CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Patch Day month

June 2026 vulnerabilities

A defender-focused view of 2,270 vulnerabilities across 5,771 returned patch records from 4 vendors. Filter the complete month, or browse the static page trail without JavaScript.

5,771all patch recordsClear filters270criticalShow these records0Microsoft exploitation detectedShow these records1Microsoft in CISA KEVShow these records885tracked hereShow these records

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as “no.” “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.

Page 20 of 29 · records 3,801–4,000 of 5,771

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-53034 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf, sockmap: Fix af_unix null-ptr-deref in proto update
CVE-2026-53102 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()
CVE-2026-53056 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/msm/dpu: fix mismatch between power and frequency
CVE-2026-53058 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable()
CVE-2026-53016 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: ccp - copy IV using skcipher ivsize
CVE-2026-53080 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: cls_fw: fix NULL dereference of "old" filters before change()
CVE-2026-53219 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: x_tables: avoid leaking percpu counter pointers
CVE-2026-53135 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
CVE-2026-52998 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nfnetlink_osf: fix potential NULL dereference in ttl check
CVE-2026-53050 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandquota: Fix race of dquot_scan_active() with quota deactivation
CVE-2026-57436 ↗azl3 rubygem-nokogiri 1.15.4-1 on Azure Linux 3.0ModerateOut-of-bandNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
CVE-2026-52958 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandlibceph: Fix potential out-of-bounds access in osdmap_decode()
CVE-2026-53091 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: pull headers in qdisc_pkt_len_segs_init()
CVE-2026-53232 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: phy: clean the sfp upstream if phy probing fails
CVE-2026-57437 ↗azl3 rubygem-nokogiri 1.15.4-1 on Azure Linux 3.0ModerateOut-of-bandNokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
CVE-2026-53074 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb
CVE-2026-53186 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/srp: bound SRP_RSP sense copy by the received length
CVE-2026-53217 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: mvpp2: sync RX data at the hardware packet offset
CVE-2026-52930 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandipc/shm: serialize orphan cleanup with shm_nattch updates
CVE-2026-53199 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandhv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf
CVE-2026-57438 ↗azl3 rubygem-nokogiri 1.15.4-1 on Azure Linux 3.0ModerateOut-of-bandNokogiri: Possible Use-After-Free in XInclude Processing
CVE-2026-52928 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandaf_unix: Reject SIOCATMARK on non-stream sockets
CVE-2026-52927 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ebtables: fix OOB read in compat_mtw_from_user
CVE-2026-53046 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix use-after-free from async crypto on Qualcomm crypto engine
CVE-2026-53268 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: conntrack_irc: fix possible out-of-bounds read
CVE-2026-53167 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandfuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
CVE-2026-52967 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb/client: fix possible infinite loop and oob read in symlink_data()
CVE-2026-52964 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans
CVE-2026-53106 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Do not allow deleting local storage in NMI
CVE-2026-53111 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap
CVE-2026-52970 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_ct: fix missing expect put in obj eval
CVE-2026-53226 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandgpio: rockchip: fix generic IRQ chip leak on remove
CVE-2026-53048 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandgfs2: prevent NULL pointer dereference during unmount
CVE-2026-53128 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrbd: Balance RCU calls in drbd_adm_dump_devices()
CVE-2026-53037 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandHID: usbhid: fix deadlock in hid_post_reset()
CVE-2026-53183 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandmptcp: allow subflow rcv wnd to shrink
CVE-2026-52925 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandvrf: Fix a potential NPD when removing a port from a VRF
CVE-2026-53208 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
CVE-2026-53006 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: fix possible UAF in icmpv6_rcv()
CVE-2026-53066 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/sun4i: backend: fix error pointer dereference
CVE-2026-53041 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandocfs2: fix listxattr handling when the buffer is full
CVE-2026-53064 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddm cache: fix null-deref with concurrent writes in passthrough mode
CVE-2026-53228 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: sit: reload inner IPv6 header after GSO offloads
CVE-2026-53258 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: fix leak if split 6 GHz scanning fails
CVE-2026-52969 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: Reject wrapped offset in kvm_reset_dirty_gfn()
CVE-2026-53225 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandsctp: fix uninit-value in __sctp_rcv_asconf_lookup()
