CYBERSECURITYTRACKER
TRACKING3,612 stories653 vuln stories
Patch Day month

July 2026 vulnerabilities

A server-rendered hunting trail for July 2026: 4,551 returned patch records across 3 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.

4,551all patches
189critical
3exploitation detected
4in CISA KEV
1,850tracked here
Red Hat 2,465Microsoft 2,070Cisco 16

Page 6 of 23 · records 1,001–1,200 of 4,551

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-64370 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandposix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path
CVE-2026-64359 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandnilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers
CVE-2026-64363 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandHID: appleir: fix UAF on pending key_up_timer in remove()
CVE-2026-64508 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandbpf: Support for hardening against JIT spraying
CVE-2026-64380 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandsmb: client: harden POSIX SID length parsing
CVE-2026-64373 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandcpufreq: Fix hotplug-suspend race during reboot
CVE-2026-64512 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-bandACPI: CPPC: Suppress UBSAN warning caused by field misuse
CVE-2026-64392 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%ksmbd: use opener credentials for delete-on-close
CVE-2026-64389 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandksmbd: validate NTLMv2 response before updating session key
CVE-2026-64434 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
CVE-2026-64483 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandALSA: firewire: isight: bound the sample count to the packet payload
CVE-2026-64503 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandiio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
CVE-2026-64269 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band1%RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
CVE-2026-64337 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: mtu3: unmap request DMA on queue failure
CVE-2026-64371 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandproc: protect ptrace_may_access() with exec_update_lock (part 1)
CVE-2026-64406 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: fix UAF in bt_accept_dequeue()
CVE-2026-64376 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandfirmware_loader: fix device reference leak in firmware_upload_register()
CVE-2026-64487 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
CVE-2026-64445 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
CVE-2026-64304 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: qat - validate RSA CRT component lengths
CVE-2026-64390 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: track the connection owning a byte-range lock
CVE-2026-64412 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ebtables: module names must be null-terminated
CVE-2026-64345 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: f_printer: take kref only for successful open
CVE-2026-64387 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%smb: client: fix query directory replay double-free
CVE-2026-64320 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
CVE-2026-64397 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%ksmbd: serialize QUERY_DIRECTORY requests per file
CVE-2026-64361 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandhfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
CVE-2026-64409 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()
CVE-2026-64446 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandstaging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
CVE-2026-64306 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: drbg - Fix returning success on failure in CTR_DRBG
CVE-2026-64279 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandi2c: core: fix adapter deregistration race
CVE-2026-64338 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandUSB: misc: uss720: unregister parport on probe failure
CVE-2026-64437 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL
CVE-2026-64504 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandiio: accel: bmc150: clamp the device-reported FIFO frame count
CVE-2026-64419 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandmm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()
CVE-2026-64507 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandx86/bugs: Enable IBPB flush on BPF JIT allocation
CVE-2026-64399 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
CVE-2026-64476 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandvfio/pci: Latch disable_idle_d3 per device
CVE-2026-64525 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit
CVE-2026-64374 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandsched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
CVE-2026-64358 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandmedia: mtk-jpeg: cancel workqueue on release for supported platforms only
CVE-2026-64341 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: iowarrior: fix use-after-free on disconnect race
CVE-2026-64268 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%RDMA/siw: bound Read Response placement to the RREAD length
CVE-2026-64505 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: gadget: function: rndis: add length check for header
CVE-2026-64348 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: free iso schedules on failed submit
CVE-2026-64316 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: caam - use print_hex_dump_devel to guard key hex dumps
CVE-2026-64340 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: legousbtower: fix use-after-free on disconnect race
CVE-2026-64425 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandio_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item
CVE-2026-64408 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: bnep: pin L2CAP connection during netdev registration
CVE-2026-64360 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandhfs/hfsplus: zero-initialize buffer in hfs_bnode_read
CVE-2026-64462 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandPCI: altera: Fix resource leaks on probe failure
CVE-2026-64333 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: serial: digi_acceleport: fix write buffer corruption
CVE-2026-64448 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%smb: client: restrict implied bcc[0] exemption to responses without data area
