CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Patch Day month

August 2026 vulnerabilities

A defender-focused view of 2,459 vulnerabilities across 3,874 returned patch records from 4 vendors. Filter the month to date, or browse the static page trail without JavaScript.

3,874all patch recordsClear filters183criticalShow these records1Microsoft exploitation detectedShow these records2Microsoft in CISA KEVShow these records1,062tracked hereShow these records

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as “no.” “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.

Page 18 of 20 · records 3,401–3,600 of 3,874

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-39716 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandparisc: Revise __get_user() to probe user read access
CVE-2025-38734 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet/smc: fix UAF on smcsk after smc_listen_out()
CVE-2025-39707 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities
CVE-2025-39706 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: Destroy KFD debugfs after destroy KFD wq
CVE-2025-39677 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandnet/sched: Fix backlog accounting in qdisc_dequeue_internal
CVE-2025-39705 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: fix a Null pointer dereference vulnerability
CVE-2025-38704 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandrcu/nocb: Fix possible invalid rdp's->nocb_cb_kthread pointer access
CVE-2025-38717 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: kcm: Fix race condition in kcm_unattach()
CVE-2025-38722 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandhabanalabs: fix UAF in export_dmabuf()
CVE-2025-38705 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/pm: fix null pointer access
CVE-2025-38709 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandloop: Avoid updating block size under exclusive owner
CVE-2025-37842 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandspi: fsl-qspi: use devm function instead of driver remove
CVE-2024-57857 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandRDMA/siw: Remove direct link to net_device
CVE-2025-38611 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandvmci: Prevent the dispatching of uninitialized payloads
CVE-2025-45768 ↗azl3 python-jwt 2.8.0-1 on Azure Linux 3.0ModerateOut-of-bandpyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).
CVE-2025-38590 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5e: Remove skb secpath if xfrm state is not found
CVE-2024-36024 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Disable idle reallow as part of command/gpint execution
CVE-2025-38591 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Reject narrower access to pointer ctx fields
CVE-2025-38272 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet: dsa: b53: do not enable EEE on bcm63xx
CVE-2025-38029 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandkasan: avoid sleepable page allocation from atomic context
CVE-2025-38520 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: Don't call mmput from MMU notifier callback
CVE-2025-38269 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: exit after state insertion failure at btrfs_convert_extent_bit()
CVE-2025-8197 ↗cbl2 libsoup 3.0.4-9 on CBL Mariner 2.0ModerateOut-of-bandRejected reason: Maintainers have included reasons at https://gitlab.gnome.org/GNOME/libsoup/-/issues/465
CVE-2025-40325 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmd/raid10: wait barrier before returning discard request with REQ_NOWAIT
CVE-2025-38279 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandbpf: Do not include stack ptr register in precision backtracking bookkeeping
CVE-2024-58006 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandPCI: dwc: ep: Prevent changing BAR size/flags in pci_epc_set_bar()
CVE-2025-38303 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandBluetooth: eir: Fix possible crashes on eir_create_adv_data
CVE-2025-37856 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandbtrfs: harden block_group::bg_list against list_del() races
CVE-2025-2309 ↗cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0ModerateOut-of-bandHDF5 Type Conversion Logic H5T__bit_copy heap-based overflow
CVE-2025-38524 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandrxrpc: Fix recv-recv race of completed call
CVE-2025-2308 ↗azl3 hdf5 1.14.4.3-1 on Azure Linux 3.0ModerateOut-of-bandHDF5 Scale-Offset Filter H5Z__scaleoffset_decompress_one_byte heap-based overflow
CVE-2025-38064 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandvirtio: break and reset virtio devices on device_shutdown()
CVE-2024-42317 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandmm/huge_memory: avoid PMD-size page cache if needed
CVE-2025-38678 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_tables: reject duplicate device on updates
CVE-2024-47794 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Prevent tailcall infinite loop caused by freplace
CVE-2024-57898 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandwifi: cfg80211: clear link ID from bitmap during link delete after clean up
CVE-2024-26759 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandmm/swap: fix race when skipping swapcache
CVE-2024-41067 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandbtrfs: scrub: handle RST lookup error correctly
CVE-2025-22115 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix block group refcount race in btrfs_create_pending_block_groups()
CVE-2025-37745 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandPM: hibernate: Avoid deadlock in hibernate_compressor_param_set()
CVE-2025-23167 ↗azl3 nodejs 20.14.0-9 on Azure Linux 3.0ModerateOut-of-bandA flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.
