Patch Day month
May 2026 vulnerabilities
A server-rendered hunting trail for May 2026: 2,180 returned patch records across 4 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.
2,180all patches
140critical
3exploitation detected
4in CISA KEV
544tracked here
Microsoft 1,128Red Hat 1,032Cisco 19Android 1
Page 2 of 11 · records 201–400 of 2,180
Microsoft Security Response Center
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-46187 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: rsi: fix kthread lifetime race between self-exit and external-stop
CVE-2026-46241 ↗2026-05-29azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—spi: mpc52xx: fix use-after-free on registration failure
CVE-2026-46153 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—8021q: delete cleared egress QoS mappings
CVE-2026-46156 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang()
CVE-2026-46227 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL
CVE-2026-46112 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—RDMA/hns: Fix unlocked call to hns_roce_qp_remove()
CVE-2026-46122 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: b43: enforce bounds check on firmware key index in b43_rx()
CVE-2026-46114 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads
CVE-2026-46233 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—batman-adv: bla: only purge non-released claims
CVE-2026-46125 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: mac80211: remove station if connection prep fails
CVE-2026-46146 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3()
CVE-2026-46204 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/amdgpu/vcn4: Prevent OOB reads when parsing IB
CVE-2026-46120 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ip6_gre: Use cached t->net in ip6erspan_changelink().
CVE-2026-46152 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: mac80211: drop stray 'static' from fast-RX rx_result
CVE-2026-46238 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—batman-adv: stop caching unowned originator pointers in BAT IV
CVE-2026-46133 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—RDMA/rxe: Reject unknown opcodes before ICRC processing
CVE-2026-46218 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/amdgpu: Add bounds checking to ib_{get,set}_value
CVE-2026-46108 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ipmi:si: Return state to normal if message allocation fails
CVE-2026-46123 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-band—Bluetooth: virtio_bt: clamp rx length before skb_put
CVE-2026-46143 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-band—ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens
CVE-2026-46145 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—RDMA/mana: Validate rx_hash_key_len
CVE-2026-46230 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg
CVE-2026-46190 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()
CVE-2026-46170 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—mptcp: pm: ADD_ADDR rtx: free sk if last
CVE-2026-46129 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—btrfs: fix double free in create_space_info() error path
CVE-2026-46175 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—f2fs: fix fsck inconsistency caused by FGGC of node block
CVE-2026-46136 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: mt76: mt7921: fix a potential clc buffer length underflow
CVE-2026-46157 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger
CVE-2026-46155 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—smb/client: fix out-of-bounds read in smb2_compound_op()
CVE-2026-46177 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ipmi: Add limits to event and receive message requests
CVE-2026-46132 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo
CVE-2026-46196 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()
CVE-2026-46127 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp()
CVE-2026-46235 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—media: saa7164: add ioremap return checks and cleanups
CVE-2026-46164 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—btrfs: fix double free in create_space_info_sub_group() error path
CVE-2026-46236 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—media: rc: xbox_remote: heed DMA restrictions
CVE-2026-46116 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete
CVE-2026-46225 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—spi: rspi: fix controller deregistration
CVE-2026-46179 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ASoC: SOF: Don't allow pointer operations on unconfigured streams
CVE-2026-46208 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—batman-adv: stop tp_meter sessions during mesh teardown
CVE-2026-46149 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show()
CVE-2026-46176 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init()
CVE-2026-46107 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—dm-thin: fix metadata refcount underflow
CVE-2026-46171 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—riscv: kvm: fix vector context allocation leak
CVE-2026-46234 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—vsock: fix buffer size clamping order
CVE-2026-46205 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—staging: media: atomisp: Disallow all private IOCTLs
CVE-2026-46220 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission
CVE-2026-46197 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/amdkfd: validate SVM ioctl nattr against buffer size
CVE-2026-46232 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—HID: playstation: Clamp num_touch_reports
CVE-2026-46158 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—mptcp: pm: ADD_ADDR rtx: always decrease sk refcount
CVE-2026-46212 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—batman-adv: bla: prevent use-after-free when deleting claims