CVE-2026-53109 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandpowerpc/pgtable-frag: Fix bad page state in pte_frag_destroy
CVE-2026-53047 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandefi/capsule-loader: fix incorrect sizeof in phys array reallocation
CVE-2026-53220 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: revalidate bridge ports
CVE-2026-53011 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: taprio: fix use-after-free in advance_sched() on schedule switch
CVE-2026-53110 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bands390/bpf: Zero-extend bpf prog return values and kfunc arguments
CVE-2026-52937 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandtap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR
CVE-2026-52977 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandfutex: Prevent lockup in requeue-PI during signal/ timeout wakeup
CVE-2026-53190 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
CVE-2026-53132 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandvsock/virtio: fix potential unbounded skb queue
CVE-2026-53096 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
CVE-2026-53245 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
CVE-2026-53061 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddm cache: fix dirty mapping checking in passthrough mode switching
CVE-2026-52961 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
CVE-2026-53088 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: bcmgenet: fix off-by-one in bcmgenet_put_txcb
CVE-2026-52999 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nfnetlink_osf: fix out-of-bounds read on option matching
CVE-2026-53122 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix deadlock between reflink and transaction commit when using flushoncommit
CVE-2026-53168 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandfuse: reject fuse_notify() pagecache ops on directories
CVE-2026-52963 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: usb-audio: Bound MIDI endpoint descriptor scans
CVE-2026-53214 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: Fix a potential NPD in cleanup_prefix_route()
CVE-2026-52992 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandfs/adfs: validate nzones in adfs_validate_bblk()
CVE-2026-53035 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf, sockmap: Fix af_unix iter deadlock
CVE-2026-52936 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: jitterentropy - replace long-held spinlock with mutex
CVE-2026-53237 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandgpio: mvebu: fix NULL pointer dereference in suspend/resume
CVE-2026-53073 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error
CVE-2026-53113 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: ath11k: fix memory leaks in beacon template setup
CVE-2026-52929 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandsctp: stream: fully roll back denied add-stream state
CVE-2026-53148 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandthunderbolt: Clamp XDomain response data copy to allocation size
CVE-2026-53218 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_exthdr: fix register tracking for F_PRESENT flag
CVE-2026-52954 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandlibceph: handle rbtree insertion error in decode_choose_args()
CVE-2026-53166 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandfutex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock
CVE-2026-53032 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix NULL deref in map_kptr_match_type for scalar regs
CVE-2026-53093 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: brcmfmac: Fix error pointer dereference
CVE-2026-53179 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandstaging: rtl8723bs: fix buffer over-read in rtw_update_protection
CVE-2026-52946 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandfs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
CVE-2026-53265 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddm cache policy smq: check allocation under invalidate lock
CVE-2026-53003 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandpppoe: drop PFC frames
CVE-2026-53255 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: MGMT: validate advertising TLV before type checks
CVE-2026-53015 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: unify lcn as u64 for 32-bit platforms
CVE-2026-53098 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()
CVE-2026-53076 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix OOB in pcpu_init_value
CVE-2026-53078 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
CVE-2026-52968 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic
CVE-2026-53082 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: hamradio: 6pack: fix uninit-value in sixpack_receive_buf
CVE-2026-53133 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/umem: Fix truncation for block sizes >= 4G
CVE-2026-52920 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: xt_policy: fix strict mode inbound policy matching
CVE-2026-52996 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open
CVE-2026-52974 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: tls: fix strparser anchor skb leak on offload RX setup failure
CVE-2026-52960 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandceph: put folios not suitable for writeback
CVE-2026-53192 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: timer: Fix UAF at snd_timer_user_params()
CVE-2026-53072 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER
CVE-2026-53209 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: hci_sync: reject oversized Broadcast Announcement prepend
CVE-2026-53063 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddm cache: fix write hang in passthrough mode
