CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Patch Day month

May 2026 vulnerabilities

A defender-focused view of 1,824 vulnerabilities across 4,941 returned patch records from 4 vendors. Filter the complete month, or browse the static page trail without JavaScript.

4,941all patch recordsClear filters160criticalShow these records3Microsoft exploitation detectedShow these records4Microsoft in CISA KEVShow these records682tracked hereShow these records

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as “no.” “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.

Page 16 of 25 · records 3,001–3,200 of 4,941

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-46153 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band8021q: delete cleared egress QoS mappings
CVE-2026-46156 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandLoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang()
CVE-2026-46227 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandsctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL
CVE-2026-46112 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/hns: Fix unlocked call to hns_roce_qp_remove()
CVE-2026-46122 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: b43: enforce bounds check on firmware key index in b43_rx()
CVE-2026-46114 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads
CVE-2026-46233 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: bla: only purge non-released claims
CVE-2026-46125 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: remove station if connection prep fails
CVE-2026-46146 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3()
CVE-2026-46204 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu/vcn4: Prevent OOB reads when parsing IB
CVE-2026-46120 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandip6_gre: Use cached t->net in ip6erspan_changelink().
CVE-2026-46152 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: drop stray 'static' from fast-RX rx_result
CVE-2026-46238 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: stop caching unowned originator pointers in BAT IV
CVE-2026-46133 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/rxe: Reject unknown opcodes before ICRC processing
CVE-2026-46218 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: Add bounds checking to ib_{get,set}_value
CVE-2026-46108 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipmi:si: Return state to normal if message allocation fails
CVE-2026-46145 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mana: Validate rx_hash_key_len
CVE-2026-46230 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg
CVE-2026-46190 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()
CVE-2026-46170 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmptcp: pm: ADD_ADDR rtx: free sk if last
CVE-2026-46129 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix double free in create_space_info() error path
CVE-2026-46175 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix fsck inconsistency caused by FGGC of node block
CVE-2026-46136 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mt76: mt7921: fix a potential clc buffer length underflow
CVE-2026-46157 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger
CVE-2026-46155 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb/client: fix out-of-bounds read in smb2_compound_op()
CVE-2026-46177 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipmi: Add limits to event and receive message requests
CVE-2026-46132 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo
CVE-2026-46196 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandtracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()
CVE-2026-46127 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp()
CVE-2026-46235 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmedia: saa7164: add ioremap return checks and cleanups
CVE-2026-46164 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix double free in create_space_info_sub_group() error path
CVE-2026-46236 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmedia: rc: xbox_remote: heed DMA restrictions
CVE-2026-46116 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: defensively unhash xfrm_state lists in __xfrm_state_delete
CVE-2026-46225 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: rspi: fix controller deregistration
CVE-2026-46179 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandASoC: SOF: Don't allow pointer operations on unconfigured streams
CVE-2026-46208 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: stop tp_meter sessions during mesh teardown
CVE-2026-46149 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show()
CVE-2026-46176 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init()
CVE-2026-46107 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddm-thin: fix metadata refcount underflow
CVE-2026-46171 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandriscv: kvm: fix vector context allocation leak
CVE-2026-46234 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandvsock: fix buffer size clamping order
CVE-2026-46205 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandstaging: media: atomisp: Disallow all private IOCTLs
CVE-2026-46220 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission
CVE-2026-46197 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: validate SVM ioctl nattr against buffer size
CVE-2026-46232 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandHID: playstation: Clamp num_touch_reports
CVE-2026-46158 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmptcp: pm: ADD_ADDR rtx: always decrease sk refcount
CVE-2026-46212 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: bla: prevent use-after-free when deleting claims
CVE-2026-46165 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandopenvswitch: vport: fix self-deadlock on release of tunnel ports
