CYBERSECURITYTRACKER
TRACKING3,812 stories701 vuln stories
Patch Day month

August 2026 vulnerabilities

A defender-focused view of 1,592 vulnerabilities across 2,157 returned patch records from 4 vendors. Filter the month to date, or browse the static page trail without JavaScript.

2,157all patch recordsClear filters76criticalShow these records0Microsoft exploitation detectedShow these records1Microsoft in CISA KEVShow these records384tracked hereShow these records

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as “no.” “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.

Page 11 of 11 · records 2,001–2,157 of 2,157

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2024-21243 ↗2026-08-07azl3 mysql 8.0.41-1 on Azure Linux 3.0LowOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).
CVE-2025-21546 ↗2026-08-07azl3 mysql 8.0.41-1 on Azure Linux 3.0LowOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
CVE-2026-64571 ↗2026-08-07azl3 kernel 6.6.145.2-1 on Azure Linux 3.0LowOut-of-bandwifi: p54: validate RX frame length in p54_rx_eeprom_readback()
CVE-2024-21000 ↗2026-08-07azl3 mysql 8.0.41-1 on Azure Linux 3.0LowOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
CVE-2024-21244 ↗2026-08-07azl3 mysql 8.0.41-1 on Azure Linux 3.0LowOut-of-band
CVE-2026-18839 ↗2026-08-07azl3 rsync 3.4.3-1 on Azure Linux 3.0LowOut-of-bandPopt-devel: popt-static: size_t underflow in singleoptionhelp
CVE-2026-18739 ↗2026-08-07azl3 popt 1.19-1 on Azure Linux 3.0LowOut-of-bandPopt-devel: popt-static: off-by-one in poptstuffargs
CVE-2026-19023 ↗2026-08-07azl3 hdf5 1.14.6-4 on Azure Linux 3.0LowOut-of-bandHDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets
CVE-2026-58039 ↗2026-08-07azl3 nodejs 24.17.0-1 on Azure Linux 3.0LowOut-of-band
CVE-2026-56847 ↗2026-08-07azl3 nodejs 24.17.0-1 on Azure Linux 3.0LowOut-of-band
CVE-2026-6879 ↗2026-08-07azl3 tensorflow 2.16.1-11 on Azure Linux 3.0LowOut-of-band
CVE-2026-15037 ↗2026-08-07azl3 qtbase 6.6.3-5 on Azure Linux 3.0LowOut-of-bandXML injection vulnerability in QDom comment, CDATA and processing-instruction serialization
CVE-2026-64549 ↗2026-08-07azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-bandBluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
CVE-2026-64546 ↗2026-08-07azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-banddrm/edid: fix OOB read in drm_parse_tiled_block()
CVE-2026-64512 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-bandACPI: CPPC: Suppress UBSAN warning caused by field misuse
CVE-2026-47059 ↗2026-07-25azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0LowOut-of-bandVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java san
CVE-2026-59846 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0LowOut-of-bandLibssh: libssh: information disclosure via proxycommand %r username expansion
CVE-2026-16517 ↗2026-07-25azl3 libarchive 3.7.7-6 on Azure Linux 3.0LowOut-of-bandLibarchive: libarchive: signed integer overflow in archive_write_zip_header
CVE-2026-56392 ↗2026-07-25azl3 coreutils 9.4-7 on Azure Linux 3.0LowOut-of-bandHeap-based Buffer Overflow in GNU coreutils
CVE-2026-42770 ↗2026-07-21azl3 openssl 3.3.7-3 on Azure Linux 3.0LowOut-of-bandFFC-DH Peer Validation Uses Attacker-Supplied q
