CYBERSECURITYTRACKER
TRACKING3,741 stories685 vuln stories
Patch Day month

August 2026 vulnerabilities

A server-rendered hunting trail for August 2026: 1,834 returned patch records across 4 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.

1,834all patches
57critical
0exploitation detected
1in CISA KEV
293tracked here
Microsoft 1,222Red Hat 581Cisco 30Android 1

Page 5 of 10 · records 801–1,000 of 1,834

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-64530 ↗2026-07-27azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
CVE-2024-14040 ↗2026-07-27azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ModerateOut-of-bandnet: nexthop: Increase weight to u16
CVE-2026-64297 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandmodule: decompress: check return value of module_extend_max_pages()
CVE-2026-64486 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: cmipci: check snd_ctl_new1() return value
CVE-2026-64494 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandiio: light: gp2ap002: fix runtime PM leak on read error
CVE-2026-64375 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandproc: protect ptrace_may_access() with exec_update_lock (FD links)
CVE-2026-64384 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%smb: client: fix change notify replay double-free
CVE-2026-64468 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%binder: fix UAF in binder_free_transaction()
CVE-2026-64472 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandvfio/mlx5: Fix racy bitfields and tighten struct layout
CVE-2026-64413 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%netfilter: ebtables: zero chainstack array
CVE-2026-64331 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusbip: vudc: fix NULL deref in vep_dequeue()
CVE-2026-64452 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%6lowpan: fix NHC entry use-after-free on error path
CVE-2026-64335 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: serial: digi_acceleport: fix broken rx after throttle
CVE-2026-64493 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandiio: pressure: mpl115: fix runtime PM leak on read error
CVE-2026-64497 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandiio: chemical: scd30: Cleanup initializations and fix sign-extension bug
CVE-2026-64401 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandsmb: client: resolve SWN tcon from live registrations
CVE-2026-64428 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandgpio: sch: use raw_spinlock_t in the irq startup path
CVE-2026-64319 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band1%nvmet-auth: validate reply message payload bounds against transfer length
CVE-2026-64276 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandInput: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
CVE-2026-64372 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandcpufreq: pcc: fix use-after-free and double free in _OSC evaluation
CVE-2026-64352 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Allow LPM map access from sleepable BPF programs
CVE-2026-64465 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: xhci: Fix sleep in atomic context in xhci_free_streams()
CVE-2026-64514 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-banduserfaultfd: gate must_wait writability check on pte_present()
CVE-2026-64475 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%vfio/pci: Release the VGA arbiter client on register_device() failure
CVE-2026-64481 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%ALSA: hda/cs35l41: Fix firmware load work teardown
CVE-2026-64421 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandmedia: nxp: imx8-isi: Fix use-after-free on remove
CVE-2026-64391 ↗2026-07-26azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ImportantOut-of-band0%ksmbd: use opener credentials for ADS I/O
CVE-2026-64274 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandInput: goodix - clamp the device-reported contact count
CVE-2026-64315 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: caam - use print_hex_dump_devel to guard key hex dumps
CVE-2026-64438 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()
CVE-2026-64443 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop
CVE-2026-64270 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandInput: mms114 - reject an oversized device packet size
CVE-2026-64322 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandudf: validate sparing table length as an entry count, not a byte count
CVE-2026-64385 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%smb: client: fix double-free in SMB2_ioctl() replay
CVE-2026-64436 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%net: af_key: initialize alg_key_len for IPComp states
CVE-2026-64479 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()
CVE-2026-64347 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: gadget: composite: fix dead empty check in the USB_DT_OTG handler
CVE-2026-64458 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandmm/damon/ops-common: handle extreme intervals in damon_hot_score()
CVE-2026-64435 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%audit: Fix data races of skb_queue_len() readers on audit_queue
CVE-2026-64422 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes
CVE-2026-64511 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandACPI: NFIT: core: Fix possible NULL pointer dereference
