Patch Day month
June 2026 vulnerabilities
A server-rendered hunting trail for June 2026: 2,939 returned patch records across 4 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.
2,939all patches
205critical
0exploitation detected
1in CISA KEV
809tracked here
Red Hat 1,504Microsoft 1,282Android 144Cisco 9
Page 3 of 15 · records 401–600 of 2,939
Microsoft Security Response Center
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-53226 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—gpio: rockchip: fix generic IRQ chip leak on remove
CVE-2026-53048 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—gfs2: prevent NULL pointer dereference during unmount
CVE-2026-49851 ↗2026-06-27azl3 python-mistune 3.2.1-1 on Azure Linux 3.0ImportantOut-of-band0%Mistune: Potential DoS via quadratic-time parsing in parse_link_text
CVE-2026-53023 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band—fs/ntfs3: terminate the cached volume label after UTF-8 conversion
CVE-2026-53002 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-band—netfilter: conntrack: remove sprintf usage
CVE-2026-53128 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—drbd: Balance RCU calls in drbd_adm_dump_devices()
CVE-2026-53075 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-band—ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
CVE-2026-53037 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—HID: usbhid: fix deadlock in hid_post_reset()
CVE-2026-53068 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band—drm/komeda: fix integer overflow in AFBC framebuffer size check
CVE-2026-53183 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—mptcp: allow subflow rcv wnd to shrink
CVE-2026-53160 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-band—misc: fastrpc: fix use-after-free race in fastrpc_map_create
CVE-2026-52925 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—vrf: Fix a potential NPD when removing a port from a VRF
CVE-2026-53010 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-band—ksmbd: fix use-after-free in smb2_open during durable reconnect
CVE-2026-53208 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
CVE-2026-53006 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ipv6: fix possible UAF in icmpv6_rcv()
CVE-2026-53066 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/sun4i: backend: fix error pointer dereference
CVE-2026-53041 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ocfs2: fix listxattr handling when the buffer is full
CVE-2026-53064 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—dm cache: fix null-deref with concurrent writes in passthrough mode
CVE-2026-53228 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—ipv6: sit: reload inner IPv6 header after GSO offloads
CVE-2026-53258 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: fix leak if split 6 GHz scanning fails
CVE-2026-52969 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—KVM: Reject wrapped offset in kvm_reset_dirty_gfn()
CVE-2026-53225 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
CVE-2026-53109 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—powerpc/pgtable-frag: Fix bad page state in pte_frag_destroy
CVE-2026-53047 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—efi/capsule-loader: fix incorrect sizeof in phys array reallocation
CVE-2026-53220 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: revalidate bridge ports
CVE-2026-53011 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net/sched: taprio: fix use-after-free in advance_sched() on schedule switch
CVE-2026-53039 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band—ocfs2: validate group add input before caching
CVE-2026-53110 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—s390/bpf: Zero-extend bpf prog return values and kfunc arguments
CVE-2026-52937 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR
CVE-2026-52977 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—futex: Prevent lockup in requeue-PI during signal/ timeout wakeup
CVE-2026-53190 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
CVE-2026-53132 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—vsock/virtio: fix potential unbounded skb queue
CVE-2026-53096 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
CVE-2026-53262 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-band—l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()
CVE-2026-53245 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
CVE-2026-53061 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—dm cache: fix dirty mapping checking in passthrough mode switching
CVE-2026-52961 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
CVE-2026-53077 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-band—net/rds: Restrict use of RDS/IB to the initial network namespace
CVE-2026-52989 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-band—nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers
CVE-2026-53107 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-band—wifi: libertas: don't kill URBs in interrupt context
CVE-2026-53088 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
CVE-2026-53000 ↗2026-06-27azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band—netfilter: nat: use kfree_rcu to release ops
CVE-2026-52999 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: nfnetlink_osf: fix out-of-bounds read on option matching
CVE-2026-53122 ↗2026-06-27azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—btrfs: fix deadlock between reflink and transaction commit when using flushoncommit
CVE-2026-53168 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—fuse: reject fuse_notify() pagecache ops on directories
CVE-2026-52963 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ALSA: usb-audio: Bound MIDI endpoint descriptor scans
CVE-2026-53097 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-band—wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work()
CVE-2026-53214 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—ipv6: Fix a potential NPD in cleanup_prefix_route()