CVE-2025-21885 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandRDMA/bnxt_re: Fix the page details for the srq created by kernel consumers
CVE-2024-57804 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandscsi: mpi3mr: Fix corrupt config pages PHY state is switched in sysfs
CVE-2025-21892 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mlx5: Fix the recovery flow of the UMR QP
CVE-2025-55199 ↗cbl2 helm 3.14.2-7 on CBL Mariner 2.0ModerateOut-of-bandHelm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion
CVE-2024-26756 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandmd: Don't register sync_thread for reshape directly
CVE-2025-21732 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandRDMA/mlx5: Fix a race for an ODP MR which leads to CQE with error
CVE-2022-49531 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandloop: implement ->free_disk
CVE-2024-41932 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandsched: fix warning in sched_setaffinity
CVE-2024-44939 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandjfs: fix null ptr deref in dtInsertEntry
CVE-2024-57875 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandblock: RCU protect disk->conv_zones_bitmap
CVE-2025-6856 ↗cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0ModerateOut-of-bandHDF5 H5FL.c H5FL__reg_gc_list use after free
CVE-2025-38380 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandi2c/designware: Fix an initialization issue
CVE-2024-56591 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: hci_conn: Use disable_delayed_work_sync
CVE-2024-26706 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandparisc: Fix random data corruption from exception handler
CVE-2025-6817 ↗cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0ModerateOut-of-bandHDF5 H5Centry.c H5C__load_entry resource consumption
CVE-2024-57976 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: do proper folio cleanup when cow_file_range() failed
CVE-2025-37826 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandscsi: ufs: core: Add NULL check in ufshcd_mcq_compl_pending_transfer()
CVE-2025-37877 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandiommu: Clear iommu-dma ops on cleanup
CVE-2024-58089 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix double accounting race when btrfs_run_delalloc_range() failed
CVE-2024-35865 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandsmb: client: fix potential UAF in smb2_is_valid_oplock_break()
CVE-2025-38643 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandwifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac()
CVE-2024-46754 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandbpf: Remove tst_run from lwt_seg6local_prog_ops.
CVE-2025-21801 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet: ravb: Fix missing rtnl lock in suspend/resume path
CVE-2024-43819 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandkvm: s390: Reject memory region operations for ucontrol VMs
CVE-2024-35931 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: Skip do PCI error slot reset during RAS recovery
CVE-2024-50009 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandcpufreq: amd-pstate: add check for cpufreq_cpu_get's return value
CVE-2024-43872 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandRDMA/hns: Fix soft lockup under heavy CEQE load
CVE-2025-37920 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandxsk: Fix race condition in AF_XDP generic RX path
CVE-2024-40999 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: ena: Add validation for completion descriptors consistency
CVE-2024-49897 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Check phantom_stream before it is used
CVE-2025-37870 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: prevent hang on link training fail
CVE-2023-51580 ↗azl3 bluez 5.63-6 on Azure Linux 3.0ModerateOut-of-bandBlueZ Audio Profile AVRCP avrcp_parse_attribute_list Out-Of-Bounds Read Information Disclosure Vulnerability
CVE-2025-37834 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandmm/vmscan: don't try to reclaim hwpoison folio
CVE-2023-51589 ↗cbl2 bluez 5.63-6 on CBL Mariner 2.0ModerateOut-of-bandBlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability
CVE-2024-46727 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/amd/display: Add otg_master NULL check within resource_log_pipe_topology_update
CVE-2024-53426 ↗cbl2 ntopng 5.2.1-3 on CBL Mariner 2.0ModerateOut-of-bandA heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.