CVE-2026-64275 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandInput: elan_i2c - prevent division by zero and arithmetic underflow
CVE-2026-64296 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandexfat: bound uniname advance in exfat_find_dir_entry()
CVE-2026-64280 ↗2026-07-26azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ImportantOut-of-bandfpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
CVE-2026-64364 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandHID: multitouch: fix out-of-bounds bit access on mt_io_flags
CVE-2026-64287 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
CVE-2026-64329 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove
CVE-2026-64332 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandUSB: ulpi: fix memory leak on registration failure
CVE-2026-64440 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%staging: rtl8723bs: fix OOB write in HT_caps_handler()
CVE-2026-64393 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%ksmbd: run set info with opener credentials
CVE-2026-64449 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%staging: vme_user: bound slave read/write to the kern_buf size
CVE-2026-64456 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%hwrng: virtio: clamp device-reported used.len at copy_data()
CVE-2026-64513 ↗2026-07-26azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ImportantOut-of-bandKVM: x86: Unconditionally recompute CR8 intercept on PPR update
CVE-2026-64342 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: iowarrior: fix use-after-free on disconnect
CVE-2026-64365 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandHID: letsketch: fix UAF on inrange_timer at driver unbind
CVE-2026-64370 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandposix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path
CVE-2026-64359 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandnilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers
CVE-2026-64363 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandHID: appleir: fix UAF on pending key_up_timer in remove()
CVE-2026-64508 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandbpf: Support for hardening against JIT spraying
CVE-2026-64380 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandsmb: client: harden POSIX SID length parsing
CVE-2026-64373 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandcpufreq: Fix hotplug-suspend race during reboot
CVE-2026-64512 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-bandACPI: CPPC: Suppress UBSAN warning caused by field misuse
CVE-2026-64392 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%ksmbd: use opener credentials for delete-on-close
CVE-2026-64389 ↗2026-07-26azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ImportantOut-of-bandksmbd: validate NTLMv2 response before updating session key
CVE-2026-64434 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
CVE-2026-64483 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandALSA: firewire: isight: bound the sample count to the packet payload
CVE-2026-64503 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandiio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
CVE-2026-64269 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band1%RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
CVE-2026-64337 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: mtu3: unmap request DMA on queue failure
CVE-2026-64371 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandproc: protect ptrace_may_access() with exec_update_lock (part 1)
CVE-2026-64406 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: fix UAF in bt_accept_dequeue()
CVE-2026-64376 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandfirmware_loader: fix device reference leak in firmware_upload_register()
CVE-2026-64487 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
CVE-2026-64445 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
CVE-2026-64304 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: qat - validate RSA CRT component lengths
CVE-2026-64390 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: track the connection owning a byte-range lock
CVE-2026-64412 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ebtables: module names must be null-terminated
CVE-2026-64345 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: f_printer: take kref only for successful open
CVE-2026-64387 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%smb: client: fix query directory replay double-free
CVE-2026-64320 ↗2026-07-26azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ImportantOut-of-band1%nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
CVE-2026-64397 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%ksmbd: serialize QUERY_DIRECTORY requests per file
CVE-2026-64361 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandhfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
CVE-2026-64409 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()
CVE-2026-64446 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandstaging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
CVE-2026-64306 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: drbg - Fix returning success on failure in CTR_DRBG
CVE-2026-64279 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandi2c: core: fix adapter deregistration race
CVE-2026-64338 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandUSB: misc: uss720: unregister parport on probe failure
CVE-2026-64437 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL
CVE-2026-64504 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandiio: accel: bmc150: clamp the device-reported FIFO frame count
CVE-2026-64419 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandmm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()
CVE-2026-64507 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandx86/bugs: Enable IBPB flush on BPF JIT allocation
CVE-2026-64399 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
CVE-2026-64476 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandvfio/pci: Latch disable_idle_d3 per device
CVE-2026-64525 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit
CVE-2026-64374 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandsched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
CVE-2026-64358 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandmedia: mtk-jpeg: cancel workqueue on release for supported platforms only
CVE-2026-64341 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: iowarrior: fix use-after-free on disconnect race
CVE-2026-64268 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%RDMA/siw: bound Read Response placement to the RREAD length
CVE-2026-64505 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: gadget: function: rndis: add length check for header
CVE-2026-64348 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: free iso schedules on failed submit
CVE-2026-64316 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: caam - use print_hex_dump_devel to guard key hex dumps
CVE-2026-64340 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: legousbtower: fix use-after-free on disconnect race
CVE-2026-64425 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandio_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item
CVE-2026-64408 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: bnep: pin L2CAP connection during netdev registration
CVE-2026-64360 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandhfs/hfsplus: zero-initialize buffer in hfs_bnode_read
CVE-2026-64462 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandPCI: altera: Fix resource leaks on probe failure
CVE-2026-64333 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: serial: digi_acceleport: fix write buffer corruption
CVE-2026-64448 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%smb: client: restrict implied bcc[0] exemption to responses without data area
CVE-2026-64395 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandksmbd: require source read access for duplicate extents
CVE-2026-64277 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandInput: synaptics-rmi4 - bound the F3A keymap to the GPIO count
CVE-2026-64450 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band1%tipc: fix out-of-bounds read in broadcast Gap ACK blocks
CVE-2026-64362 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandHID: lg-g15: cancel pending work on remove to fix a use-after-free
CVE-2026-64489 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: ymfpci: check snd_ctl_new1() return value
CVE-2026-64343 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: ldusb: fix use-after-free on disconnect race
CVE-2026-64400 ↗2026-07-26azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: prevent path traversal bypass by restricting caseless retry
CVE-2026-64305 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: qat - protect service table iterations with service_lock
CVE-2026-64368 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandmm/slab: do not limit zeroing to orig_size when only red zoning is enabled
CVE-2026-64386 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%smb: client: fix query_info() replay double-free
CVE-2026-64336 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: serial: keyspan_pda: fix information leak
CVE-2026-64474 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandvfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc
CVE-2026-64411 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandnetfilter: ebtables: terminate table name before find_table_lock()
CVE-2026-64273 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandInput: iforce - bound the device-reported force-feedback effect index
CVE-2026-64326 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandblock: skip sync_blockdev() on surprise removal in bdev_mark_dead()
CVE-2026-64495 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandiio: gyro: bmg160: bail out when bandwidth/filter is not in table
CVE-2026-64424 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnetpoll: fix a use-after-free on shutdown path
CVE-2026-64469 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%binder: fix UAF in binder_thread_release()

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-47204CVSS 6.5Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:59fa6f408b345a25d7e9dd12cf79c5e56cae7a7c2d814ef32512346021485060_amd64Patch ↗Advisory ↗
Red HatCVE-2026-47204CVSS 6.5Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:94921265f210e84d79eeba8821c4527e81c36bfc7ce98f0cc8d64b44cbeef7a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-47204CVSS 6.5Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:a9893f3cced5ab9bafa20ae5f920cba27e852cc5e9f28b01a349a21d8f1ea63f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-47204CVSS 6.5Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:09292f6545b2e6619bbbd267024fa4f9c6c8b760e53cfc2833eb54d9f453453e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-47221CVSS 5.9Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:59fa6f408b345a25d7e9dd12cf79c5e56cae7a7c2d814ef32512346021485060_amd64Patch ↗Advisory ↗
