Patch Day month
August 2026 vulnerabilities
A server-rendered hunting trail for August 2026: 1,834 returned patch records across 4 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.
1,834all patches
57critical
0exploitation detected
1in CISA KEV
293tracked here
Microsoft 1,222Red Hat 581Cisco 30Android 1
Page 6 of 10 · records 1,001–1,200 of 1,834
Microsoft Security Response Center
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-64405 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()
CVE-2026-64388 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—smb/client: fix chown/chgrp with SMB3 POSIX Extensions
CVE-2026-64471 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—Bluetooth: btusb: fix use-after-free on registration failure
CVE-2026-64346 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—usb: gadget: udc: Fix use-after-free in gadget_match_driver
CVE-2026-64482 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—ALSA: gus: check snd_ctl_new1() return value
CVE-2026-64301 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—regulator: scmi: fix of_node refcount leak in scmi_regulator_probe()
CVE-2026-64324 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—udf: validate free block extents against the partition length
CVE-2026-64350 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
CVE-2026-64266 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—fuse: re-lock request before returning from fuse_ref_folio()
CVE-2026-64246 ↗2026-07-26azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-band—power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
CVE-2026-64403 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—Bluetooth: L2CAP: validate option length before reading conf opt value
CVE-2026-66033 ↗2026-07-26azl3 libssh 0.10.6-8 on Azure Linux 3.0ImportantOut-of-band0%libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation
CVE-2026-64271 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—Input: touchwin - reset the packet index on every complete packet
CVE-2026-66035 ↗2026-07-26azl3 nmap 7.95-4 on Azure Linux 3.0ImportantOut-of-band0%libssh2 Heap Buffer Overflow via ETM Cipher Negotiation
CVE-2026-64488 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—ALSA: aoa: check snd_ctl_new1() return value
CVE-2026-64286 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
CVE-2026-66032 ↗2026-07-26azl3 nmap 7.95-4 on Azure Linux 3.0ImportantOut-of-band0%libssh2 Double-Free Heap Corruption via sftp_open()
CVE-2026-64377 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—cpufreq: qcom-cpufreq-hw: Fix possible double free
CVE-2026-64272 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—Input: mms114 - fix touch indexing for MMS134S and MMS136
CVE-2026-66034 ↗2026-07-26azl3 libssh2 1.11.1-4 on Azure Linux 3.0ImportantOut-of-band0%libssh2 Heap Out-of-Bounds Read via publickey subsystem
CVE-2026-64344 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—USB: idmouse: fix use-after-free on disconnect race
CVE-2026-64254 ↗2026-07-26azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-band—NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
CVE-2026-64351 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
CVE-2026-64252 ↗2026-07-26azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-band—MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
CVE-2026-64441 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()
CVE-2026-64429 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—gpio: eic-sprd: use raw_spinlock_t in the irq startup path
CVE-2026-64250 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—LoongArch: Report dying CPU to RCU in stop_this_cpu()
CVE-2026-64455 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—USB: chaoskey: Fix slab-use-after-free in chaoskey_release()
CVE-2026-64241 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—gpio: rockchip: teardown bugs and resource leaks
CVE-2026-64382 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—smb: client: fix double-free in SMB2_open() replay
CVE-2026-64248 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—MIPS: smp: report dying CPU to RCU in stop_this_cpu()
CVE-2026-64298 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
CVE-2026-64433 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete
CVE-2026-64247 ↗2026-07-26azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—KVM: x86: hyper-v: Bound the bank index when querying sparse banks
CVE-2026-64396 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation
CVE-2026-64249 ↗2026-07-26azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-band—fpga: region: fix use-after-free in child_regions_with_firmware()
CVE-2026-64330 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
CVE-2026-64255 ↗2026-07-26azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ImportantOut-of-band—wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
CVE-2026-64334 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—USB: serial: digi_acceleport: fix hard lockup on disconnect
CVE-2026-64212 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it
CVE-2026-64529 ↗2026-07-26azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band0%crypto: qat - remove unused character device and IOCTLs
CVE-2026-64313 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—crypto: ecc - Fix carry overflow in vli multiplication
CVE-2026-64480 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—ALSA: ice1712: check snd_ctl_new1() return value
