xattr related buffer overflow...
CVE-2025-40292 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderate—virtio-net: fix received length check in big packets
CVE-2025-40293 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderate—iommufd: Don't overflow during division for dirty tracking
CVE-2025-40305 ↗2025-12-09azl3 kernel 6.6.117.1-1 on Azure Linux 3.0Moderate—9p/trans_fd: p9_fd_request: kick rx thread if EPOLLIN
CVE-2025-40309 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderate—Bluetooth: SCO: Fix UAF on sco_conn_free
CVE-2025-40308 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderate—Bluetooth: bcsp: receive data only if registered
CVE-2025-40307 ↗2025-12-09azl3 kernel 6.6.117.1-1 on Azure Linux 3.0Moderate—exfat: validate cluster allocation bits of the allocation bitmap
CVE-2023-53749 ↗2025-12-09azl3 kernel 6.6.117.1-1 on Azure Linux 3.0Moderate—x86: fix clear_user_rep_good() exception handling annotation
CVE-2025-54100 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant2%KB5071417KB5071501PowerShell Remote Code Execution Vulnerability
and 13 more
KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072033KB5074204KB5074353CVE-2025-55233 ↗2025-12-09Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5071413KB5071417Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-59516 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5071413KB5071417Windows Storage VSP Driver Elevation of Privilege Vulnerability
CVE-2025-59517 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5071413KB5071417Windows Storage VSP Driver Elevation of Privilege Vulnerability
CVE-2025-62221 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant2%Exploitation detectedCISA KEVVulnCheckENISAKB5071413KB5071417Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-62454 ↗2025-12-09Windows 11 Version 25H2 for ARM64-based SystemsImportant2%More likelyKB5071413KB5071417Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-62455 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071501KB5071503Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
CVE-2025-62456 ↗2025-12-09Windows 11 Version 25H2 for ARM64-based SystemsImportant1%KB5071413KB5071417Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
CVE-2025-62457 ↗2025-12-09Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5071413KB5071417Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-62458 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant1%More likelyKB5071413KB5071417Win32k Elevation of Privilege Vulnerability
CVE-2025-62461 ↗2025-12-09Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5071413KB5071417Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62462 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62463 ↗2025-12-09Windows Server 2022Important0%KB5071413KB5071417DirectX Graphics Kernel Denial of Service Vulnerability
CVE-2025-62464 ↗2025-12-09Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5071413KB5071417Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62465 ↗2025-12-09Windows Server 2022Important0%KB5071413KB5071417DirectX Graphics Kernel Denial of Service Vulnerability
CVE-2025-62466 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417Windows Client-Side Caching Elevation of Privilege Vulnerability
and 13 more
KB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033CVE-2025-62467 ↗2025-12-09Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5071413KB5071417Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62468 ↗2025-12-09Windows Server 2025 (Server Core installation)Important0%More likelyKB5071417KB5071542Windows Defender Firewall Service Information Disclosure Vulnerability
CVE-2025-62469 ↗2025-12-09Windows Server 2025 (Server Core installation)Important0%KB5072014KB5072033Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-62470 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5071413KB5071417Windows Common Log File System Driver Elevation of Privilege Vulnerability
and 13 more
KB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033CVE-2025-62472 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5071413KB5071417Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
and 13 more
KB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033CVE-2025-62473 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5071413KB5071417Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
and 13 more
KB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033CVE-2025-62474 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
and 11 more
KB5071501KB5071503KB5071505KB5071506KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033CVE-2025-62549 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5071413KB5071417Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
and 13 more
KB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033CVE-2025-62550 ↗2025-12-09Azure Monitor AgentImportant1%Azure Monitor Agent Remote Code Execution Vulnerability
CVE-2025-62552 ↗2025-12-09Microsoft Office 2019 for 32-bit editionsImportant1%KB5002812Microsoft Access Remote Code Execution Vulnerability
CVE-2025-62553 ↗2025-12-09Microsoft Office 2019 for 32-bit editionsImportant1%KB5002818KB5002820Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62554 ↗2025-12-09Microsoft Office LTSC 2024 for 64-bit editionsCritical0%KB5002819Microsoft Office Remote Code Execution Vulnerability
CVE-2025-62555 ↗2025-12-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002802KB5002804Microsoft Word Remote Code Execution Vulnerability
