CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Patch Day month

August 2026 vulnerabilities

A defender-focused view of 2,459 vulnerabilities across 3,874 returned patch records from 4 vendors. Filter the month to date, or browse the static page trail without JavaScript.

3,874all patch recordsClear filters183criticalShow these records1Microsoft exploitation detectedShow these records2Microsoft in CISA KEVShow these records1,062tracked hereShow these records

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as “no.” “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.

Page 17 of 20 · records 3,201–3,400 of 3,874

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-43970 ↗azl3 rabbitmq-server 3.13.7-3 on Azure Linux 3.0ModerateOut-of-bandDecompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame
CVE-2026-31767 ↗azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode
CVE-2026-43308 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandbtrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref()
CVE-2026-43294 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels
CVE-2026-43299 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandbtrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure()
CVE-2026-43456 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandbonding: fix type confusion in bond_setup_by_slave()
CVE-2026-43344 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandperf/x86/intel/uncore: Fix die ID init and look up bugs
CVE-2026-43416 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandpowerpc, perf: Check that current->mm is alive before getting user callchain
CVE-2026-43309 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandmd raid: fix hang when stopping arrays with metadata through dm-raid
CVE-2026-43338 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandbtrfs: reserve enough transaction items for qgroup ioctls
CVE-2026-6383 ↗cbl2 kubevirt 0.59.0-38 on CBL Mariner 2.0ModerateOut-of-bandKubevirt: kubevirt: unauthorized subresource access due to improper rbac evaluation
CVE-2026-33857 ↗cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-bandApache HTTP Server: Off-by-one OOB reads in AJP getter functions
CVE-2026-33007 ↗cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-bandApache HTTP Server: mod_authn_socache crash
CVE-2026-33006 ↗cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-bandApache HTTP Server: mod_auth_digest timing attack
CVE-2026-34032 ↗azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-bandApache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)
CVE-2026-33523 ↗cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-bandApache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line
CVE-2026-3833 ↗cbl2 gnutls 3.7.11-6 on CBL Mariner 2.0ModerateOut-of-bandGnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison
CVE-2026-43083 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: ioam6: fix OOB and missing lock
CVE-2026-43199 ↗azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query
CVE-2026-43101 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data()
CVE-2026-43119 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandBluetooth: hci_sync: annotate data-races around hdev->req_status
CVE-2026-43216 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: Drop the lock in skb_may_tx_timestamp()
CVE-2026-43250 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandusb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke()
CVE-2026-43107 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: account XFRMA_IF_ID in aevent size calculation
CVE-2025-71289 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandfs/ntfs3: handle attr_set_size() errors when truncating files
CVE-2026-43244 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandkcm: fix zero-frag skb in frag_list on partial sendmsg error
CVE-2026-43153 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandxfs: remove xfs_attr_leaf_hasname
CVE-2026-43118 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix zero size inode with non-zero size after log replay
CVE-2025-71273 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandwifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()
CVE-2026-43197 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetconsole: avoid OOB reads, msg is not nul-terminated
CVE-2025-71285 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: qrtr: Drop the MHI auto_queue feature for IPCR DL channels
CVE-2026-43172 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandwifi: iwlwifi: fix 22000 series SMEM parsing
CVE-2026-43234 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandteam: avoid NETDEV_CHANGEMTU event when unregistering slave
CVE-2026-43198 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandtcp: fix potential race in tcp_v6_syn_recv_sock()
CVE-2026-43161 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandiommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode
CVE-2026-43127 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandntfs3: fix circular locking dependency in run_unpack_ex
CVE-2026-43131 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amd/pm: Fix null pointer dereference issue
CVE-2026-43248 ↗azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandvhost: move vdpa group bound check to vhost_vdpa