CVE-2026-46161 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmd/raid10: fix divide-by-zero in setup_geo() with zero far_copies
CVE-2026-46226 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: fsl: fix controller deregistration
CVE-2026-46185 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb/client: fix out-of-bounds read in symlink_data()
CVE-2026-46159 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak
CVE-2026-46115 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandblock: add pgmap check to biovec_phys_mergeable
CVE-2026-46180 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task
CVE-2026-42250 ↗azl3 bzip2 1.0.8-1 on Azure Linux 3.0ModerateOut-of-bandOff-by-One Leading to Out-of-Bounds Write in bzip2
CVE-2026-46160 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix missing last_unlink_trans update when removing a directory
CVE-2026-46173 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandexit: prevent preemption of oopsing TASK_DEAD task
CVE-2026-46128 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipmi: Check event message buffer response for bad data
CVE-2026-46229 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: Clear VRAM on allocation to prevent stale data exposure
CVE-2026-46109 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: ulpi: fix memory leak on ulpi_register() error paths
CVE-2026-46194 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix node_cnt race between extent node destroy and writeback
CVE-2026-46110 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: stmmac: Prevent NULL deref when RX memory exhausted
CVE-2026-46195 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb: client: validate dacloffset before building DACL pointers
CVE-2026-46131 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: x86: check for nEPT/nNPT in slow flush hypercalls
CVE-2026-46111 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: hci_conn: fix potential UAF in create_big_sync
CVE-2026-46163 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: b43legacy: enforce bounds check on firmware key index in RX path
CVE-2026-46198 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: fix integer overflow on buff_pos
CVE-2026-46168 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmptcp: fix scheduling with atomic in timestamp sockopt
CVE-2026-46148 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: microchip-core-qspi: control built-in cs manually
CVE-2026-46172 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: xfrm6: release dst on error in xfrm6_rcv_encap()
CVE-2026-46186 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: virtio_bt: validate rx pkt_type header length
CVE-2026-46209 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()
CVE-2026-46137 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmptcp: pm: ADD_ADDR rtx: fix potential data-race
CVE-2026-46200 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: mpc52xx: fix controller deregistration
CVE-2026-46214 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandvsock/virtio: fix accept queue count leak on transport mismatch
CVE-2026-46231 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: bla: put backbone reference on failed claim hash insert
CVE-2026-46219 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: mpc52xx: fix use-after-free on unbind
CVE-2026-46094 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandext4: fix bounds check in check_xattrs() to prevent out-of-bounds access
CVE-2026-46076 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1
CVE-2026-46003 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: qrtr: ns: Limit the total number of nodes
CVE-2026-46006 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/nouveau: fix u32 overflow in pushbuf reloc bounds check
CVE-2026-46026 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: qrtr: ns: Limit the maximum number of lookups
CVE-2026-46000 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix conn-level packet handling to unshare RESPONSE packets
CVE-2026-46016 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandremoteproc: xlnx: Only access buffer information if IPI is buffered
CVE-2026-46102 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: strparser: fix skb_head leak in strp_abort_strp()
CVE-2026-45993 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandLoongArch: Add spectre boundry for syscall dispatch table
CVE-2026-46022 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmisc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt()
CVE-2026-46082 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0
CVE-2026-45844 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: arp_tables: fix IEEE1394 ARP payload parsing
CVE-2026-46090 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: aloop: Fix peer runtime UAF during format-change stop
CVE-2026-45963 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandASoC: nau8821: Cancel delayed work on component remove
CVE-2026-45998 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix potential UAF after skb_unshare() failure
CVE-2026-46024 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandlibceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply()
CVE-2026-45934 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation
CVE-2026-45858 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1
CVE-2026-45843 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandslip: bound decode() reads against the compressed packet length
CVE-2026-46015 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandtcp: call sk_data_ready() after listener migration
CVE-2026-46068 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx
CVE-2026-45987 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2
CVE-2026-46056 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: hci_event: fix potential UAF in SSP passkey handlers