CVE-2025-62556 ↗2025-12-09Office Online ServerImportant1%KB5002817KB5002820Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62557 ↗2025-12-09Microsoft Office LTSC 2024 for 32-bit editionsCritical0%KB5002819Microsoft Office Remote Code Execution Vulnerability
CVE-2025-62558 ↗2025-12-09Microsoft SharePoint Enterprise Server 2016Important1%KB5002802KB5002804Microsoft Word Remote Code Execution Vulnerability
CVE-2025-62559 ↗2025-12-09Microsoft SharePoint Enterprise Server 2016Important1%KB5002802KB5002804Microsoft Word Remote Code Execution Vulnerability
CVE-2025-62560 ↗2025-12-09Office Online ServerImportant0%KB5002817KB5002820Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62561 ↗2025-12-09Office Online ServerImportant0%KB5002817KB5002818Microsoft Excel Remote Code Execution Vulnerability
and 1 more
KB5002820CVE-2025-62562 ↗2025-12-09Microsoft SharePoint Enterprise Server 2016Important1%KB5002802KB5002804Microsoft Outlook Remote Code Execution Vulnerability
CVE-2025-62563 ↗2025-12-09Office Online ServerImportant1%KB5002817KB5002818Microsoft Excel Remote Code Execution Vulnerability
and 1 more
KB5002820CVE-2025-62564 ↗2025-12-09Office Online ServerImportant0%KB5002817KB5002820Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62565 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5071413KB5071417Windows File Explorer Elevation of Privilege Vulnerability
CVE-2025-62567 ↗2025-12-09Windows 10 Version 1809 for x64-based SystemsImportant1%KB5071413KB5071417Windows Hyper-V Denial of Service Vulnerability
CVE-2025-62569 ↗2025-12-09Windows Server 2025 (Server Core installation)Important0%KB5071542KB5072014Microsoft Brokering File System Elevation of Privilege Vulnerability
and 1 more
KB5072033CVE-2025-62570 ↗2025-12-09Windows Server 2025 (Server Core installation)Important0%KB5072014KB5072033Windows Camera Frame Server Monitor Information Disclosure Vulnerability
CVE-2025-62571 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417Windows Installer Elevation of Privilege Vulnerability
and 13 more
KB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033CVE-2025-62572 ↗2025-12-09Windows Server 2025 (Server Core installation)Important0%KB5072014KB5072033Application Information Service Elevation of Privilege Vulnerability
CVE-2025-62573 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-64658 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417Windows File Explorer Elevation of Privilege Vulnerability
CVE-2025-64661 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417Windows Shell Elevation of Privilege Vulnerability
CVE-2025-64666 ↗2025-12-09Microsoft Exchange Server 2019 Cumulative Update 15Important1%KB5071873KB5071874Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-64667 ↗2025-12-09Microsoft Exchange Server Subscription Edition RTMImportant1%KB5071873KB5071874Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-64670 ↗2025-12-09Windows Server 2022Important1%KB5071413KB5071417Windows DirectX Information Disclosure Vulnerability
CVE-2025-64671 ↗2025-12-09GitHub Copilot Plugin for JetBrains IDEsImportant0%GitHub Copilot for Jetbrains Remote Code Execution Vulnerability
CVE-2025-64672 ↗2025-12-09Microsoft SharePoint Server Subscription EditionImportant1%KB5002815Microsoft SharePoint Server Spoofing Vulnerability
CVE-2025-64673 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417Windows Storage VSP Driver Elevation of Privilege Vulnerability
CVE-2025-64678 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5068779KB5068781Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
and 13 more
KB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966CVE-2025-64679 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-64680 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-40282 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: 6lowpan: reset link-local header on ipv6 recv path
CVE-2025-40279 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—net: sched: act_connmark: initialize struct tc_ife to fix kernel leak
CVE-2025-40283 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF
CVE-2025-40286 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—smb/server: fix possible memory leak in smb2_read()
CVE-2025-40285 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—smb/server: fix possible refcount leak in smb2_sess_setup()
CVE-2025-40284 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: MGMT: cancel mesh send timer when hdev removed
CVE-2025-40288 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—drm/amdgpu: Fix NULL pointer dereference in VRAM logic for APU devices
CVE-2025-40275 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—ALSA: usb-audio: Fix NULL pointer dereference in snd_usb_mixer_controls_badd
CVE-2025-40272 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-band—mm/secretmem: fix use-after-free race in fault handler
CVE-2025-40268 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—cifs: client: fix memory leak in smb3_fs_context_parse_param
CVE-2025-40278 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak
CVE-2025-40289 ↗2025-12-08azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM
CVE-2025-40287 ↗2025-12-08azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-band—exfat: fix improper check of dentry.stream.valid_size
CVE-2025-40269 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—ALSA: usb-audio: Fix potential overflow of PCM transfer buffer
CVE-2025-40281 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto
CVE-2025-40280 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—tipc: Fix use-after-free in tipc_mon_reinit_self().