CVE-2026-6845 ↗cbl2 binutils 2.37-20 on CBL Mariner 2.0ModerateOut-of-bandBinutils: binutils: denial of service via crafted elf file
CVE-2026-43036 ↗azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: use skb_header_pointer() for TCPv4 GSO frag_off check
CVE-2026-43053 ↗azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandxfs: close crash window in attr dabtree inactivation
CVE-2026-4948 ↗cbl2 firewalld 1.0.3-2 on CBL Mariner 2.0ModerateOut-of-bandFirewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
CVE-2026-31692 ↗azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandrtnetlink: add missing netlink_ns_capable() check for peer netns
CVE-2026-41607 ↗cbl2 ceph 16.2.10-11 on CBL Mariner 2.0ModerateOut-of-bandApache Thrift: C++ JSON OOB read
CVE-2026-41606 ↗azl3 thrift 0.15.0-6 on Azure Linux 3.0ModerateOut-of-bandApache Thrift: c_glib dispatch stack overflow
CVE-2026-31499 ↗azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandBluetooth: L2CAP: Fix deadlock in l2cap_conn_del()
CVE-2026-6238 ↗azl3 glibc 2.38-19 on Azure Linux 3.0ModerateOut-of-bandBuffer overread in ns_printrrf with corrupted RDATA field
CVE-2018-5407 ↗cbl2 shim-unsigned-aarch64 15-5 on CBL Mariner 2.0ModerateOut-of-bandSimultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
CVE-2026-31592 ↗azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandKVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock
CVE-2026-31677 ↗azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: af_alg - limit RX SG extraction by receive buffer budget
CVE-2026-31579 ↗azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandwireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit
CVE-2026-31575 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandmm/userfaultfd: fix hugetlb fault mutex hash calculation
CVE-2026-40255 ↗azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-band@adonisjs/http-server has an Open Redirect vulnerability
CVE-2026-29181 ↗azl3 containerd2 2.1.6-1 on Azure Linux 3.0ModerateOut-of-bandOpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
CVE-2026-34446 ↗azl3 pytorch 2.2.2-12 on Azure Linux 3.0ModerateOut-of-bandONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
CVE-2026-23472 ↗azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandserial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
CVE-2026-23473 ↗azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandio_uring/poll: fix multishot recv missing EOF on wakeup race
CVE-2026-35549 ↗azl3 mariadb 10.11.16-1 on Azure Linux 3.0ModerateOut-of-bandAn issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.
CVE-2026-35414 ↗azl3 openssh 9.8p1-5 on Azure Linux 3.0ModerateOut-of-bandOpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
CVE-2026-21717 ↗azl3 nodejs 20.14.0-15 on Azure Linux 3.0ModerateOut-of-bandA flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process. The most common trigger is any endpoint that calls `JSON.parse()` on attacker-controlled input, as JSON parsing automatically internalizes short strings into the affected hash table. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-4833 ↗azl3 rubygem-rdiscount 2.2.7.1-1 on Azure Linux 3.0ModerateOut-of-bandOrc discount Markdown markdown.c compile recursion
CVE-2026-4647 ↗cbl2 binutils 2.37-20 on CBL Mariner 2.0ModerateOut-of-bandBinutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
CVE-2025-71183 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbtrfs: always detect conflicting inodes when logging inode refs
CVE-2026-23371 ↗azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandsched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting
CVE-2026-23383 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing
CVE-2026-23333 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_set_rbtree: validate open interval overlap
CVE-2026-3099 ↗azl3 libsoup 3.4.4-12 on Azure Linux 3.0ModerateOut-of-bandLibsoup: libsoup: authentication bypass via digest authentication replay attack
CVE-2026-4438 ↗azl3 glibc 2.38-19 on Azure Linux 3.0ModerateOut-of-bandgethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
CVE-2026-4437 ↗azl3 glibc 2.38-19 on Azure Linux 3.0ModerateOut-of-bandgethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response
CVE-2026-23276 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: add xmit recursion limit to tunnel xmit functions
CVE-2026-23207 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: tegra210-quad: Protect curr_xfer check in IRQ handler
CVE-2026-3644 ↗azl3 python3 3.12.9-9 on Azure Linux 3.0ModerateOut-of-bandIncomplete control character validation in http.cookies
CVE-2026-4224 ↗azl3 python3 3.12.9-9 on Azure Linux 3.0ModerateOut-of-bandStack overflow parsing XML with deeply nested DTD content models
CVE-2026-23247 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandtcp: secure_seq: add back ports to TS offset
CVE-2025-71202 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandiommu/sva: invalidate stale IOTLB entries for kernel address space
CVE-2026-4105 ↗cbl2 systemd 250.3-23 on CBL Mariner 2.0ModerateOut-of-bandSystemd: systemd: privilege escalation via improper access control in registermachine d-bus method
CVE-2025-69647 ↗cbl2 binutils 2.37-20 on CBL Mariner 2.0ModerateOut-of-bandGNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.