CVE-2026-64395 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandksmbd: require source read access for duplicate extents
CVE-2026-64277 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandInput: synaptics-rmi4 - bound the F3A keymap to the GPIO count
CVE-2026-64450 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band1%tipc: fix out-of-bounds read in broadcast Gap ACK blocks
CVE-2026-64362 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandHID: lg-g15: cancel pending work on remove to fix a use-after-free
CVE-2026-64489 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: ymfpci: check snd_ctl_new1() return value
CVE-2026-64343 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: ldusb: fix use-after-free on disconnect race
CVE-2026-64400 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: prevent path traversal bypass by restricting caseless retry
CVE-2026-64305 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: qat - protect service table iterations with service_lock
CVE-2026-64368 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandmm/slab: do not limit zeroing to orig_size when only red zoning is enabled
CVE-2026-64386 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%smb: client: fix query_info() replay double-free
CVE-2026-64336 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: serial: keyspan_pda: fix information leak
CVE-2026-64474 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandvfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc
CVE-2026-64411 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandnetfilter: ebtables: terminate table name before find_table_lock()
CVE-2026-64273 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandInput: iforce - bound the device-reported force-feedback effect index
CVE-2026-64326 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandblock: skip sync_blockdev() on surprise removal in bdev_mark_dead()
CVE-2026-64495 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandiio: gyro: bmg160: bail out when bandwidth/filter is not in table
CVE-2026-64424 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnetpoll: fix a use-after-free on shutdown path
CVE-2026-64469 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%binder: fix UAF in binder_thread_release()
CVE-2026-64405 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandBluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()
CVE-2026-64388 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb/client: fix chown/chgrp with SMB3 POSIX Extensions
CVE-2026-64471 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandBluetooth: btusb: fix use-after-free on registration failure
CVE-2026-64346 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: udc: Fix use-after-free in gadget_match_driver
CVE-2026-64482 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: gus: check snd_ctl_new1() return value
CVE-2026-64301 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandregulator: scmi: fix of_node refcount leak in scmi_regulator_probe()
CVE-2026-64324 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandudf: validate free block extents against the partition length
CVE-2026-64350 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
CVE-2026-64407 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandBluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()
CVE-2026-64266 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandfuse: re-lock request before returning from fuse_ref_folio()
CVE-2026-64381 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb: client: Fix next buffer leak in receive_encrypted_standard()
CVE-2026-64423 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%ipv4: igmp: remove multicast group from hash table on device destruction
CVE-2026-64355 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%bpf: Reject fragmented frames in devmap
CVE-2026-64383 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%smb: client: fix double-free in SMB2_flush() replay
CVE-2026-64470 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandBluetooth: btusb: fix use-after-free on marvell probe failure
CVE-2026-64496 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%iio: event: Fix event FIFO reset race
CVE-2026-64398 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: add a permission check for FSCTL_SET_ZERO_DATA
CVE-2026-64478 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: usb-audio: avoid kobject path lookup in DualSense match
CVE-2026-64500 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandiio: adc: lpc32xx: Initialize completion before requesting IRQ
CVE-2026-64523 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%net/handshake: Take a long-lived file reference at submit
CVE-2026-64454 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: dwc3: run gadget disconnect from sleepable suspend context
CVE-2026-64312 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: pcrypt - restore callback for non-parallel fallback
CVE-2026-64510 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
CVE-2026-64317 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandisofs: bound Rock Ridge symlink components to the SL record
CVE-2026-64484 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: es1938: check snd_ctl_new1() return value
CVE-2026-64299 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandtracing: Prevent out-of-bounds read in glob matching
CVE-2026-64323 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandudf: validate VAT header length against the VAT inode size
CVE-2026-64318 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandpartitions: aix: bound the pp_count scan to the ppe array
CVE-2026-64463 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%usb: typec: tcpci_rt1711h: unregister TCPCI port with devres
CVE-2026-64444 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop
CVE-2026-66373 ↗2026-07-26azl3 valkey 8.0.9-1 on Azure Linux 3.0ImportantOut-of-band0%Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
CVE-2026-64430 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%NTB: epf: Avoid calling pci_irq_vector() from hardirq context
CVE-2026-64246 ↗2026-07-26azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandpower: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
CVE-2026-64403 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandBluetooth: L2CAP: validate option length before reading conf opt value