CVE-2024-26758 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandmd: Don't ignore suspended array in md_check_recovery()
CVE-2024-47661 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Avoid overflow from uint32_t to uint8_t
CVE-2024-53219 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandvirtiofs: use pages instead of pointer for kernel direct IO
CVE-2025-38636 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandrv: Use strings in da monitors tracepoints
CVE-2024-41066 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandibmvnic: Add tx check to prevent skb leak
CVE-2024-26757 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandmd: Don't ignore read-only array in md_check_recovery()
CVE-2025-38359 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bands390/mm: Fix in_atomic() handling in do_secure_storage_access()
CVE-2024-46730 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Ensure array index tg_inst won't be -1
CVE-2023-45927 ↗azl3 slang 2.3.3-1 on Azure Linux 3.0ModerateOut-of-bandS-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf().
CVE-2024-57974 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandudp: Deal with race between UDP socket address change and rehash
CVE-2023-52670 ↗cbl2 kernel 5.15.182.1-1 on CBL Mariner 2.0ModerateOut-of-bandrpmsg: virtio: Free driver_override when rpmsg_remove()
CVE-2025-6516 ↗cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0ModerateOut-of-bandHDF5 H5Fint.c H5F_addr_decode_len heap-based overflow
CVE-2024-57809 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandPCI: imx6: Fix suspend/resume support on i.MX6QDL
CVE-2024-35999 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandsmb3: missing lock when picking channel
CVE-2025-22108 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandbnxt_en: Mask the bd_cnt field in the TX BD properly
CVE-2024-27062 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnouveau: lock the client object tree.
CVE-2024-35887 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandax25: fix use-after-free bugs caused by ax25_ds_del_timer
CVE-2024-41082 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnvme-fabrics: use reserved tag for reg read/write command
CVE-2025-8734 ↗azl3 bison 3.8.2-1 on Azure Linux 3.0ModerateOut-of-bandGNU Bison scan-code.c code_free double free
CVE-2024-40969 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandf2fs: don't set RO when shutting down f2fs
CVE-2025-8733 ↗azl3 bison 3.8.2-1 on Azure Linux 3.0ModerateOut-of-bandGNU Bison obprintf.c __obstack_vprintf_internal assertion
CVE-2025-38232 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNFSD: fix race between nfsd registration and exports_proc
CVE-2024-26853 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandigc: avoid returning frame twice in XDP_REDIRECT
CVE-2025-21768 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels
CVE-2024-26830 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandi40e: Do not allow untrusted VF to remove administratively set MAC
CVE-2025-38234 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandsched/rt: Fix race in push_rt_task
CVE-2025-21825 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Cancel the running bpf_timer through kworker for PREEMPT_RT
CVE-2024-40977 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandwifi: mt76: mt7921s: fix potential hung tasks during chip recovery
CVE-2024-41008 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: change vm->task_info handling
CVE-2025-22109 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandax25: Remove broken autobind
CVE-2025-21870 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers
CVE-2024-50177 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: fix a UBSAN warning in DML2.1
CVE-2025-21888 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mlx5: Fix a WARN during dereg_mr for DM type
CVE-2025-45582 ↗azl3 tar 1.35-2 on Azure Linux 3.0ModerateOut-of-bandGNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in wh
CVE-2024-42151 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandbpf: mark bpf_dummy_struct_ops.test_1 parameter as nullable
CVE-2025-21696 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandmm: clear uffd-wp PTE/PMD state on mremap()
CVE-2024-56738 ↗cbl2 grub2 2.06-14 on CBL Mariner 2.0ModerateOut-of-bandGNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
CVE-2024-41045 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandbpf: Defer work in bpf_timer_cancel_and_free
CVE-2024-42081 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddrm/xe/xe_devcoredump: Check NULL before assignments
CVE-2025-21976 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandfbdev: hyperv_fb: Allow graceful removal of framebuffer
CVE-2025-37907 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandaccel/ivpu: Fix locking order in ivpu_job_submit
CVE-2024-44951 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandserial: sc16is7xx: fix TX fifo corruption
CVE-2025-37861 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandscsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue
CVE-2024-47736 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: handle overlapped pclusters out of crafted images properly
CVE-2024-6531 ↗cbl2 opa 0.63.0-4 on CBL Mariner 2.0ModerateOut-of-bandRejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.