CVE-2026-46165 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—openvswitch: vport: fix self-deadlock on release of tunnel ports
CVE-2026-46161 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—md/raid10: fix divide-by-zero in setup_geo() with zero far_copies
CVE-2026-46226 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—spi: fsl: fix controller deregistration
CVE-2026-46185 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—smb/client: fix out-of-bounds read in symlink_data()
CVE-2026-46159 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak
CVE-2026-46191 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band—fbcon: Avoid OOB font access if console rotation fails
CVE-2026-46115 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—block: add pgmap check to biovec_phys_mergeable
CVE-2026-46180 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task
CVE-2026-42250 ↗2026-05-29azl3 bzip2 1.0.8-1 on Azure Linux 3.0ModerateOut-of-band—Off-by-One Leading to Out-of-Bounds Write in bzip2
CVE-2026-46160 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—btrfs: fix missing last_unlink_trans update when removing a directory
CVE-2026-46173 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—exit: prevent preemption of oopsing TASK_DEAD task
CVE-2026-46128 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ipmi: Check event message buffer response for bad data
CVE-2026-46229 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure
CVE-2026-46109 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—usb: ulpi: fix memory leak on ulpi_register() error paths
CVE-2026-46194 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—f2fs: fix node_cnt race between extent node destroy and writeback
CVE-2026-46110 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: stmmac: Prevent NULL deref when RX memory exhausted
CVE-2026-46195 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—smb: client: validate dacloffset before building DACL pointers
CVE-2026-46131 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—KVM: x86: check for nEPT/nNPT in slow flush hypercalls
CVE-2026-46111 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: hci_conn: fix potential UAF in create_big_sync
CVE-2026-46163 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: b43legacy: enforce bounds check on firmware key index in RX path
CVE-2026-46198 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—batman-adv: fix integer overflow on buff_pos
CVE-2026-46168 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—mptcp: fix scheduling with atomic in timestamp sockopt
CVE-2026-46148 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—spi: microchip-core-qspi: control built-in cs manually
CVE-2026-46172 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ipv6: xfrm6: release dst on error in xfrm6_rcv_encap()
CVE-2026-46186 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: virtio_bt: validate rx pkt_type header length
CVE-2026-46209 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()
CVE-2026-46137 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—mptcp: pm: ADD_ADDR rtx: fix potential data-race
CVE-2026-46200 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—spi: mpc52xx: fix controller deregistration
CVE-2026-46214 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—vsock/virtio: fix accept queue count leak on transport mismatch
CVE-2026-46231 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—batman-adv: bla: put backbone reference on failed claim hash insert
CVE-2026-46219 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—spi: mpc52xx: fix use-after-free on unbind
CVE-2026-46094 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access
CVE-2026-46076 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1
CVE-2026-46003 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: qrtr: ns: Limit the total number of nodes
CVE-2026-46006 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/nouveau: fix u32 overflow in pushbuf reloc bounds check
CVE-2026-46026 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: qrtr: ns: Limit the maximum number of lookups
CVE-2025-71305 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-band—drm/display/dp_mst: Add protection against 0 vcpi
CVE-2026-46000 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—rxrpc: Fix conn-level packet handling to unshare RESPONSE packets
CVE-2026-46016 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—remoteproc: xlnx: Only access buffer information if IPI is buffered
CVE-2026-46102 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: strparser: fix skb_head leak in strp_abort_strp()
CVE-2026-45993 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—LoongArch: Add spectre boundry for syscall dispatch table
CVE-2026-46022 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt()
CVE-2026-46082 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0
CVE-2026-45892 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band—ext4: drop extent cache after doing PARTIAL_VALID1 zeroout
CVE-2026-45844 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: arp_tables: fix IEEE1394 ARP payload parsing
CVE-2026-46023 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-band—dm mirror: fix integer overflow in create_dirty_log()
CVE-2026-46090 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ALSA: aloop: Fix peer runtime UAF during format-change stop
CVE-2026-45963 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—ASoC: nau8821: Cancel delayed work on component remove
CVE-2026-45998 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—rxrpc: Fix potential UAF after skb_unshare() failure
CVE-2026-46024 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply()
CVE-2026-45934 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—btrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation
CVE-2026-45858 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1
CVE-2026-45843 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—slip: bound decode() reads against the compressed packet length