CVE-2026-66033 ↗2026-07-26azl3 libssh 0.10.6-8 on Azure Linux 3.0ImportantOut-of-band0%libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation
CVE-2026-64271 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandInput: touchwin - reset the packet index on every complete packet
CVE-2026-66035 ↗2026-07-26azl3 libssh 0.10.6-8 on Azure Linux 3.0ImportantOut-of-band0%libssh2 Heap Buffer Overflow via ETM Cipher Negotiation
CVE-2026-64488 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: aoa: check snd_ctl_new1() return value
CVE-2026-64286 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandKVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
CVE-2026-66032 ↗2026-07-26azl3 libssh 0.10.6-8 on Azure Linux 3.0ImportantOut-of-band0%libssh2 Double-Free Heap Corruption via sftp_open()
CVE-2026-64377 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandcpufreq: qcom-cpufreq-hw: Fix possible double free
CVE-2026-64272 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandInput: mms114 - fix touch indexing for MMS134S and MMS136
CVE-2026-66034 ↗2026-07-26azl3 libssh2 1.11.1-4 on Azure Linux 3.0ImportantOut-of-band0%libssh2 Heap Out-of-Bounds Read via publickey subsystem
CVE-2026-64344 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: idmouse: fix use-after-free on disconnect race
CVE-2026-64254 ↗2026-07-26azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandNTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
CVE-2026-64351 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
CVE-2026-64252 ↗2026-07-26azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandMIPS: DEC: Prevent initial console buffer from landing in XKPHYS
CVE-2026-64441 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()
CVE-2026-64245 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandfbdev: modedb: fix a possible UAF in fb_find_mode()
CVE-2026-64429 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandgpio: eic-sprd: use raw_spinlock_t in the irq startup path
CVE-2026-64250 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandLoongArch: Report dying CPU to RCU in stop_this_cpu()
CVE-2026-64455 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: chaoskey: Fix slab-use-after-free in chaoskey_release()
CVE-2026-64241 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandgpio: rockchip: teardown bugs and resource leaks
CVE-2026-64382 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandsmb: client: fix double-free in SMB2_open() replay
CVE-2026-64248 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandMIPS: smp: report dying CPU to RCU in stop_this_cpu()
CVE-2026-64298 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNFSv4: include MAY_WRITE in open permission mask for O_TRUNC
CVE-2026-64227 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandACPI: driver: Check ACPI_COMPANION() against NULL during probe
CVE-2026-64433 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete
CVE-2026-64247 ↗2026-07-26azl3 kernel 6.6.143.1-1 on Azure Linux 3.0N/AOut-of-bandKVM: x86: hyper-v: Bound the bank index when querying sparse banks
CVE-2026-64396 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation
CVE-2026-64249 ↗2026-07-26azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandfpga: region: fix use-after-free in child_regions_with_firmware()
CVE-2026-64330 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: typec: tcpm: Validate SVID index in svdm_consume_modes()
CVE-2026-64255 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
CVE-2026-64334 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: serial: digi_acceleport: fix hard lockup on disconnect
CVE-2026-64212 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: iwlwifi: mld: don't dereference a pointer before NULL checking it
CVE-2026-64529 ↗2026-07-26azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band0%crypto: qat - remove unused character device and IOCTLs
CVE-2026-64313 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: ecc - Fix carry overflow in vli multiplication
CVE-2026-64244 ↗2026-07-26azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-banddrivers/base/memory: set mem->altmap after successful device registration
CVE-2026-64480 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: ice1712: check snd_ctl_new1() return value
CVE-2026-64402 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandcoresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()
CVE-2026-64210 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandnet/mlx5e: xsk: Fix unlocked writing to ICOSQ
CVE-2026-64378 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandwriteback: fix race between cgroup_writeback_umount() and inode_switch_wbs()
CVE-2026-64379 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandsmb: client: mask server-provided mode to 07777 in modefromsid
CVE-2026-64213 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandhwmon: (lm90) Add lock protection to lm90_alert
CVE-2026-64442 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()
CVE-2026-64303 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
CVE-2026-64237 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandInput: elan_i2c - validate firmware size before use
CVE-2026-64294 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandmm: do file ownership checks with the proper mount idmap
CVE-2026-64219 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async
CVE-2026-16768 ↗2026-07-26azl3 gdk-pixbuf2 2.42.10-5 on Azure Linux 3.0ModerateOut-of-bandGdk-pixbuf: out-of-bounds read in ico parser
CVE-2026-47143 ↗2026-07-25azl3 rust 1.90.0-9 on Azure Linux 3.0ModerateOut-of-bandCapstone has a NULL Pointer Dereference with 3DNow! opcodes
CVE-2026-16461 ↗2026-07-25azl3 rpcbind 1.2.6-1 on Azure Linux 3.0ModerateOut-of-bandRpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting
CVE-2026-16615 ↗2026-07-25azl3 rest 0.9.0-1 on Azure Linux 3.0ModerateOut-of-bandLibrest: weak random number generation in pkce implementation
CVE-2026-47059 ↗2026-07-25azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0LowOut-of-bandVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java san
CVE-2026-46917 ↗2026-07-25azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1
CVE-2026-47063 ↗2026-07-25azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients ru
CVE-2026-60147 ↗2026-07-25azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web
CVE-2026-6390 ↗2026-07-25azl3 nano 6.4-3 on Azure Linux 3.0ModerateOut-of-bandNano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling.