Red HatCVE-2026-47221CVSS 5.9Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:94921265f210e84d79eeba8821c4527e81c36bfc7ce98f0cc8d64b44cbeef7a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-47221CVSS 5.9Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:a9893f3cced5ab9bafa20ae5f920cba27e852cc5e9f28b01a349a21d8f1ea63f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-47221CVSS 5.9Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:09292f6545b2e6619bbbd267024fa4f9c6c8b760e53cfc2833eb54d9f453453e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-47691CVSS 8.7Red Hat JBoss EAP 8.1 for RHEL 10eap8-eap-product-conf-parent-0:801.7.1-1.GA_redhat_00001.1.el10eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-47691CVSS 8.7Red Hat JBoss Enterprise Application Platform 8.1Patch ↗Advisory ↗
Red HatCVE-2026-48042CVSS 7.5Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:59fa6f408b345a25d7e9dd12cf79c5e56cae7a7c2d814ef32512346021485060_amd64Patch ↗Advisory ↗
Red HatCVE-2026-48042CVSS 7.5Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:94921265f210e84d79eeba8821c4527e81c36bfc7ce98f0cc8d64b44cbeef7a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-48042CVSS 7.5Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:a9893f3cced5ab9bafa20ae5f920cba27e852cc5e9f28b01a349a21d8f1ea63f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-48042CVSS 7.5Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:09292f6545b2e6619bbbd267024fa4f9c6c8b760e53cfc2833eb54d9f453453e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-48044CVSS 7.5Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:59fa6f408b345a25d7e9dd12cf79c5e56cae7a7c2d814ef32512346021485060_amd64Patch ↗Advisory ↗
Red HatCVE-2026-48044CVSS 7.5Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:94921265f210e84d79eeba8821c4527e81c36bfc7ce98f0cc8d64b44cbeef7a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-48044CVSS 7.5Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:a9893f3cced5ab9bafa20ae5f920cba27e852cc5e9f28b01a349a21d8f1ea63f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-48044CVSS 7.5Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:09292f6545b2e6619bbbd267024fa4f9c6c8b760e53cfc2833eb54d9f453453e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-48068CVSS 7.5Red Hat Developer Hub 1.10registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:08883fc7f9806289ecec95f75d4e9ee5c44a12ff372252e10398293c78b0514f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-48069CVSS 7.5Red Hat Developer Hub 1.10registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:08883fc7f9806289ecec95f75d4e9ee5c44a12ff372252e10398293c78b0514f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-48706CVSS 5.9Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:94921265f210e84d79eeba8821c4527e81c36bfc7ce98f0cc8d64b44cbeef7a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-48706CVSS 5.9Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:a9893f3cced5ab9bafa20ae5f920cba27e852cc5e9f28b01a349a21d8f1ea63f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-48706CVSS 5.9Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:09292f6545b2e6619bbbd267024fa4f9c6c8b760e53cfc2833eb54d9f453453e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-48743CVSS 7.5Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:a9893f3cced5ab9bafa20ae5f920cba27e852cc5e9f28b01a349a21d8f1ea63f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-48743CVSS 7.5Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:09292f6545b2e6619bbbd267024fa4f9c6c8b760e53cfc2833eb54d9f453453e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-48801CVSS 7.5Red Hat Developer Hub 1.10registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:08883fc7f9806289ecec95f75d4e9ee5c44a12ff372252e10398293c78b0514f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-49978CVSS 8.1Red Hat Developer Hub 1.10registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:08883fc7f9806289ecec95f75d4e9ee5c44a12ff372252e10398293c78b0514f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-49978CVSS 8.1Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:0afd0142183f5b43b618e3db4fc16efd5fd6c5db688ad7eb22ec7a315247bf92_s390xPatch ↗Advisory ↗
Red HatCVE-2026-50010CVSS 7.5Red Hat JBoss EAP 8.1 for RHEL 10eap8-eap-product-conf-parent-0:801.7.1-1.GA_redhat_00001.1.el10eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-50010CVSS 7.5Red Hat JBoss Enterprise Application Platform 8.1Patch ↗Advisory ↗
Red HatCVE-2026-5038CVSS 7.5Red Hat Developer Hub 1.10registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:08883fc7f9806289ecec95f75d4e9ee5c44a12ff372252e10398293c78b0514f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-5079CVSS 7.5Red Hat Developer Hub 1.10registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:08883fc7f9806289ecec95f75d4e9ee5c44a12ff372252e10398293c78b0514f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-53705CVSS 7.6Red Hat Enterprise Linux AppStream AUS (v.8.4)gstreamer1-plugins-good-0:1.16.1-4.el8_4.1.i686Patch ↗Advisory ↗