CVE-2026-46015 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—tcp: call sk_data_ready() after listener migration
CVE-2026-46068 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx
CVE-2026-45987 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2
CVE-2026-46056 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: hci_event: fix potential UAF in SSP passkey handlers
CVE-2026-45956 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band—drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl()
CVE-2026-46083 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—spi: fix resource leaks on device setup failure
CVE-2026-46063 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—x86/shstk: Prevent deadlock during shstk sigreturn
CVE-2026-46077 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—crypto: atmel-tdes - fix DMA sync direction
CVE-2026-46099 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels
CVE-2026-45861 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—gfs2: Fix slab-use-after-free in qd_put
CVE-2026-46079 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—rbd: fix null-ptr-deref when device_add_disk() fails
CVE-2026-46098 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: caif: clear client service pointer on teardown
CVE-2026-46065 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info
CVE-2026-46086 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: bridge: use a stable FDB dst snapshot in RCU readers
CVE-2026-46014 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—KVM: SVM: Add missing save/restore handling of LBR MSRs
CVE-2026-45845 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net/sched: taprio: fix NULL pointer dereference in class dump
CVE-2026-46101 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: reject zero shift in nft_bitwise
CVE-2026-46044 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-band—ipmi:ssif: Clean up kthread on errors
CVE-2026-46072 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ntfs3: add buffer boundary checks to run_unpack()
CVE-2026-45949 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—hwrng: core - use RCU and work_struct to fix race condition
CVE-2026-45842 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—slip: reject VJ receive packets on instances with no rstate array
CVE-2026-46032 ↗2026-05-28azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—KVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT
CVE-2026-46092 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: rtw88: check for PCI upstream bridge existence
CVE-2026-46019 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup
CVE-2026-45859 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation
CVE-2026-45988 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—rxrpc: Fix re-decryption of RESPONSE packets
CVE-2026-46103 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—can: ucan: fix devres lifetime
CVE-2026-45942 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band—ext4: fix e4b bitmap inconsistency reports
CVE-2026-46040 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails
CVE-2026-45996 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—spi: imx: fix use-after-free on unbind
CVE-2026-46069 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup()
CVE-2026-45994 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ibmasm: fix OOB reads in command_file_write due to missing size checks
CVE-2026-46043 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
CVE-2026-46038 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: qrtr: ns: Free the node during ctrl_cmd_bye()
CVE-2026-46070 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—md/raid5: validate payload size before accessing journal metadata
CVE-2026-46052 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ceph: only d_add() negative dentries when they are unhashed
CVE-2026-45570 ↗2026-05-28azl3 packer 1.9.5-13 on Azure Linux 3.0LowOut-of-band—go-git: Improper single-quote escaping in go-git SSH transport
CVE-2026-45850 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ipvs: skip ipv6 extension headers for csum checks
CVE-2026-45571 ↗2026-05-28azl3 packer 1.9.5-13 on Azure Linux 3.0ModerateOut-of-band—go-git: Crafted repositories may modify main and submodule .git directories
CVE-2026-46047 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: qrtr: ns: Fix use-after-free in driver remove()
CVE-2026-47104 ↗2026-05-28azl3 libgusb 0.3.5-3 on Azure Linux 3.0LowOut-of-band—libusb < 1.0.30 Out-of-Bounds Read in parse_iad_array()
CVE-2026-45986 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—crypto: ccree - fix a memory leak in cc_mac_digest()
CVE-2026-23679 ↗2026-05-28azl3 libgusb 0.3.5-3 on Azure Linux 3.0ModerateOut-of-band—libusb < 1.0.30 NULL Pointer Dereference in parse_interface()
CVE-2026-46009 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown
CVE-2026-46046 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all()
CVE-2026-45997 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails
CVE-2026-46033 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—crypto: authencesn - reject short ahash digests during instance creation
CVE-2026-46089 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—zram: do not forget to endio for partial discard requests
CVE-2026-46017 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—mm: fix deferred split queue races during migration
CVE-2026-45897 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: nft_counter: serialize reset with spinlock
CVE-2026-45943 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—erofs: fix inline data read failure for ztailpacking pclusters
CVE-2026-45846 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst()
CVE-2026-44899 ↗2026-05-28azl3 python-mistune 3.0.2-1 on Azure Linux 3.0ModerateOut-of-band—Mistune Image Directive CSS Injection Vulnerability