CVE-2026-59850 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-bandLibssh: libssh: use-after-free via data callbacks on closed channels
CVE-2026-59844 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-bandLibssh: libssh: denial of service via oversized sftp read length
CVE-2026-59846 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0LowOut-of-bandLibssh: libssh: information disclosure via proxycommand %r username expansion
CVE-2026-59845 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-bandLibssh: libssh: denial of service via unchecked proxycommand fork() failure
CVE-2026-59847 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-bandLibssh: libssh: integrity downgrade via openssl aes-gcm tag verification
CVE-2026-59843 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-bandLibssh: libssh: denial of service via zero advertised channel packet size
CVE-2026-59848 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-bandLibssh: libssh: denial of service via sftp responses with unknown request ids
CVE-2026-12547 ↗2026-07-25azl3 libsoup 3.4.4-16 on Azure Linux 3.0LowOut-of-bandLibsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch
CVE-2026-16517 ↗2026-07-25azl3 libarchive 3.7.7-6 on Azure Linux 3.0LowOut-of-bandLibarchive: libarchive: signed integer overflow in archive_write_zip_header
CVE-2026-46600 ↗2026-07-25azl3 golang 1.25.11-3 on Azure Linux 3.0ModerateOut-of-bandParsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
CVE-2026-12617 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-band0%Record ordering based unexpected exit with CNAME or DNAME
CVE-2026-11622 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-band1%Potential memory usage beyond configured limits
CVE-2026-11721 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-band0%Cache poisoning possible with label count discrepancy, RRSIG, and wildcards
CVE-2026-11331 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-band0%Potential wildcard CNAME RPZ policy bypass
CVE-2026-11605 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-band1%Unnecessary validation of DNSSEC signed records
CVE-2026-13321 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ImportantOut-of-band0%DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
CVE-2026-10723 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-bandIncorrect acceptance of NSEC3 records
CVE-2026-13204 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-band1%Unexpected exit in certain situations with NSEC and NSEC3 both present
CVE-2026-10822 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-bandKey Record using PRIVATEDNS algorithm may lead to unexpected exit
CVE-2026-56852 ↗2026-07-25azl3 azurelinux-image-tools 1.5.0-1 on Azure Linux 3.0ImportantOut-of-bandInfinite loop on invalid input in golang.org/x/text
CVE-2026-16493 ↗2026-07-25azl3 ansible 2.17.11-1 on Azure Linux 3.0ImportantOut-of-band0%Ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for cve-2026-11332)
CVE-2026-56392 ↗2026-07-25azl3 coreutils 9.4-6 on Azure Linux 3.0LowOut-of-bandHeap-based Buffer Overflow in GNU coreutils
CVE-2026-44210 ↗2026-07-25azl3 kata-containers-cc 3.15.0.aks0-15 on Azure Linux 3.0ModerateOut-of-bandKata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations
CVE-2026-16807 ↗2026-07-25Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16807 Out of bounds write in Codecs
CVE-2026-16806 ↗2026-07-25Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16806 Use after free in WebMCP
CVE-2026-16805 ↗2026-07-25Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16805 Use after free in Blink
CVE-2026-16804 ↗2026-07-25Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16804 Use after free in Input
CVE-2026-57978 ↗2026-07-24Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-57989 ↗2026-07-24Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-57990 ↗2026-07-24Microsoft Edge (Chromium-based)ImportantOut-of-band1%Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-64600 ↗2026-07-24azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandxfs: resample the data fork mapping after cycling ILOCK
CVE-2026-59677 ↗2026-07-24azl3 checkpolicy 3.6-1 on Azure Linux 3.0ModerateOut-of-bandProcess Kill Attack Vector in killall() in seunshare
CVE-2026-59676 ↗2026-07-24azl3 checkpolicy 3.6-1 on Azure Linux 3.0ModerateOut-of-bandLocal File Deletion Attack Vector in rm_rf() in seunshare

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-48586trackedCVSS 7.5Red Hat Hardened Imagesloki3-7-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-51297trackedImportant (Red Hat rating)Red Hat Hardened Imagessqlite-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-51298CVSS 7.5Red Hat Hardened Imagessqlite-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-51302trackedImportant (Red Hat rating)Red Hat Hardened Imagessqlite-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-51304trackedImportant (Red Hat rating)Red Hat Hardened Imagessqlite-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-11233CVSS 6.5Red Hat Hardened Imagesrust-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-13149trackedCVSS 7.5Red Hat Hardened Imagesnodejs26-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-44216CVSS 7.5Red Hat Hardened Imagesrust-main@aarch64Patch ↗Advisory ↗