CVE-2026-53045 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-band—memory: tegra124-emc: Fix dll_change check
CVE-2026-52992 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—fs/adfs: validate nzones in adfs_validate_bblk()
CVE-2026-53035 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—bpf, sockmap: Fix af_unix iter deadlock
CVE-2026-52936 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—crypto: jitterentropy - replace long-held spinlock with mutex
CVE-2026-53237 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—gpio: mvebu: fix NULL pointer dereference in suspend/resume
CVE-2026-53073 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error
CVE-2026-53113 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: ath11k: fix memory leaks in beacon template setup
CVE-2026-52929 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—sctp: stream: fully roll back denied add-stream state
CVE-2026-53148 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—thunderbolt: Clamp XDomain response data copy to allocation size
CVE-2026-53218 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: nft_exthdr: fix register tracking for F_PRESENT flag
CVE-2026-52922 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-band—batman-adv: dat: handle forward allocation error
CVE-2026-52954 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—libceph: handle rbtree insertion error in decode_choose_args()
CVE-2026-53166 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock
CVE-2026-53032 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—bpf: Fix NULL deref in map_kptr_match_type for scalar regs
CVE-2026-53093 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: brcmfmac: Fix error pointer dereference
CVE-2026-53179 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—staging: rtl8723bs: fix buffer over-read in rtw_update_protection
CVE-2026-52946 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
CVE-2026-53265 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—dm cache policy smq: check allocation under invalidate lock
CVE-2026-53003 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—pppoe: drop PFC frames
CVE-2026-53049 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-band—gfs2: add some missing log locking
CVE-2026-53255 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: MGMT: validate advertising TLV before type checks
CVE-2026-53015 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—erofs: unify lcn as u64 for 32-bit platforms
CVE-2026-53009 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-band—ice: fix double-free of tx_buf skb
CVE-2026-53098 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()
CVE-2026-52919 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-band—batman-adv: fix tp_meter counter underflow during shutdown
CVE-2026-53062 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-band—dm cache policy smq: fix missing locks in invalidating cache blocks
CVE-2026-53076 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—bpf: Fix OOB in pcpu_init_value
CVE-2026-53198 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-band—ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL
CVE-2026-53078 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
CVE-2026-52968 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic
CVE-2026-53082 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf
CVE-2026-53133 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—RDMA/umem: Fix truncation for block sizes >= 4G
CVE-2026-52920 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: xt_policy: fix strict mode inbound policy matching
CVE-2026-52996 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open
CVE-2026-52974 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: tls: fix strparser anchor skb leak on offload RX setup failure
CVE-2026-52960 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—ceph: put folios not suitable for writeback
CVE-2026-53192 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—ALSA: timer: Fix UAF at snd_timer_user_params()
CVE-2026-53072 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER
CVE-2026-53209 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
CVE-2026-53063 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—dm cache: fix write hang in passthrough mode
CVE-2026-52911 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band—ksmbd: scope conn->binding slowpath to bound sessions only
CVE-2026-52957 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—libceph: Fix potential null-ptr-deref in decode_choose_args()
CVE-2026-53275 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—ipv6: mcast: Fix use-after-free when processing MLD queries
CVE-2026-53060 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—dm cache metadata: fix memory leak on metadata abort retry
CVE-2026-52942 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: nf_log: validate MAC header was set before dumping it
CVE-2026-53139 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/v3d: Skip CSD when it has zeroed workgroups
CVE-2026-53267 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: nft_ct: bail out on template ct in get eval
CVE-2026-53178 ↗2026-06-27azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction
CVE-2026-53249 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
CVE-2026-53143 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-band—drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
CVE-2026-53177 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—bnxt_en: Fix NULL pointer dereference
CVE-2026-52923 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-band—ipc: limit next_id allocation to the valid ID range
CVE-2026-53184 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—udp: clear skb->dev before running a sockmap verdict
CVE-2026-52943 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-band—net: skbuff: fix missing zerocopy reference in pskb_carve helpers
CVE-2026-53131 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: require Ethernet MAC header before using eth_hdr()