CVE-2026-27137 ↗azl3 golang 1.25.7-1 on Azure Linux 3.0ModerateOut-of-bandIncorrect enforcement of email constraints in crypto/x509
CVE-2025-69649 ↗azl3 binutils 2.41-10 on Azure Linux 3.0ModerateOut-of-bandGNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.
CVE-2025-69645 ↗azl3 binutils 2.41-11 on Azure Linux 3.0ModerateOut-of-bandBinutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.
CVE-2025-69646 ↗azl3 binutils 2.41-10 on Azure Linux 3.0ModerateOut-of-bandBinutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.
CVE-2026-2297 ↗cbl2 python3 3.9.19-19 on CBL Mariner 2.0ModerateOut-of-bandSourcelessFileLoader does not use io.open_code()
CVE-2025-71161 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-banddm-verity: disable recursive forward error correction
CVE-2025-71150 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandksmbd: Fix refcount leak when invalid session is found on session lookup
CVE-2025-71227 ↗azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: don't WARN for connections on invalid channels
CVE-2025-39770 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM
CVE-2025-71095 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandnet: stmmac: fix the crash issue for zero copy XDP_TX action
CVE-2025-68972 ↗cbl2 gnupg2 2.4.0-3 on CBL Mariner 2.0ModerateOut-of-bandIn GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.
CVE-2025-59529 ↗cbl2 avahi 0.8-4 on CBL Mariner 2.0ModerateOut-of-bandsimple protocol server ignores accepts unlimited connections and logs failures without limit
CVE-2025-68384 ↗azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandElasticsearch Allocation of Resources Without Limits or Throttling
CVE-2025-68390 ↗azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandElasticsearch Allocation of Resources Without Limits or Throttling
CVE-2025-68146 ↗azl3 python-filelock 3.14.0-1 on Azure Linux 3.0ModerateOut-of-bandfilelock has TOCTOU race condition that allows symlink attacks during lock file creation
CVE-2025-37959 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandbpf: Scrub packet on bpf_redirect_peer
CVE-2025-68209 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandmlx5: Fix default values in create CQ
CVE-2025-40355 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandsysfs: check visibility before changing group attribute ownership
CVE-2025-68230 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: fix gpu page fault after hibernation on PF passthrough
CVE-2025-68201 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: remove two invalid BUG_ON()s
CVE-2025-68223 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-banddrm/radeon: delete radeon_fence_process in is_signaled, no deadlock
CVE-2025-37731 ↗azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandElasticsearch Improper Authentication
CVE-2024-58241 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandBluetooth: hci_core: Disable works on hci_unregister_dev
CVE-2023-53376 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandscsi: mpi3mr: Use number of bits to manage bitmap sizes
CVE-2022-50393 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/amdgpu: SDMA update use unlocked iterator
CVE-2023-53429 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandbtrfs: don't check PageError in __extent_writepage
CVE-2022-50407 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandcrypto: hisilicon/qm - increase the memory of local variables
CVE-2025-40339 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: fix nullptr err of vm_handle_moved
CVE-2023-53749 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandx86: fix clear_user_rep_good() exception handling annotation
CVE-2025-40289 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM
CVE-2025-61727 ↗cbl2 golang 1.18.8-10 on CBL Mariner 2.0ModerateOut-of-bandImproper application of excluded DNS name constraints when verifying wildcard names in crypto/x509
CVE-2025-40247 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/msm: Fix pgtable prealloc error path
CVE-2023-53178 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandmm: fix zswap writeback race condition
CVE-2022-50350 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandscsi: target: iscsi: Fix a race condition between login_work and the login thread
CVE-2025-64713 ↗cbl2 fluent-bit 3.0.6-4 on CBL Mariner 2.0ModerateOut-of-bandWebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode
CVE-2025-64704 ↗azl3 fluent-bit 3.1.9-6 on Azure Linux 3.0ModerateOut-of-bandWebAssembly Micro Runtime vulnerable to a segmentation fault in v128.store instruction
CVE-2025-54770 ↗cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandGrub2: use-after-free in net_set_vlan
CVE-2025-54771 ↗cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandGrub2: use-after-free in grub_file_close()
CVE-2022-50233 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandBluetooth: eir: Fix using strlen with hdev->{dev_name,short_name}
CVE-2022-50167 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandbpf: fix potential 32-bit overflow when accessing ARRAY map element
CVE-2022-50073 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null