CVE-2026-45958 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band—drm/exynos: vidi: fix to avoid directly dereferencing user pointer
CVE-2026-44898 ↗2026-05-28azl3 python-mistune 3.0.2-1 on Azure Linux 3.0ModerateOut-of-band—Mistune TOC Anchor Injection XSS
CVE-2026-45893 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-band—apparmor: Fix & Optimize table creation from possibly unaligned memory
CVE-2026-44897 ↗2026-05-28azl3 python-mistune 3.0.2-1 on Azure Linux 3.0ModerateOut-of-band—Mistune Heading ID Attribute Injection XSS
CVE-2026-46091 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—media: rc: igorplugusb: heed coherency rules
CVE-2026-44708 ↗2026-05-28azl3 python-mistune 3.0.2-1 on Azure Linux 3.0ModerateOut-of-band—Mistune Math Plugin XSS Escape Bypass
CVE-2026-45940 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: stmmac: fix oops when split header is enabled
CVE-2026-44896 ↗2026-05-28azl3 python-mistune 3.0.2-1 on Azure Linux 3.0LowOut-of-band—Mistune: XSS via unescaped figclass/figwidth in Figure directive
CVE-2026-45839 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec()
CVE-2026-44844 ↗2026-05-28azl3 perl-XML-Parser 2.47-2 on Azure Linux 3.0ModerateOut-of-band—eml_parser: Recursion DoS via nested message/rfc822 attachments
CVE-2026-45961 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—gfs2: fix memory leaks in gfs2_fill_super error path
CVE-2026-45836 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()
CVE-2026-45932 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—bpf: Fix tcx/netkit detach permissions when prog fd isn't given
CVE-2026-45834 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb()
CVE-2026-45944 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—iommu/vt-d: Clear Present bit before tearing down context entry
CVE-2026-45835 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb()
CVE-2026-45999 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap()
CVE-2026-45912 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band—ext4: don't cache extent during splitting extent
CVE-2026-46018 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES
CVE-2026-46053 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: rds: fix MR cleanup on copy error
CVE-2026-46051 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—md/raid5: fix soft lockup in retry_aligned_read()
CVE-2026-46031 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: ks8851: Reinstate disabling of BHs around IRQ handler
CVE-2026-46088 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names()
CVE-2026-46027 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net/smc: avoid early lgr access in smc_clc_wait_msg
Cross-vendor patches
VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2025-13465CVSS 8.2Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-monitoring-plugin-rhel9@sha256:67d9273bfa159a5c4911e356c06d992ad3ed91f7b090bacfcb198133f234b0d6_s390xPatch ↗Advisory ↗
Red HatCVE-2025-58183CVSS 7.5Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-dpu-cni-rhel9@sha256:32c2dd7f3a21c4eb4da50044c5c3d260f955c0add58ca43a0a3ca6fbd80466ca_s390xPatch ↗Advisory ↗
Red HatCVE-2025-61731CVSS 8.6Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:313c0e44208e7fc7d4039f2f22cd01135db0cd3337a258034b774fd7820d8a98_s390xPatch ↗Advisory ↗
Red HatCVE-2026-1526CVSS 7.5Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:1a687d78104fa92356a6af1ef4b5564d8bfd8fa9bc1b02b7ccbdc598be190654_s390xPatch ↗Advisory ↗
Red HatCVE-2026-1528CVSS 7.5Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:1a687d78104fa92356a6af1ef4b5564d8bfd8fa9bc1b02b7ccbdc598be190654_s390xPatch ↗Advisory ↗
Red HatCVE-2026-2229CVSS 7.5Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:1a687d78104fa92356a6af1ef4b5564d8bfd8fa9bc1b02b7ccbdc598be190654_s390xPatch ↗Advisory ↗
Red HatCVE-2026-24049CVSS 7.1Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:12e5769722f41cfff3ec88000d157eafee309fe3e7262beb93ee1a26eca26740_s390xPatch ↗Advisory ↗
Red HatCVE-2026-25679CVSS 7.5Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:313c0e44208e7fc7d4039f2f22cd01135db0cd3337a258034b774fd7820d8a98_s390xPatch ↗Advisory ↗
Red HatCVE-2026-29063CVSS 8.8Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-monitoring-plugin-rhel9@sha256:67d9273bfa159a5c4911e356c06d992ad3ed91f7b090bacfcb198133f234b0d6_s390xPatch ↗Advisory ↗
Red HatCVE-2026-29063CVSS 8.8Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:1a687d78104fa92356a6af1ef4b5564d8bfd8fa9bc1b02b7ccbdc598be190654_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-csi-driver-nfs-rhel9@sha256:7d1f571b87ba1e197285c78a78ac4dcffa55ac4e6382ecf10ed630abd02e4df0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:a38d8ed8b5ea31126b1f2238db1e790ea01a154949187bfe355c21a76f789462_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9@sha256:0b165040657b16770b52a0cde7be46db0d6410e6d502b11e7b6053f9ad441c49_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:f4100f181620f5424e66633dbdd3c7402c8db75f93c54fe092ff2301d8dd0015_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33211CVSS 9.6Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9@sha256:0b165040657b16770b52a0cde7be46db0d6410e6d502b11e7b6053f9ad441c49_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33211CVSS 9.6Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:f4100f181620f5424e66633dbdd3c7402c8db75f93c54fe092ff2301d8dd0015_amd64Patch ↗Advisory ↗
Red HatCVE-2026-34986CVSS 7.5Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9@sha256:0b165040657b16770b52a0cde7be46db0d6410e6d502b11e7b6053f9ad441c49_amd64Patch ↗Advisory ↗
Red HatCVE-2026-34986CVSS 7.5Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:f4100f181620f5424e66633dbdd3c7402c8db75f93c54fe092ff2301d8dd0015_amd64Patch ↗Advisory ↗
Red HatCVE-2026-35469CVSS 6.5Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:78dd3a2b6a0f6323b1bb6ba04e7651cdbbe6f09752433f49de045eda0532a1e0_amd64Patch ↗Advisory ↗
The next page could not be added in place. The ordinary page link remains available; try it again to navigate normally.