CVE-2024-46834 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandethtool: fail closed if we can't get max channel used in indirection tables
CVE-2024-42065 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/xe: Add a NULL check in xe_ttm_stolen_mgr_init
CVE-2024-49934 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandfs/inode: Prevent dump_mapping() accessing invalid dentry.d_name.name
CVE-2024-43886 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/amd/display: Add null check in resource_log_pipe_topology_update
CVE-2024-38608 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5e: Fix netif state handling
CVE-2024-50613 ↗azl3 libsndfile 1.2.2-3 on Azure Linux 3.0ModerateOut-of-bandlibsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.
CVE-2024-49926 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandrcu-tasks: Fix access non-existent percpu rtpcp variable in rcu_tasks_need_gpcb()
CVE-2024-42253 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandgpio: pca953x: fix pca953x_irq_bus_sync_unlock race
CVE-2024-50614 ↗cbl2 tinyxml2 9.0.0-2 on CBL Mariner 2.0ModerateOut-of-bandTinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
CVE-2024-43901 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Fix NULL pointer dereference for DTN log in DCN401
CVE-2022-48887 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/vmwgfx: Remove rcu locks from user resources
CVE-2025-31181 ↗cbl2 gnuplot 5.4.3-1 on CBL Mariner 2.0ModerateOut-of-bandGnuplot: gnuplot segmentation fault on x11_graphics
CVE-2024-42227 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/amd/display: Fix overlapping copy within dml_core_mode_programming
CVE-2023-1386 ↗azl3 qemu 8.2.0-17 on Azure Linux 3.0ModerateOut-of-bandQemu: 9pfs: suid/sgid bits not dropped on file write
CVE-2024-46842 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandscsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info
CVE-2024-44956 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/xe/preempt_fence: enlarge the fence critical section
CVE-2025-31179 ↗cbl2 gnuplot 5.4.3-1 on CBL Mariner 2.0ModerateOut-of-bandGnuplot: gnuplot segmentation fault on xstrftime
CVE-2024-52559 ↗azl3 kernel 6.6.82.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit()
CVE-2025-31176 ↗azl3 gnuplot 5.4.8-1 on Azure Linux 3.0ModerateOut-of-bandGnuplot: gnuplot segmentation fault on plot3d_points
CVE-2024-42123 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: fix double free err_addr pointer warnings
CVE-2024-41085 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandcxl/mem: Fix no cxl_nvd during pmem region auto-assembling
CVE-2024-49917 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Add NULL check for clk_mgr and clk_mgr->funcs in dcn30_init_hw
CVE-2019-20633 ↗azl3 patch 2.7.6-9 on Azure Linux 3.0ModerateOut-of-bandGNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.
CVE-2022-48673 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet/smc: Fix possible access to freed memory in link clear
CVE-2024-49915 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Add NULL check for clk_mgr in dcn32_init_hw
CVE-2024-49923 ↗azl3 kernel 6.6.79.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Pass non-null to dcn20_validate_apply_pipe_split_flags
CVE-2024-43913 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandnvme: apple: fix device reference counting
CVE-2024-46681 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandpktgen: use cpus_read_lock() in pg_net_init()
CVE-2024-46705 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/xe: reset mmio mappings with devm
CVE-2024-46701 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandlibfs: fix infinite directory reads for offset dir
CVE-2024-41014 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandxfs: add bounds checking to xlog_recover_process_data
CVE-2024-44970 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet/mlx5e: SHAMPO, Fix invalid WQ linked list unlink
CVE-2024-49898 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Check null-initialized variables
CVE-2024-42158 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bands390/pkey: Use kfree_sensitive() to fix Coccinelle warnings
CVE-2024-49911 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Add NULL check for function pointer in dcn20_set_output_transfer_func
CVE-2024-46698 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandvideo/aperture: optionally match the device in sysfb_disable()
CVE-2019-11254 ↗azl3 packer 1.9.5-11 on Azure Linux 3.0ModerateOut-of-bandKubernetes API Server denial of service vulnerability from malicious YAML payloads
CVE-2024-46808 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Add missing NULL pointer check within dpcd_extend_address_range
CVE-2024-41023 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandsched/deadline: Fix task_struct reference leak