CVE-2026-46083 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: fix resource leaks on device setup failure
CVE-2026-46063 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandx86/shstk: Prevent deadlock during shstk sigreturn
CVE-2026-46077 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: atmel-tdes - fix DMA sync direction
CVE-2026-46099 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels
CVE-2026-45861 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandgfs2: Fix slab-use-after-free in qd_put
CVE-2026-46079 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandrbd: fix null-ptr-deref when device_add_disk() fails
CVE-2026-46098 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: caif: clear client service pointer on teardown
CVE-2026-46065 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandfbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info
CVE-2026-46086 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: bridge: use a stable FDB dst snapshot in RCU readers
CVE-2026-46014 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: SVM: Add missing save/restore handling of LBR MSRs
CVE-2026-45845 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: taprio: fix NULL pointer dereference in class dump
CVE-2026-46101 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: reject zero shift in nft_bitwise
CVE-2026-46072 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandntfs3: add buffer boundary checks to run_unpack()
CVE-2026-45949 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandhwrng: core - use RCU and work_struct to fix race condition
CVE-2026-45842 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandslip: reject VJ receive packets on instances with no rstate array
CVE-2026-46032 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT
CVE-2026-46092 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: rtw88: check for PCI upstream bridge existence
CVE-2026-46019 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup
CVE-2026-45859 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation
CVE-2026-45988 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix re-decryption of RESPONSE packets
CVE-2026-46103 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: ucan: fix devres lifetime
CVE-2026-46040 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandinotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails
CVE-2026-45996 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: imx: fix use-after-free on unbind
CVE-2026-46069 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup()
CVE-2026-45994 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandibmasm: fix OOB reads in command_file_write due to missing size checks
CVE-2026-46043 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
CVE-2026-46038 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: qrtr: ns: Free the node during ctrl_cmd_bye()
CVE-2026-46070 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmd/raid5: validate payload size before accessing journal metadata
CVE-2026-46052 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandceph: only d_add() negative dentries when they are unhashed
CVE-2026-45850 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipvs: skip ipv6 extension headers for csum checks
CVE-2026-45571 ↗azl3 packer 1.9.5-13 on Azure Linux 3.0ModerateOut-of-bandgo-git: Crafted repositories may modify main and submodule .git directories
CVE-2026-46047 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: qrtr: ns: Fix use-after-free in driver remove()
CVE-2026-45986 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: ccree - fix a memory leak in cc_mac_digest()
CVE-2026-23679 ↗azl3 libgusb 0.3.5-3 on Azure Linux 3.0ModerateOut-of-bandlibusb < 1.0.30 NULL Pointer Dereference in parse_interface()
CVE-2026-46009 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandPCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown
CVE-2026-46046 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all()
CVE-2026-45997 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: sd: fix missing put_disk() when device_add(&disk_dev) fails
CVE-2026-46033 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: authencesn - reject short ahash digests during instance creation
CVE-2026-46089 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandzram: do not forget to endio for partial discard requests
CVE-2026-46017 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmm: fix deferred split queue races during migration
CVE-2026-45897 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_counter: serialize reset with spinlock
CVE-2026-45943 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: fix inline data read failure for ztailpacking pclusters
CVE-2026-45846 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst()
CVE-2026-44899 ↗azl3 python-mistune 3.0.2-1 on Azure Linux 3.0ModerateOut-of-bandMistune Image Directive CSS Injection Vulnerability
CVE-2026-44898 ↗azl3 python-mistune 3.0.2-1 on Azure Linux 3.0ModerateOut-of-bandMistune TOC Anchor Injection XSS
CVE-2026-44897 ↗azl3 python-mistune 3.0.2-1 on Azure Linux 3.0ModerateOut-of-bandMistune Heading ID Attribute Injection XSS
CVE-2026-46091 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmedia: rc: igorplugusb: heed coherency rules
CVE-2026-44708 ↗azl3 python-mistune 3.0.2-1 on Azure Linux 3.0ModerateOut-of-bandMistune Math Plugin XSS Escape Bypass
CVE-2026-45940 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: stmmac: fix oops when split header is enabled
CVE-2026-45839 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: reject negative CO-RE accessor indices in bpf_core_parse_spec()
CVE-2026-44844 ↗azl3 perl-XML-Parser 2.47-2 on Azure Linux 3.0ModerateOut-of-bandeml_parser: Recursion DoS via nested message/rfc822 attachments