CVE-2026-52934 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-band—batman-adv: tvlv: reject oversized TVLV packets
CVE-2026-53151 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—rxrpc: Fix the ACK parser to extract the SACK table for parsing
CVE-2026-52918 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: serialize accept_q access
CVE-2026-53052 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-band—ASoC: qcom: qdsp6: topology: check widget type before accessing data
CVE-2026-54905 ↗2026-06-27azl3 rubygem-concurrent-ruby 1.2.2-1 on Azure Linux 3.0LowOut-of-band—concurrent-ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity
CVE-2026-53120 ↗2026-06-27azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—PCI: use generic driver_override infrastructure
CVE-2026-53158 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—misc: fastrpc: Fix NULL pointer dereference in rpmsg callback
CVE-2025-15661 ↗2026-06-27azl3 libssh2 1.11.1-2 on Azure Linux 3.0ModerateOut-of-band—libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c
CVE-2026-53089 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-band—bpf: Fix use-after-free in offloaded map/prog info fill
CVE-2026-54906 ↗2026-06-27azl3 rubygem-concurrent-ruby 1.2.2-1 on Azure Linux 3.0LowOut-of-band—concurrent-ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption
CVE-2026-53181 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—vsock/vmci: fix sk_ack_backlog leak on failed handshake
CVE-2026-53017 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-band—f2fs: fix data loss caused by incorrect use of nat_entry flag
CVE-2026-47242 ↗2026-06-27azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-band—Net::IMAP: Command Injection via ID command argument
CVE-2026-53246 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-band—sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
CVE-2026-47240 ↗2026-06-27azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-band—Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-53018 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-band—f2fs: avoid reading already updated pages during GC
CVE-2026-55200 ↗2026-06-27azl3 libssh2 1.11.1-3 on Azure Linux 3.0CriticalOut-of-band—libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
CVE-2026-53163 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
CVE-2026-53086 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-band—net: bcmgenet: fix racing timeout handler
CVE-2026-47241 ↗2026-06-27azl3 ruby 3.3.5-8 on Azure Linux 3.0LowOut-of-band—Net::IMAP: Denial of Service via incomplete raw argument validation
CVE-2026-53022 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—platform/x86: dell-wmi-sysman: bound enumeration string aggregation
CVE-2026-48715 ↗2026-06-27azl3 radvd 2.19-1 on Azure Linux 3.0ImportantOut-of-band—radvdump's Route Information Option Parser has a Stack Buffer Overflow
CVE-2026-53150 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—thunderbolt: Reject zero-length property entries in validator
CVE-2026-53115 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—bus: fsl-mc: use generic driver_override infrastructure
CVE-2026-53254 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: RFCOMM: validate skb length in MCC handlers
CVE-2026-53013 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF
CVE-2026-53149 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—thunderbolt: Bound root directory content to block size
CVE-2026-3196 ↗2026-06-27azl3 qemu 9.1.0-8 on Azure Linux 3.0ModerateOut-of-band—Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
CVE-2026-55199 ↗2026-06-27azl3 libssh 0.10.6-8 on Azure Linux 3.0ImportantOut-of-band—libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler
CVE-2026-52924 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—sctp: purge outqueue on stale COOKIE-ECHO handling
CVE-2026-3195 ↗2026-06-27azl3 qemu 9.1.0-8 on Azure Linux 3.0ImportantOut-of-band—Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730)
CVE-2026-52916 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—batman-adv: frag: disallow unicast fragment in fragment
CVE-2026-53161 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
CVE-2026-53194 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-band—USB: serial: kl5kusb105: fix bulk-out buffer overflow
CVE-2026-0864 ↗2026-06-27azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-band—Configuration Injection via Carriage Return (\r) in write() method
CVE-2026-9539 ↗2026-06-27azl3 libslirp 4.7.0-1 on Azure Linux 3.0ModerateOut-of-band—libslirp TCP URG OOB Read Information Leak
CVE-2026-53126 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current()
CVE-2026-52956 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-band—libceph: Fix potential out-of-bounds access in __ceph_x_decrypt()
CVE-2026-52915 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: ip6t_hbh: reject oversized option lists
CVE-2026-11972 ↗2026-06-27azl3 tensorflow 2.16.1-11 on Azure Linux 3.0ImportantOut-of-band—tarfile opened in streaming mode mishandles EOF
CVE-2026-47770 ↗2026-06-27azl3 jq 1.7.1-6 on Azure Linux 3.0ModerateOut-of-band—jq: stack overflow in deep structural equality
CVE-2026-53065 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ASoC: sti: use managed regmap_field allocations
CVE-2026-53182 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: nl80211: reject oversized EMA RNR lists
CVE-2026-53138 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/amd/display: Bound VBIOS record-chain walk loops
CVE-2026-54679 ↗2026-06-27azl3 jq 1.7.1-6 on Azure Linux 3.0ModerateOut-of-band—jq: potential integer overflow in jvp_string_append
CVE-2026-53264 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—net/sched: act_api: use RCU with deferred freeing for action lifecycle
CVE-2026-52986 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: nf_conntrack_sip: don't use simple_strtoul
CVE-2026-49839 ↗2026-06-27azl3 jq 1.7.1-8 on Azure Linux 3.0ImportantOut-of-band—jq --rawfile invalid-state reuse after String too long causes heap-buffer-overflow