CVE-2026-42768 ↗2026-06-13azl3 openssl 3.3.7-1 on Azure Linux 3.0LowOut-of-bandMulti-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
CVE-2026-46044 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-bandipmi:ssif: Clean up kthread on errors
CVE-2026-45893 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-bandapparmor: Fix & Optimize table creation from possibly unaligned memory
CVE-2026-43969 ↗2026-05-15azl3 rabbitmq-server 3.13.7-3 on Azure Linux 3.0LowOut-of-bandCookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
CVE-2026-3832 ↗2026-05-07cbl2 gnutls 3.7.11-6 on CBL Mariner 2.0LowOut-of-bandGnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response
CVE-2026-34743 ↗2026-04-04azl3 xz 5.4.4-2 on Azure Linux 3.0LowOut-of-bandXZ Utils: Buffer overflow in lzma_index_append()
CVE-2026-35388 ↗2026-04-04cbl2 openssh 8.9p1-9 on CBL Mariner 2.0LowOut-of-bandOpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
CVE-2026-3633 ↗2026-03-21azl3 libsoup 3.4.4-12 on Azure Linux 3.0LowOut-of-bandLibsoup: libsoup: header and http request injection via crlf injection
CVE-2026-3632 ↗2026-03-21azl3 libsoup 3.4.4-12 on Azure Linux 3.0LowOut-of-bandLibsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
CVE-2026-3634 ↗2026-03-21cbl2 libsoup 3.0.4-12 on CBL Mariner 2.0LowOut-of-bandLibsoup: libsoup: http header injection and response splitting via crlf injection in content-type header
CVE-2026-0989 ↗2026-01-19cbl2 libxml2 2.10.4-9 on CBL Mariner 2.0LowOut-of-bandLibxml2: unbounded relaxng include recursion leading to stack overflow
CVE-2025-13837 ↗2025-12-05cbl2 python3 3.9.19-16 on CBL Mariner 2.0LowOut-of-bandOut-of-memory when loading Plist
CVE-2023-53012 ↗2025-11-01cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0LowOut-of-bandthermal: core: call put_device() only after device_register() fails
CVE-2024-36920 ↗2025-10-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0LowOut-of-bandscsi: mpi3mr: Avoid memcpy field-spanning write WARNING
CVE-2025-46394 ↗2025-09-04azl3 busybox 1.36.1-14 on Azure Linux 3.0LowOut-of-bandIn tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
CVE-2024-58251 ↗2025-09-04azl3 busybox 1.36.1-17 on Azure Linux 3.0LowOut-of-bandIn netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
CVE-2024-7598 ↗2025-09-04azl3 kubernetes 1.30.10-9 on Azure Linux 3.0LowOut-of-bandNetwork restriction bypass via race condition during namespace termination
CVE-2025-7069 ↗2025-09-04cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0LowOut-of-bandHDF5 H5FSsection.c H5FS__sect_link_size heap-based overflow
CVE-2025-1180 ↗2025-09-04cbl2 gdb 11.2-6 on CBL Mariner 2.0LowOut-of-bandGNU Binutils ld elf-eh-frame.c _bfd_elf_write_section_eh_frame memory corruption
CVE-2025-1150 ↗2025-09-04azl3 binutils 2.41-7 on Azure Linux 3.0LowOut-of-bandGNU Binutils ld libbfd.c bfd_malloc memory leak
CVE-2025-29477 ↗2025-09-03cbl2 fluent-bit 3.0.6-2 on CBL Mariner 2.0LowOut-of-bandAn issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.
CVE-2025-29478 ↗2025-09-03cbl2 fluent-bit 3.0.6-2 on CBL Mariner 2.0LowOut-of-bandAn issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.