CVE-2024-49909 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Add NULL check for function pointer in dcn32_set_output_transfer_func
CVE-2023-52920 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbpf: support non-r10 register spill/fill to/from stack in precision tracking
CVE-2024-43824 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandPCI: endpoint: pci-epf-test: Make use of cached 'epc_features' in pci_epf_test_core_init()
CVE-2025-38333 ↗azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix to bail out in get_new_segment()
CVE-2025-38097 ↗azl3 kernel 6.6.92.2-2 on Azure Linux 3.0ModerateOut-of-bandespintcp: remove encap socket caching to avoid reference leak
CVE-2025-38127 ↗azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ModerateOut-of-bandice: fix Tx scheduler error handling in XDP callback
CVE-2025-38192 ↗azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: clear the dst when changing skb protocol
CVE-2025-38334 ↗azl3 kernel 6.6.92.2-2 on Azure Linux 3.0ModerateOut-of-bandx86/sgx: Prevent attempts to reclaim poisoned pages
CVE-2025-4432 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandRing: some aes functions may panic when overflow checking is enabled in ring
CVE-2024-49569 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandnvme-rdma: unquiesce admin_q before destroy it
CVE-2025-22057 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandnet: decrease cached dst counters in dst_release
CVE-2025-37800 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-banddriver core: fix potential NULL pointer dereference in dev_uevent()
CVE-2025-37801 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandspi: spi-imx: Add check for spi_imx_setupxfer()
CVE-2025-37849 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandKVM: arm64: Tear down vGIC on failed vCPU creation
CVE-2025-37852 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create()
CVE-2025-37853 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: debugfs hang_hws skip GPU with MES
CVE-2025-37878 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandperf/core: Fix WARN_ON(!ctx) in __free_event() for partial init
CVE-2025-37884 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix deadlock between rcu_tasks_trace and event_mutex.
CVE-2024-50615 ↗azl3 tinyxml2 9.0.0-2 on Azure Linux 3.0ModerateOut-of-bandTinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
CVE-2025-21947 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandksmbd: fix type confusion via race condition when using ipc_msg_send_request
CVE-2025-21969 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandBluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd
CVE-2025-21792 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandax25: Fix refcount leak caused by setting SO_BINDTODEVICE sockopt
CVE-2025-21667 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandiomap: avoid avoid truncating 64-bit offset to 32 bits
CVE-2025-21673 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandsmb: client: fix double free of TCP_Server_Info::hostname
CVE-2024-47141 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandpinmux: Use sequential access to access desc->pinmux data
CVE-2024-47809 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-banddlm: fix possible lkb_resource null dereference
CVE-2024-48875 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: don't take dev_replace rwsem on task already holding it
CVE-2024-56665 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf,perf: Fix invalid prog_array access in perf_event_detach_bpf_prog
CVE-2024-56703 ↗azl3 kernel 6.6.78.1-3 on Azure Linux 3.0ModerateOut-of-bandipv6: Fix soft lockups in fib6_select_path under high next hop churn
CVE-2024-56719 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: stmmac: fix TSO DMA API usage causing oops
CVE-2024-50248 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandntfs3: Add bounds checking to mi_enum_attr()
CVE-2024-50256 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_reject_ipv6: fix potential crash in nf_send_reset6()
CVE-2024-50284 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: Fix the missing xa_store error check
CVE-2024-50285 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: check outstanding simultaneous SMB operations
CVE-2024-53079 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandmm/thp: fix deferred split unqueue naming and locking
CVE-2024-53091 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Add sk_is_inet and IS_ICSK check in tls_sw_has_ctx_tx/rx
CVE-2024-53093 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandnvme-multipath: defer partition scanning
CVE-2024-53094 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES
CVE-2024-53100 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandnvme: tcp: avoid race between queue_lock lock and destroy