CVE-2026-52957 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandlibceph: Fix potential null-ptr-deref in decode_choose_args()
CVE-2026-53275 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: mcast: Fix use-after-free when processing MLD queries
CVE-2026-53060 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddm cache metadata: fix memory leak on metadata abort retry
CVE-2026-52942 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_log: validate MAC header was set before dumping it
CVE-2026-53139 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/v3d: Skip CSD when it has zeroed workgroups
CVE-2026-53267 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_ct: bail out on template ct in get eval
CVE-2026-53178 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandstaging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction
CVE-2026-53249 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
CVE-2026-53177 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandbnxt_en: Fix NULL pointer dereference
CVE-2026-53184 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandudp: clear skb->dev before running a sockmap verdict
CVE-2026-53131 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: require Ethernet MAC header before using eth_hdr()
CVE-2026-53151 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix the ACK parser to extract the SACK table for parsing
CVE-2026-52918 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: serialize accept_q access
CVE-2026-53120 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandPCI: use generic driver_override infrastructure
CVE-2026-53158 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandmisc: fastrpc: Fix NULL pointer dereference in rpmsg callback
CVE-2025-15661 ↗azl3 libssh2 1.11.1-2 on Azure Linux 3.0ModerateOut-of-bandlibssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c
CVE-2026-53181 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandvsock/vmci: fix sk_ack_backlog leak on failed handshake
CVE-2026-47242 ↗azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-bandNet::IMAP: Command Injection via ID command argument
CVE-2026-47240 ↗azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-bandNet::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-53163 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandlocking/rtmutex: Skip remove_waiter() when waiter is not enqueued
CVE-2026-53022 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandplatform/x86: dell-wmi-sysman: bound enumeration string aggregation
CVE-2026-53150 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandthunderbolt: Reject zero-length property entries in validator
CVE-2026-53115 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandbus: fsl-mc: use generic driver_override infrastructure
CVE-2026-53254 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: RFCOMM: validate skb length in MCC handlers
CVE-2026-53013 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmacvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF
CVE-2026-53149 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandthunderbolt: Bound root directory content to block size
CVE-2026-3196 ↗azl3 qemu 9.1.0-8 on Azure Linux 3.0ModerateOut-of-bandQemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
CVE-2026-52924 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandsctp: purge outqueue on stale COOKIE-ECHO handling
CVE-2026-52916 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: frag: disallow unicast fragment in fragment
CVE-2026-53161 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandmisc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
CVE-2026-0864 ↗azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-bandConfiguration Injection via Carriage Return (\r) in write() method
CVE-2026-9539 ↗azl3 libslirp 4.7.0-1 on Azure Linux 3.0ModerateOut-of-bandlibslirp TCP URG OOB Read Information Leak
CVE-2026-53126 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandblk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current()
CVE-2026-52915 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ip6t_hbh: reject oversized option lists
CVE-2026-47770 ↗azl3 jq 1.7.1-6 on Azure Linux 3.0ModerateOut-of-bandjq: stack overflow in deep structural equality
CVE-2026-53065 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandASoC: sti: use managed regmap_field allocations
CVE-2026-53182 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: nl80211: reject oversized EMA RNR lists
CVE-2026-53138 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Bound VBIOS record-chain walk loops
CVE-2026-54679 ↗azl3 jq 1.7.1-6 on Azure Linux 3.0ModerateOut-of-bandjq: potential integer overflow in jvp_string_append
CVE-2026-53264 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: act_api: use RCU with deferred freeing for action lifecycle
CVE-2026-52986 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_conntrack_sip: don't use simple_strtoul
CVE-2026-53274 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
CVE-2026-53146 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandthunderbolt: Limit XDomain response copy to actual frame size
CVE-2026-52917 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandsctp: diag: reject stale associations in dump_one path
CVE-2026-56131 ↗azl3 cmake 3.30.3-13 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
CVE-2026-53147 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandthunderbolt: Validate XDomain request packet size before type cast
CVE-2026-53118 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandvdpa: use generic driver_override infrastructure
CVE-2026-53094 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix stale offload->prog pointer after constant blinding
CVE-2026-53112 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet
CVE-2026-56412 ↗azl3 cmake 3.30.3-14 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
CVE-2026-52975 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbonding: 3ad: implement proper RCU rules for port->aggregator
CVE-2026-53137 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
CVE-2026-53230 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
CVE-2026-56410 ↗azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandxmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-53236 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandtcp: restrict SO_ATTACH_FILTER to priv users
CVE-2026-52933 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandio_uring/poll: fix signed comparison in io_poll_get_ownership()
CVE-2026-56409 ↗azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandxmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-53012 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnexthop: fix IPv6 route referencing IPv4 nexthop
CVE-2026-52982 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()
CVE-2026-56411 ↗azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandxmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-53024 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandgreybus: raw: fix use-after-free if write is called after disconnect
CVE-2026-53238 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetlabel: validate unlabeled address and mask attribute lengths
CVE-2026-56132 ↗azl3 cmake 3.30.3-13 on Azure Linux 3.0ModerateOut-of-bandIn libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
CVE-2026-53266 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: bridge: make ebt_snat ARP rewrite writable
CVE-2026-55653 ↗azl3 openssh 9.8p1-6 on Azure Linux 3.0ModerateOut-of-bandOpenssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service
CVE-2026-55655 ↗azl3 openssh 9.8p1-6 on Azure Linux 3.0ModerateOut-of-bandOpenssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions
CVE-2026-53242 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
CVE-2026-56403 ↗azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-53213 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/vc4: fix krealloc() memory leak
CVE-2026-53071 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
CVE-2026-53270 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandipvs: clear the svc scheduler ptr early on edit
CVE-2026-53227 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: openvswitch: fix possible kfree_skb of ERR_PTR
CVE-2026-56407 ↗azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVE-2026-52981 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandneigh: let neigh_xmit take skb ownership
CVE-2026-52921 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ipset: stop hash:* range iteration at end
CVE-2026-48142 ↗azl3 nginx 1.28.3-4 on Azure Linux 3.0ModerateOut-of-bandNGINX ngx_http_charset_module vulnerability
CVE-2026-53212 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_tunnel: fix use-after-free on object destroy
CVE-2026-53129 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandfs/mbcache: cancel shrink work before destroying the cache
CVE-2026-56406 ↗azl3 cmake 3.30.3-13 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
CVE-2026-13201 ↗azl3 kubevirt 1.7.1-7 on Azure Linux 3.0ModerateOut-of-bandKubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption
CVE-2026-53207 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandmm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison
CVE-2026-53059 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddm log: fix out-of-bounds write due to region_count overflow
CVE-2026-56404 ↗azl3 python3 3.12.9-13 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-12725 ↗azl3 dnsmasq 2.92-1 on Azure Linux 3.0ModerateOut-of-bandDnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies
CVE-2026-12969 ↗azl3 dnsmasq 2.92-1 on Azure Linux 3.0ModerateOut-of-bandDnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation
CVE-2026-53136 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Clamp VBIOS HDMI retimer register count to array size
CVE-2026-53239 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
CVE-2026-56405 ↗azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-56115 ↗azl3 dhcpcd 10.0.8-1 on Azure Linux 3.0ModerateOut-of-bandBootimus 0.1.70 Broken Access Control via JWTMiddleware Authorization Bypass
CVE-2026-53195 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandUSB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
CVE-2026-53021 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: target: core: Fix integer overflow in UNMAP bounds check
CVE-2026-56116 ↗azl3 dhcpcd 10.0.8-4 on Azure Linux 3.0ModerateOut-of-banddhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling
CVE-2026-52948 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandi2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
CVE-2026-4367 ↗azl3 libXpm 3.5.17-1 on Azure Linux 3.0ModerateOut-of-bandLibxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-42250CVSS 5.0Red Hat Hardened Imagesbzip2-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4367CVSS 5.5Red Hat Hardened Imageslibxpm-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-57452CVSS 4.7Red Hat Hardened Imagesvim-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-57455CVSS 4.7Red Hat Hardened Imagesvim-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2023-40403CVSS 6.5Red Hat Enterprise Linux AppStream E4S (v.9.2)libxslt-0:1.1.34-12.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-10911CVSS 5.5Red Hat Enterprise Linux AppStream EUS (v.9.6)libxslt-0:1.1.34-13.el9_6.2.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-10911CVSS 5.5Red Hat Enterprise Linux AppStream EUS (v. 10.0)libxslt-0:1.1.39-8.el10_0.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-10911CVSS 5.5Red Hat Enterprise Linux AppStream E4S (v.9.2)libxslt-0:1.1.34-12.el9_2.aarch64Patch ↗Advisory ↗