CVE-2025-2998 ↗azl3 pytorch 2.2.2-7 on Azure Linux 3.0ModerateOut-of-bandPyTorch torch.nn.utils.rnn.pad_packed_sequence memory corruption
CVE-2025-37820 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandxen-netfront: handle NULL returned by xdp_convert_buff_to_frame()
CVE-2023-53093 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandtracing: Do not let histogram values have some modifiers
CVE-2023-53074 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/amdgpu: fix ttm_bo calltrace warning in psp_hw_fini
CVE-2023-53068 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: usb: lan78xx: Limit packet length to skb->len
CVE-2023-53042 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/amd/display: Do not set DRR on pipe Commit
CVE-2023-53037 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandscsi: mpi3mr: Bad drive in topology results kernel crash
CVE-2022-49932 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandKVM: VMX: Do _all_ initialization before exposing /dev/kvm to userspace
CVE-2025-40180 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandmailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox cleanup loop
CVE-2011-10034 ↗azl3 autogen 5.18.16-9 on Azure Linux 3.0ModerateOut-of-bandIRAI AUTOMGEN <= 8.0.0.7 Use-After-Free Remote DoS
CVE-2025-40158 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: use RCU in ip6_output()
CVE-2025-40168 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandsmc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
CVE-2025-40146 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandblk-mq: fix potential deadlock while nr_requests grown
CVE-2025-64436 ↗cbl2 kubevirt 0.59.0-30 on CBL Mariner 2.0ModerateOut-of-bandKubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
CVE-2025-22124 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandmd/md-bitmap: fix wrong bitmap_limit for clustermd when write sb
CVE-2025-22090 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandx86/mm/pat: Fix VM_PAT handling when fork() fails in copy_page_range()
CVE-2025-21899 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandtracing: Fix bad hist from corrupting named_triggers list
CVE-2025-21907 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandmm: memory-failure: update ttu flag inside unmap_poisoned_folio
CVE-2024-38595 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5: Fix peer devlink set for SF representor devlink port
CVE-2025-21881 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-banduprobes: Reject the shared zeropage in uprobe_write_opcode()
CVE-2025-21872 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandefi: Don't map the entire mokvar table to determine its size
CVE-2023-53010 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbnxt: Do not read past the end of test names
CVE-2023-53009 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/amdkfd: Add sync after creating vram bo
CVE-2025-58186 ↗cbl2 gcc 11.2.0-8 on CBL Mariner 2.0ModerateOut-of-bandLack of limit when parsing cookies can cause memory exhaustion in net/http
CVE-2025-58183 ↗cbl2 cri-o 1.22.3-16 on CBL Mariner 2.0ModerateOut-of-bandUnbounded allocation when parsing GNU sparse map in archive/tar
CVE-2025-21838 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandusb: gadget: core: flush gadget workqueue after device removal
CVE-2025-21831 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandPCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1
CVE-2025-21738 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandata: libata-sff: Ensure that we cannot write outside the allocated buffer
CVE-2023-52981 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/i915: Fix request ref counting during error capture & debugfs dump
CVE-2025-40064 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandsmc: Fix use-after-free in __pnet_find_base_ndev().
CVE-2024-58053 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandrxrpc: Fix handling of received connection abort
CVE-2024-46716 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banddmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor
CVE-2025-21712 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandmd/md-bitmap: Synchronize bitmap_get_stats() with bitmap lifetime
CVE-2025-62813 ↗cbl2 lz4 1.9.4-1 on CBL Mariner 2.0ModerateOut-of-bandLZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in lib/lz4frame.c mishandles NULL checks.
CVE-2022-49562 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandKVM: x86: Use __try_cmpxchg_user() to update guest PTE A/D bits
CVE-2024-38564 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE
CVE-2024-57899 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandwifi: mac80211: fix mbss changed flags corruption on 32 bit systems
CVE-2025-21629 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets
CVE-2024-56709 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandio_uring: check if iowq is killed before queuing
CVE-2024-49568 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg
CVE-2025-39990 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandbpf: Check the helper function is valid in get_helper_proto
CVE-2020-8130 ↗azl3 ruby 3.3.5-5 on Azure Linux 3.0ModerateOut-of-bandThere is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.