CVE-2025-40277 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
CVE-2025-40273 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—NFSD: free copynotify stateid in nfs4_free_ol_stateid()
CVE-2025-59775 ↗2025-12-07cbl2 httpd 2.4.65-1 on CBL Mariner 2.0ImportantOut-of-band—Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF
CVE-2025-66200 ↗2025-12-07azl3 httpd 2.4.65-1 on Azure Linux 3.0ModerateOut-of-band—Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo
CVE-2025-65082 ↗2025-12-07azl3 httpd 2.4.65-1 on Azure Linux 3.0ModerateOut-of-band—Apache HTTP Server: CGI environment variable override
CVE-2025-65637 ↗2025-12-07cbl2 influxdb 2.6.1-27 on CBL Mariner 2.0ModerateOut-of-band—A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters.
CVE-2025-12084 ↗2025-12-06cbl2 python3 3.9.19-17 on CBL Mariner 2.0ModerateOut-of-band—Quadratic complexity in node ID cache clearing
CVE-2025-61727 ↗2025-12-06cbl2 golang 1.18.8-10 on CBL Mariner 2.0ModerateOut-of-band—Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509
CVE-2025-40263 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—Input: cros_ec_keyb - fix an invalid memory access
CVE-2025-40266 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—KVM: arm64: Check the untrusted offset in FF-A memory share
CVE-2025-40251 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-band—devlink: rate: Unset parent pointer in devl_rate_nodes_destroy
CVE-2025-40250 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—net/mlx5: Clean up only new IRQ glue on request_irq() failure
CVE-2025-40247 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—drm/msm: Fix pgtable prealloc error path
CVE-2025-40233 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-band—ocfs2: clear extent cache after moving/defragmenting extents
CVE-2025-40253 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—s390/ctcm: Fix double-kfree
CVE-2025-40264 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—be2net: pass wrb_params in case of OS2BMC
CVE-2025-40243 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits()
CVE-2025-40223 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-band—most: usb: Fix use-after-free in hdm_disconnect
CVE-2025-40248 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—vsock: Ignore signal/timeout on connect() if already established
CVE-2025-40252 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end()
CVE-2025-40244 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-band—hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent()
CVE-2025-40259 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—scsi: sg: Do not sleep in atomic context
CVE-2025-40254 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—net: openvswitch: remove never-working support for setting nsh fields
CVE-2025-40258 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-band—mptcp: fix race condition in mptcp_schedule_work()
CVE-2025-40245 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—nios2: ensure that memblock.current_limit is set when setting pfn limits
CVE-2025-40240 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-band—sctp: avoid NULL dereference when chunk data buffer is missing
CVE-2025-40257 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—mptcp: fix a race in mptcp_pm_del_add_timer()
CVE-2025-40242 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-band—gfs2: Fix unlikely race in gdlm_put_lock
CVE-2025-40261 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()
CVE-2025-40262 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-band—Input: imx_sc_key - fix memory corruption on unload
CVE-2025-12385 ↗2025-12-06cbl2 qt5-qtbase 5.12.11-18 on CBL Mariner 2.0ImportantOut-of-band—Improper validation of <img> tag size in Text component parser
CVE-2025-34297 ↗2025-12-05cbl2 tensorflow 2.11.1-2 on CBL Mariner 2.0ImportantOut-of-band—KissFFT Integer Overflow Heap Buffer Overflow via kiss_fft_alloc
CVE-2025-10543 ↗2025-12-05cbl2 influxdb 2.6.1-24 on CBL Mariner 2.0ModerateOut-of-band—In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly encoded if their length exceeds 65535 bytes. This may lead to unexpected content in packets sent to the server (for example, part of an MQTT topic may leak into the message body in a PUBLISH packet).