CVE-2025-2912 ↗2025-09-03cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0LowOut-of-bandHDF5 H5Omessage.c H5O_msg_flush heap-based overflow
CVE-2025-2923 ↗2025-09-03azl3 hdf5 1.14.4.3-1 on Azure Linux 3.0LowOut-of-bandHDF5 H5Fint.c H5F_addr_encode_len heap-based overflow
CVE-2024-42155 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0LowOut-of-bands390/pkey: Wipe copies of protected- and secure-keys
CVE-2025-29923 ↗2025-04-01azl3 telegraf 1.31.0-10 on Azure Linux 3.0LowOut-of-bandgo-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment
CVE-2024-50211 ↗2025-01-29azl3 kernel 6.6.64.2-1 on Azure Linux 3.0LowOut-of-bandudf: refactor inode_bmap() to handle error
CVE-2024-47738 ↗2024-11-09azl3 kernel 6.6.56.1-5 on Azure Linux 3.0LowOut-of-bandwifi: mac80211: don't use rate mask for offchannel TX either
CVE-2026-71226 ↗2026-08-09azl3 libkcapi 1.5.0-2 on Azure Linux 3.0N/AOut-of-band0%Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path
CVE-2024-26464 ↗2026-08-07cbl2 net-snmp 5.9.4-1N/AOut-of-band
CVE-2024-31745 ↗2025-04-01cbl2 libdwarf 0.9.0-3N/AOut-of-band
CVE-2024-5814 ↗2024-12-07cbl2 mariadb 10.6.9-6N/AOut-of-band0%Unverifed Ciphersuite used on a client-side TLS1.3 Downgrade
CVE-2026-44605 ↗2026-08-09azl3 rpm 4.18.2-1 on Azure Linux 3.0N/AOut-of-bandRpm: heap buffer overflow in ndb slot table parsing
CVE-2026-71227 ↗2026-08-09azl3 libkcapi 1.5.0-2 on Azure Linux 3.0N/AOut-of-bandLibkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
CVE-2026-71225 ↗2026-08-09azl3 libkcapi 1.5.0-2 on Azure Linux 3.0N/AOut-of-bandLibkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
CVE-2026-68082 ↗2026-08-09azl3 kernel 6.6.145.2-1 on Azure Linux 3.0N/AOut-of-bandlibceph: fix two unsafe bare decodes in decode_lockers()
CVE-2026-68081 ↗2026-08-09azl3 kernel 6.6.145.2-1 on Azure Linux 3.0N/AOut-of-bandKVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
CVE-2026-34502 ↗2026-08-09azl3 apr-util 1.6.3-2 on Azure Linux 3.0N/AOut-of-bandApache Portable Runtime Utility: Heap buffer overflow in APR memcached client
CVE-2026-34501 ↗2026-08-09azl3 apr-util 1.6.3-2 on Azure Linux 3.0N/AOut-of-bandApache Portable Runtime Utility: Heap buffer overflow in APR redis client
CVE-2026-34191 ↗2026-08-09azl3 apr-util 1.6.3-2 on Azure Linux 3.0N/AOut-of-bandApache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
CVE-2025-49506 ↗2026-08-09azl3 apr-util 1.6.3-2 on Azure Linux 3.0N/AOut-of-bandApache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
CVE-2026-47243 ↗2026-08-09azl3 kata-containers 3.19.1.kata3-7 on Azure Linux 3.0N/AOut-of-bandKata guest escape: runtime-rs guest-root to host-root escape via virtiofs
CVE-2026-64676 ↗2026-08-09azl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0N/AOut-of-bandKata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory
CVE-2026-50540 ↗2026-08-09azl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0N/AOut-of-bandKata Containers: Config Path Annotation Arbitrary File Loading
CVE-2026-54522 ↗2026-08-07azl3 rubygem-msgpack 1.7.2-1 on Azure Linux 3.0N/AOut-of-bandMessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
CVE-2026-54787 ↗2026-08-07azl3 gh 2.62.0-20 on Azure Linux 3.0N/AOut-of-bandsigstore-go fails to check signature timestamps against a signing key's validity period
CVE-2024-3205 ↗2026-08-07azl3 libyaml 0.2.5-3 on Azure Linux 3.0N/AOut-of-bandRejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The maintainer identified an error in the libyaml fuzzers. It is not possible to reproduce nor exploit the issue.
CVE-2024-36022 ↗2026-08-07azl3 kernel 6.6.92.2-1 on Azure Linux 3.0N/AOut-of-bandRejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-37753 ↗2026-08-07azl3 kernel 6.6.92.2-1 on Azure Linux 3.0N/AOut-of-bandRejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-43022 ↗2026-05-02azl3 kernel 6.6.141.1-1 on Azure Linux 3.0N/AOut-of-bandBluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists
CVE-2024-38620 ↗2025-10-05cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandBluetooth: HCI: Remove HCI_AMP support
CVE-2025-21635 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-bandrds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy
CVE-2024-38628 ↗2025-09-04cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0N/AOut-of-bandusb: gadget: u_audio: Fix race condition use of controls after free during gadget unbind.