Red HatCVE-2026-56208CVSS 7.6Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-58010CVSS 6.5Red Hat Enterprise Linux CRB (v. 8)mingw-glib2-0:2.70.1-9.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-58011CVSS 6.5Red Hat Enterprise Linux CRB (v. 8)mingw-glib2-0:2.70.1-9.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-58012CVSS 6.5Red Hat Enterprise Linux CRB (v. 8)mingw-glib2-0:2.70.1-9.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-58013CVSS 6.5Red Hat Enterprise Linux CRB (v. 8)mingw-glib2-0:2.70.1-9.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-58014CVSS 7.3Red Hat Enterprise Linux CRB (v. 8)mingw-glib2-0:2.70.1-9.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-58015CVSS 5.9Red Hat Enterprise Linux CRB (v. 8)mingw-glib2-0:2.70.1-9.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-58016CVSS 7.5Red Hat Enterprise Linux CRB (v. 8)mingw-glib2-0:2.70.1-9.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-59869trackedCVSS 7.5Red Hat Developer Hub 1.10registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:08883fc7f9806289ecec95f75d4e9ee5c44a12ff372252e10398293c78b0514f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-59869trackedCVSS 7.5Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:0afd0142183f5b43b618e3db4fc16efd5fd6c5db688ad7eb22ec7a315247bf92_s390xPatch ↗Advisory ↗
Red HatCVE-2026-59869trackedCVSS 7.5Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:75b1c9d084f5cfd18aeced0d801bdff647bce79b83cfa27d3e2ba7954515ced0_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-59869trackedCVSS 7.5Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:4621e29182691b4968319d414ad7fcda8c625c73e9cd91bc9a1fc3e3c8fc438f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-59869trackedCVSS 7.5Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:097bbedcb4141e9b58d790cf7bb4c6612df8b9aefa1bc90826bb3a8176740960_s390xPatch ↗Advisory ↗
Red HatCVE-2026-59873trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)nodejs-1:24.18.0-3.module+el9.8.0+24537+83ec84e1.aarch64::nodejs:24Patch ↗Advisory ↗
Red HatCVE-2026-59873trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)nodejs-1:22.23.1-2.module+el9.8.0+24538+3f176d52.aarch64::nodejs:22Patch ↗Advisory ↗
Red HatCVE-2026-59873trackedCVSS 7.5Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:0afd0142183f5b43b618e3db4fc16efd5fd6c5db688ad7eb22ec7a315247bf92_s390xPatch ↗Advisory ↗
Red HatCVE-2026-59873trackedCVSS 7.5Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:75b1c9d084f5cfd18aeced0d801bdff647bce79b83cfa27d3e2ba7954515ced0_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-59873trackedCVSS 7.5Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:4621e29182691b4968319d414ad7fcda8c625c73e9cd91bc9a1fc3e3c8fc438f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-59873trackedCVSS 7.5Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:097bbedcb4141e9b58d790cf7bb4c6612df8b9aefa1bc90826bb3a8176740960_s390xPatch ↗Advisory ↗
Red HatCVE-2026-59874trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)nodejs-1:24.18.0-3.module+el9.8.0+24537+83ec84e1.aarch64::nodejs:24Patch ↗Advisory ↗
Red HatCVE-2026-59874trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)nodejs-1:22.23.1-2.module+el9.8.0+24538+3f176d52.aarch64::nodejs:22Patch ↗Advisory ↗
Red HatCVE-2026-59874trackedCVSS 7.5Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:0afd0142183f5b43b618e3db4fc16efd5fd6c5db688ad7eb22ec7a315247bf92_s390xPatch ↗Advisory ↗
Red HatCVE-2026-59874trackedCVSS 7.5Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:75b1c9d084f5cfd18aeced0d801bdff647bce79b83cfa27d3e2ba7954515ced0_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-59874trackedCVSS 7.5Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:4621e29182691b4968319d414ad7fcda8c625c73e9cd91bc9a1fc3e3c8fc438f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-59874trackedCVSS 7.5Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:097bbedcb4141e9b58d790cf7bb4c6612df8b9aefa1bc90826bb3a8176740960_s390xPatch ↗Advisory ↗
Red HatCVE-2026-59877CVSS 7.5Red Hat Developer Hub 1.10registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:08883fc7f9806289ecec95f75d4e9ee5c44a12ff372252e10398293c78b0514f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-59877CVSS 7.5Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:0afd0142183f5b43b618e3db4fc16efd5fd6c5db688ad7eb22ec7a315247bf92_s390xPatch ↗Advisory ↗
Red HatCVE-2026-59892trackedCVSS 7.5Red Hat Developer Hub 1.10registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:08883fc7f9806289ecec95f75d4e9ee5c44a12ff372252e10398293c78b0514f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-67313CVSS 7.5Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67314CVSS 7.4Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67315CVSS 5.8Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67316CVSS 3.7Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67317CVSS 5.3Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67318CVSS 5.3Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-9538CVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)perl-Archive-Tar-0:3.02-512.el10_2.2.noarchPatch ↗Advisory ↗
Red HatCVE-2026-9538CVSS 7.5Red Hat Enterprise Linux BaseOS (v. 8)perl-Archive-Tar-0:2.30-3.el8_10.noarchPatch ↗Advisory ↗
Red HatCVE-2026-9538CVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)perl-Archive-Tar-0:2.38-6.el9_8.2.noarchPatch ↗Advisory ↗
Red HatCVE-2026-18446trackedCVSS 7.5Red Hat Hardened Imagesgrafana12-4-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-56852CVSS 7.5Red Hat Hardened Imagesbuildah-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67319CVSS 6.5Red Hat Hardened Imagesgrafana12-4-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-69198CVSS 5.3Red Hat Hardened Imagesgrafana12-4-main@aarch64Patch ↗Advisory ↗