The issue arises because the length of the data passed in was converted from an int64/int32 (depending upon CPU) to an int16 without checks for overflows. The int16 length was then written, followed by the data (e.g. topic). This meant that when the data (e.g. topic) was over 65535 bytes then the amount of data written exceeds what the length field indicates. This could lead to a corrupt packet, or mean that the excess data leaks into another field (e.g. topic leaks into message body).
CVE-2025-40219 ↗2025-12-05azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV
CVE-2025-40220 ↗2025-12-05azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—fuse: fix livelock in synchronous file put from fuseblk workers
CVE-2025-40217 ↗2025-12-05azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—pidfs: validate extensible ioctls
CVE-2025-40218 ↗2025-12-05azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—mm/damon/vaddr: do not repeat pte_offset_map_lock() until success
CVE-2025-40215 ↗2025-12-05azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—xfrm: delete x->tunnel as we delete x
CVE-2025-66476 ↗2025-12-05azl3 vim 9.1.1616-1 on Azure Linux 3.0ImportantOut-of-band—Vim for Windows Uncontrolled Search Path Element Remote Code Execution Vulnerability
CVE-2025-13837 ↗2025-12-05cbl2 python3 3.9.19-16 on CBL Mariner 2.0LowOut-of-band—Out-of-memory when loading Plist
CVE-2025-13836 ↗2025-12-05cbl2 python3 3.9.19-16 on CBL Mariner 2.0ModerateOut-of-band—Excessive read buffering DoS in http.client
CVE-2025-12819 ↗2025-12-05cbl2 pgbouncer 1.24.1-1 on CBL Mariner 2.0ImportantOut-of-band—Untrusted search path in auth_query connection in PgBouncer
CVE-2025-66293 ↗2025-12-05cbl2 libpng 1.6.51-1 on CBL Mariner 2.0ImportantOut-of-band—LIBPNG has an out-of-bounds read in png_image_read_composite
CVE-2025-61729 ↗2025-12-05cbl2 python-tensorboard 2.11.0-3 on CBL Mariner 2.0ImportantOut-of-band—Excessive resource consumption when printing error string for host certificate validation in crypto/x509
CVE-2025-13640 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13640 Inappropriate implementation in Passwords
CVE-2025-13639 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13639 Inappropriate implementation in WebRTC
CVE-2025-13638 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13638 Use after free in Media Stream
CVE-2025-13637 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13637 Inappropriate implementation in Downloads
CVE-2025-13636 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13636 Inappropriate implementation in Split View
CVE-2025-13635 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13635 Inappropriate implementation in Downloads
CVE-2025-13720 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13720 Bad cast in Loader
CVE-2025-13721 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13721 Race in v8
CVE-2025-13634 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13634 Inappropriate implementation in Downloads
CVE-2025-13633 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13633 Use after free in Digital Credentials
CVE-2025-13632 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13632 Inappropriate implementation in DevTools
CVE-2025-13631 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13631 Inappropriate implementation in Google Updater
CVE-2025-13630 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13630 Type Confusion in V8
CVE-2025-62223 ↗2025-12-04Microsoft Edge (Chromium-based)LowOut-of-band0%Microsoft Edge (Chromium-based) for Mac Spoofing Vulnerability
The next page could not be added in place. The ordinary page link remains available; try it again to navigate normally.