CVE-2025-21949 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-bandLoongArch: Set hugetlb mmap base address aligned with pmd size
CVE-2024-24856 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandNULL pointer deference in acpi_db_convert_to_package of Linux acpi module
CVE-2023-52939 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandmm: memcg: fix NULL pointer in mem_cgroup_track_foreign_dirty_slowpath()
CVE-2025-21891 ↗2025-09-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0N/AOut-of-bandipvlan: ensure network headers are in skb linear part
CVE-2022-49750 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandcpufreq: CPPC: Add u64 casts to avoid overflowing
CVE-2023-53002 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-banddrm/i915: Fix a memory leak with reused mmap_offset
CVE-2023-53008 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandcifs: fix potential memory leaks in session setup
CVE-2022-49742 ↗2025-09-03cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0N/AOut-of-bandf2fs: initialize locks earlier in f2fs_fill_super()
CVE-2025-21961 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandeth: bnxt: fix truesize for mb-xdp-pass case
CVE-2024-39478 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandcrypto: starfive - Do not free stack buffer
CVE-2024-56712 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandudmabuf: fix memory leak on last export_udmabuf() error path
CVE-2024-49937 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandwifi: cfg80211: Set correct chandef when starting CAC
CVE-2024-49939 ↗2025-09-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0N/AOut-of-bandwifi: rtw89: avoid to add interface to list twice when SER
CVE-2024-53114 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandx86/CPU/AMD: Clear virtualized VMLOAD/VMSAVE on Zen4 client
CVE-2024-42134 ↗2025-09-03azl3 kernel 6.6.112.1-2 on Azure Linux 3.0N/AOut-of-bandvirtio-pci: Check if is_avq is NULL
CVE-2024-49920 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Check null pointers before multiple uses
CVE-2024-49925 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandfbdev: efifb: Register sysfs groups through driver core
CVE-2024-49971 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Increase array size of dummy_boolean
CVE-2024-49945 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-bandnet/ncsi: Disable the ncsi work before freeing the associated structure
CVE-2024-46870 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Disable DMCUB timeout for DCN35
CVE-2024-49972 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Deallocate DML memory if allocation fails
CVE-2024-49885 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandmm, slub: avoid zeroing kmalloc redzone
CVE-2024-53201 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Fix null check for pipe_ctx->plane_state in dcn20_program_pipe
CVE-2024-49932 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandbtrfs: don't readahead the relocation inode on RST
CVE-2023-52485 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Wake DMCUB before sending a command
CVE-2024-49940 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandl2tp: prevent possible tunnel refcount underflow
CVE-2024-53089 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandLoongArch: KVM: Mark hrtimer to expire in hard interrupt context
CVE-2024-47662 ↗2025-09-03azl3 kernel 6.6.104.2-4 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Remove register from DCN35 DMCUB diagnostic collection
CVE-2024-53090 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandafs: Fix lock recursion
CVE-2024-49888 ↗2025-09-03azl3 kernel 6.6.104.2-4 on Azure Linux 3.0N/AOut-of-bandbpf: Fix a sdiv overflow issue
CVE-2025-21682 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandeth: bnxt: always recalculate features after XDP clearing, fix null-deref
CVE-2024-47702 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandbpf: Fail verification for sign-extension of packet data/data_end/data_meta
CVE-2024-57872 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandscsi: ufs: pltfrm: Dellocate HBA during ufshcd_pltfrm_remove()
CVE-2024-53050 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-banddrm/i915/hdcp: Add encoder check in hdcp2_get_capability
CVE-2024-42107 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandice: Don't process extts if PTP is disabled
CVE-2024-50090 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-banddrm/xe/oa: Fix overflow in oa batch buffer
CVE-2024-50091 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-banddm vdo: don't refer to dedupe_context after releasing it
CVE-2024-26962 ↗2025-09-03azl3 kernel 6.6.104.2-4 on Azure Linux 3.0N/AOut-of-banddm-raid456, md/raid456: fix a deadlock for dm-raid456 while io concurrent with reshape
CVE-2024-53051 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-banddrm/i915/hdcp: Add encoder check in intel_hdcp_get_capability
CVE-2024-27010 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandnet/sched: Fix mirred deadlock on device recursion