CVE-2026-45961 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandgfs2: fix memory leaks in gfs2_fill_super error path
CVE-2026-45836 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()
CVE-2026-45932 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix tcx/netkit detach permissions when prog fd isn't given
CVE-2026-45834 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb()
CVE-2026-45944 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandiommu/vt-d: Clear Present bit before tearing down context entry
CVE-2026-45835 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb()
CVE-2026-45999 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: fix unsigned underflow in z_erofs_lz4_handle_overlap()
CVE-2026-46018 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES
CVE-2026-46053 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: rds: fix MR cleanup on copy error
CVE-2026-46051 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmd/raid5: fix soft lockup in retry_aligned_read()
CVE-2026-46031 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: ks8851: Reinstate disabling of BHs around IRQ handler
CVE-2026-46088 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names()
CVE-2026-46027 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/smc: avoid early lgr access in smc_clc_wait_msg
CVE-2026-45991 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandudf: fix partition descriptor append bookkeeping
CVE-2026-46058 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmedia: amphion: Fix race between m2m job_abort and device_run
CVE-2026-46054 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandselinux: fix overlayfs mmap() and mprotect() access checks
CVE-2026-45855 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandata: libata-scsi: avoid Non-NCQ command starvation
CVE-2026-45840 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandopenvswitch: cap upcall PID array size and pre-size vport replies
CVE-2026-45989 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandof: unittest: fix use-after-free in testdrv_probe()
CVE-2026-46066 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandceph: fix num_ops off-by-one when crypto allocation fails
CVE-2026-45894 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandiommu/vt-d: Clear Present bit before tearing down PASID entry
CVE-2026-46080 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandocfs2: split transactions in dio completion to avoid credit exhaustion
CVE-2026-46049 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: ctxfi: Add fallback to default RSR for S/PDIF
CVE-2026-45901 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_tables: revert commit_mutex usage in reset path
CVE-2026-46059 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN
CVE-2026-46071 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: nSVM: Avoid clearing VMCB_LBR in vmcb12
CVE-2026-46085 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix rxkad crypto unalignment handling
CVE-2026-46012 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix memory leaks in rxkad_verify_response()
CVE-2026-46084 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mana_ib: Disable RX steering on RSS QP destroy
CVE-2026-46037 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipv4: icmp: validate reply type before using icmp_pointers
CVE-2026-46021 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandthermal: core: Fix thermal zone governor cleanup issues
CVE-2026-45838 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: fix end-of-list detection in cgroup_storage_get_next_key()
CVE-2026-45930 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: mctp: ensure our nlmsg responses are initialised
CVE-2026-46005 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandxfs: fix a resource leak in xfs_alloc_buftarg()
CVE-2026-45973 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mlx5: Fix UMR hang in LAG error state unload
CVE-2026-46062 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandntfs3: fix integer overflow in run_unpack() volume boundary check
CVE-2026-46075 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: atmel-sha204a - Fix potential UAF and memory leak in remove path
CVE-2026-45841 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO
CVE-2026-45917 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipvs: do not keep dest_dst if dev is going down
CVE-2026-45877 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ModerateOut-of-bandHID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients
CVE-2026-46064 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandibmasm: fix heap over-read in ibmasm_send_i2o_message()
CVE-2026-46078 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: fix the out-of-bounds nameoff handling for trailing dirents
CVE-2026-46011 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmedia: mtk-jpeg: fix use-after-free in release path due to uncancelled work
CVE-2026-46002 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandext2: reject inodes with zero i_nlink and valid mode in ext2_iget()
CVE-2026-46050 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmd/raid10: fix deadlock with check operation and nowait requests
CVE-2026-46048 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: caiaq: fix usb_dev refcount leak on probe failure

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-35469CVSS 6.5Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:78dd3a2b6a0f6323b1bb6ba04e7651cdbbe6f09752433f49de045eda0532a1e0_amd64Patch ↗Advisory ↗
Red HatCVE-2025-38653CVSS 5.1Red Hat Enterprise Linux AppStream (v. 9)kernel-64k-debug-debuginfo-0:5.14.0-687.12.1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-0636CVSS 6.5Red Hat OpenShift Dev Spaces 3.28registry.redhat.io/devspaces/openvsx-rhel9@sha256:341c8f0f91bd41d4bded00443cd7ab2ddab4972a5ee1ddff4dcbfcdd5c2764f4_arm64Patch ↗Advisory ↗