CVE-2026-53274 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
CVE-2026-55203 ↗2026-06-27azl3 haproxy 2.9.11-6 on Azure Linux 3.0ImportantOut-of-band—HAProxy - Integer Overflow in FCGI Demux Record Length Field
CVE-2026-53146 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—thunderbolt: Limit XDomain response copy to actual frame size
CVE-2026-9697 ↗2026-06-27azl3 nodejs 24.14.1-3 on Azure Linux 3.0ImportantOut-of-band—undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
CVE-2026-53043 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-band—ocfs2/dlm: validate qr_numregions in dlm_match_regions()
CVE-2026-55204 ↗2026-06-27azl3 haproxy 2.9.11-6 on Azure Linux 3.0ImportantOut-of-band—HAProxy - NULL Pointer Dereference in hpack_dht_insert Function
CVE-2026-53159 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-band—misc: fastrpc: fix DMA address corruption due to find_vma misuse
CVE-2026-52917 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—sctp: diag: reject stale associations in dump_one path
CVE-2026-56131 ↗2026-06-27azl3 cmake 3.30.3-13 on Azure Linux 3.0ModerateOut-of-band—libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
CVE-2026-53147 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—thunderbolt: Validate XDomain request packet size before type cast
CVE-2026-53118 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—vdpa: use generic driver_override infrastructure
CVE-2026-53094 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—bpf: Fix stale offload->prog pointer after constant blinding
CVE-2026-9675 ↗2026-06-27azl3 nodejs 24.14.1-3 on Azure Linux 3.0ImportantOut-of-band—undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
CVE-2026-53112 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet
CVE-2026-56412 ↗2026-06-27azl3 cmake 3.30.3-14 on Azure Linux 3.0ModerateOut-of-band—libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
CVE-2026-52993 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-band—tipc: fix double-free in tipc_buf_append()
CVE-2026-52975 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—bonding: 3ad: implement proper RCU rules for port->aggregator
CVE-2026-53137 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
CVE-2026-53230 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
CVE-2026-56410 ↗2026-06-27azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-band—xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-53236 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—tcp: restrict SO_ATTACH_FILTER to priv users
CVE-2026-52933 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—io_uring/poll: fix signed comparison in io_poll_get_ownership()
CVE-2026-56409 ↗2026-06-27azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-band—xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-53012 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—nexthop: fix IPv6 route referencing IPv4 nexthop
CVE-2026-52982 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()
CVE-2026-56411 ↗2026-06-27azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-band—xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-53024 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—greybus: raw: fix use-after-free if write is called after disconnect
CVE-2026-53238 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—netlabel: validate unlabeled address and mask attribute lengths
CVE-2026-56132 ↗2026-06-27azl3 cmake 3.30.3-13 on Azure Linux 3.0ModerateOut-of-band—In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
CVE-2026-53266 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: bridge: make ebt_snat ARP rewrite writable
CVE-2026-55653 ↗2026-06-27azl3 openssh 9.8p1-6 on Azure Linux 3.0ModerateOut-of-band—Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service
CVE-2026-52913 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-band—batman-adv: v: stop OGMv2 on disabled interface
CVE-2026-52931 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-band—batman-adv: tp_meter: avoid use of uninit sender vars
CVE-2026-55655 ↗2026-06-27azl3 openssh 9.8p1-6 on Azure Linux 3.0ModerateOut-of-band—Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions
CVE-2026-53242 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
CVE-2026-56403 ↗2026-06-27azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-band—libexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-53213 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/vc4: fix krealloc() memory leak
CVE-2026-11525 ↗2026-06-27azl3 nodejs 24.17.0-1 on Azure Linux 3.0LowOut-of-band—undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
CVE-2026-53071 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
CVE-2026-53270 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—ipvs: clear the svc scheduler ptr early on edit
CVE-2026-53227 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—net: openvswitch: fix possible kfree_skb of ERR_PTR
CVE-2026-53027 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-band—fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked()
CVE-2026-56407 ↗2026-06-27azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-band—libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVE-2026-52981 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—neigh: let neigh_xmit take skb ownership
CVE-2026-52921 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: ipset: stop hash:* range iteration at end
CVE-2026-48142 ↗2026-06-27azl3 nginx 1.28.3-4 on Azure Linux 3.0ModerateOut-of-band—NGINX ngx_http_charset_module vulnerability
CVE-2026-53212 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: nft_tunnel: fix use-after-free on object destroy
CVE-2026-53129 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—fs/mbcache: cancel shrink work before destroying the cache
CVE-2026-56406 ↗2026-06-27azl3 cmake 3.30.3-13 on Azure Linux 3.0ModerateOut-of-band—libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
The next page could not be added in place. The ordinary page link remains available; try it again to navigate normally.