CVE-2025-21723 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandscsi: mpi3mr: Fix possible crash when setting up bsg fails
CVE-2024-53224 ↗2025-09-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0N/AOut-of-bandRDMA/mlx5: Move events notifier registration to be after device registration
CVE-2024-49970 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Implement bounds check for stream encoder creation in DCN401
CVE-2024-47703 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandbpf, lsm: Add check for BPF LSM return value
CVE-2024-50102 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandx86: fix user address masking non-canonical speculation issue
CVE-2024-37021 ↗2025-09-03cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0N/AOut-of-bandfpga: manager: add owner module and take its refcount
CVE-2024-56702 ↗2025-09-03azl3 kernel 6.6.112.1-2 on Azure Linux 3.0N/AOut-of-bandbpf: Mark raw_tp arguments with PTR_MAYBE_NULL
CVE-2025-21672 ↗2025-09-03azl3 kernel 6.6.112.1-2 on Azure Linux 3.0N/AOut-of-bandafs: Fix merge preference rule failure condition
CVE-2024-53056 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-banddrm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy()
CVE-2024-58012 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-bandASoC: SOF: Intel: hda-dai: Ensure DAI widget is valid during params
CVE-2024-46823 ↗2025-09-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0N/AOut-of-bandkunit/overflow: Fix UB in overflow_allocation_test
CVE-2024-53084 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-banddrm/imagination: Break an object reference loop
CVE-2024-49990 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-banddrm/xe/hdcp: Check GSC structure validity
CVE-2024-46787 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-banduserfaultfd: fix checks for huge PMDs
CVE-2024-49918 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-banddrm/amd/display: Add null check for head_pipe in dcn32_acquire_idle_pipe_for_head_pipe_in_layer
CVE-2024-50187 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-banddrm/vc4: Stop the active perfmon before being destroyed
CVE-2024-46778 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Check UnboundedRequestEnabled's value
CVE-2024-46775 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-banddrm/amd/display: Validate function returns
CVE-2024-49916 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Add NULL check for clk_mgr and clk_mgr->funcs in dcn401_init_hw
CVE-2023-4134 ↗2025-09-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0N/AOut-of-bandKernel: cyttsp4_core: use-after-free in cyttsp4_watchdog_work()
CVE-2024-56742 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandvfio/mlx5: Fix an unwind issue in mlx5vf_add_migration_pages()
CVE-2025-21833 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandiommu/vt-d: Avoid use of NULL after WARN_ON_ONCE
CVE-2024-49908 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Add null check for 'afb' in amdgpu_dm_update_cursor (v2)
CVE-2024-38625 ↗2025-09-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0N/AOut-of-bandfs/ntfs3: Check 'folio' pointer for NULL
CVE-2024-27079 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandiommu/vt-d: Fix NULL domain on device release
CVE-2024-26775 ↗2025-09-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0N/AOut-of-bandaoe: avoid potential deadlock at set_capacity
CVE-2024-49910 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Add NULL check for function pointer in dcn401_set_output_transfer_func
CVE-2024-50225 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandbtrfs: fix error propagation of split bios
CVE-2024-50004 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: update DML2 policy EnhancedPrefetchScheduleAccelerationFinal DCN35
CVE-2024-56557 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandiio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer
CVE-2024-50178 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-bandcpufreq: loongson3: Use raw_smp_processor_id() in do_service_request()
CVE-2024-42139 ↗2025-09-03azl3 kernel 6.6.104.2-4 on Azure Linux 3.0N/AOut-of-bandice: Fix improper extts handling
CVE-2024-47658 ↗2025-09-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0N/AOut-of-bandcrypto: stm32/cryp - call finalize with bh disabled
CVE-2024-50277 ↗2025-08-21azl3 kernel 6.6.96.1-1 on Azure Linux 3.0N/AOut-of-banddm: fix a crash if blk_alloc_disk fails

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-67316CVSS 3.7Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream (v. 8)thunderbird-0:140.13.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-portable-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47059CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-portable-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47059CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-40469CVSS 2.8Red Hat Hardened Imagesgawk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67316CVSS 3.7Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