CVE-2025-37727 ↗azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandElasticsearch Insertion of sensitive information in log file
CVE-2025-11413 ↗cbl2 binutils 2.37-16 on CBL Mariner 2.0ModerateOut-of-bandGNU Binutils Linker elflink.c elf_link_add_object_symbols out-of-bounds
CVE-2024-46717 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet/mlx5e: SHAMPO, Fix incorrect page release
CVE-2024-41079 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandnvmet: always initialize cqe.result
CVE-2024-56641 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet/smc: initialize close_work early to avoid warning
CVE-2024-40989 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandKVM: arm64: Disassociate vcpus from redistributor region on teardown
CVE-2022-48816 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandSUNRPC: lock against ->sock changing during sysfs read
CVE-2022-50502 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmm: /proc/pid/smaps_rollup: fix no vma's null-deref
CVE-2025-39940 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddm-stripe: fix a possible integer overflow
CVE-2025-39932 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandsmb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work)
CVE-2024-39508 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandio_uring/io-wq: Use set_bit() and test_bit() at worker->flags
CVE-2025-55554 ↗cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-bandpytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
CVE-2024-36922 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandwifi: iwlwifi: read txq->read_ptr under lock
CVE-2025-39927 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandceph: fix race condition validating r_parent before applying state
CVE-2024-36911 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandhv_netvsc: Don't free decrypted memory
CVE-2024-36909 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandDrivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted
CVE-2025-46150 ↗azl3 pytorch 2.2.2-7 on Azure Linux 3.0ModerateOut-of-bandIn PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
CVE-2025-46149 ↗cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-bandIn PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
CVE-2025-46153 ↗azl3 pytorch 2.2.2-7 on Azure Linux 3.0ModerateOut-of-bandPyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True.
CVE-2025-11083 ↗azl3 binutils 2.41-7 on Azure Linux 3.0ModerateOut-of-bandGNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflow
CVE-2024-49214 ↗cbl2 haproxy 2.4.24-1 on CBL Mariner 2.0ModerateOut-of-bandQUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a spoofed IP address. This can bypass the IP allow/block list functionality.
CVE-2022-43410 ↗azl3 mercurial 6.5.1-1 on Azure Linux 3.0ModerateOut-of-bandJenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.
CVE-2022-40896 ↗azl3 python-pygments 2.4.2-1 on Azure Linux 3.0ModerateOut-of-bandA ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
CVE-2007-3205 ↗cbl2 php 8.1.32-1 on CBL Mariner 2.0ModerateOut-of-bandThe parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin.
CVE-2025-10911 ↗cbl2 libxslt 1.1.34-8 on CBL Mariner 2.0ModerateOut-of-bandLibxslt: use-after-free with key data stored cross-rvt
CVE-2024-57945 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandriscv: mm: Fix the out of bound issue of vmemmap address
CVE-2024-57893 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandALSA: seq: oss: Fix races at processing SysEx messages
CVE-2024-57843 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandvirtio-net: fix overflow inside virtnet_rq_alloc
CVE-2024-35971 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: ks8851: Handle softirqs at the end of IRQ thread to fix hang
CVE-2024-35951 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/panfrost: Fix the error path in panfrost_mmu_map_fault_addr()
CVE-2024-35939 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-banddma-direct: Leak pages on dma_set_decrypted() failure
CVE-2024-35839 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandnetfilter: bridge: replace physindev with physinif in nf_bridge_info
CVE-2023-52732 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandceph: blocklist the kclient when receiving corrupted snap trace
CVE-2023-52676 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbpf: Guard stack limits against 32bit overflow
CVE-2025-39789 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandcrypto: x86/aegis - Add missing error checks
CVE-2025-39747 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddrm/msm: Add error handling for krealloc in metadata setup
CVE-2025-39762 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: add null check
CVE-2025-39754 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmm/smaps: fix race between smaps_hugetlb_range and migration
CVE-2025-39779 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandbtrfs: subpage: keep TOWRITE tag until folio is cleaned
CVE-2025-9901 ↗azl3 libsoup 3.4.4-9 on Azure Linux 3.0ModerateOut-of-bandLibsoup: improper handling of http vary header in libsoup caching