CVE-2026-64402 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()
CVE-2026-64210 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—net/mlx5e: xsk: Fix unlocked writing to ICOSQ
CVE-2026-64378 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()
CVE-2026-64379 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—smb: client: mask server-provided mode to 07777 in modefromsid
CVE-2026-64213 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—hwmon: (lm90) Add lock protection to lm90_alert
CVE-2026-64442 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()
CVE-2026-64303 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
CVE-2026-64294 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band—mm: do file ownership checks with the proper mount idmap
CVE-2026-47143 ↗2026-07-25azl3 rust 1.90.0-9 on Azure Linux 3.0ModerateOut-of-band—Capstone has a NULL Pointer Dereference with 3DNow! opcodes
CVE-2026-16615 ↗2026-07-25azl3 rest 0.9.0-1 on Azure Linux 3.0ModerateOut-of-band—Librest: weak random number generation in pkce implementation
CVE-2026-47059 ↗2026-07-25azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0LowOut-of-band—Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java san
CVE-2026-46917 ↗2026-07-25azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-band—Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1
CVE-2026-47063 ↗2026-07-25azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-band—Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients ru
CVE-2026-60147 ↗2026-07-25azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-band—Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web
CVE-2026-59850 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-band—Libssh: libssh: use-after-free via data callbacks on closed channels
CVE-2026-59844 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-band—Libssh: libssh: denial of service via oversized sftp read length
CVE-2026-59846 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0LowOut-of-band—Libssh: libssh: information disclosure via proxycommand %r username expansion
CVE-2026-59845 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-band—Libssh: libssh: denial of service via unchecked proxycommand fork() failure
CVE-2026-59847 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-band—Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification
CVE-2026-59843 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-band—Libssh: libssh: denial of service via zero advertised channel packet size
CVE-2026-59848 ↗2026-07-25azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-band—Libssh: libssh: denial of service via sftp responses with unknown request ids
CVE-2026-16517 ↗2026-07-25azl3 libarchive 3.7.7-6 on Azure Linux 3.0LowOut-of-band—Libarchive: libarchive: signed integer overflow in archive_write_zip_header
CVE-2026-46600 ↗2026-07-25azl3 golang 1.25.12-1 on Azure Linux 3.0ModerateOut-of-band—Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
CVE-2026-12617 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-band0%Record ordering based unexpected exit with CNAME or DNAME
CVE-2026-11622 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-band1%Potential memory usage beyond configured limits
CVE-2026-11721 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-band0%Cache poisoning possible with label count discrepancy, RRSIG, and wildcards
CVE-2026-11331 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-band0%Potential wildcard CNAME RPZ policy bypass
CVE-2026-11605 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-band1%Unnecessary validation of DNSSEC signed records
CVE-2026-13321 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ImportantOut-of-band0%DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
CVE-2026-10723 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-band—Incorrect acceptance of NSEC3 records
CVE-2026-13204 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-band1%Unexpected exit in certain situations with NSEC and NSEC3 both present
CVE-2026-10822 ↗2026-07-25azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-band—Key Record using PRIVATEDNS algorithm may lead to unexpected exit
CVE-2026-56852 ↗2026-07-25azl3 azurelinux-image-tools 1.5.0-1 on Azure Linux 3.0ImportantOut-of-band—Infinite loop on invalid input in golang.org/x/text
CVE-2026-56392 ↗2026-07-25azl3 coreutils 9.4-7 on Azure Linux 3.0LowOut-of-band—Heap-based Buffer Overflow in GNU coreutils
CVE-2026-44210 ↗2026-07-25azl3 kata-containers-cc 3.15.0.aks0-15 on Azure Linux 3.0ModerateOut-of-band—Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations
CVE-2025-5278 ↗2026-07-25azl3 coreutils 9.4-6 on Azure Linux 3.0ModerateOut-of-band—Coreutils: heap buffer under-read in gnu coreutils sort via key specification
CVE-2026-42770 ↗2026-07-21azl3 openssl 3.3.7-3 on Azure Linux 3.0LowOut-of-band—FFC-DH Peer Validation Uses Attacker-Supplied q
CVE-2026-34181 ↗2026-06-13azl3 kata-containers 3.32.0.kata0-1 on Azure Linux 3.0ImportantOut-of-band—PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys
CVE-2026-34180 ↗2026-06-13azl3 shim-unsigned-aarch64 16.1-2 on Azure Linux 3.0ImportantOut-of-band—Heap Buffer Over-read in ASN.1 Content Parsing
CVE-2026-42769 ↗2026-06-13azl3 nodejs 24.14.1-3 on Azure Linux 3.0ModerateOut-of-band—Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
CVE-2026-42767 ↗2026-06-13azl3 kata-containers 3.32.0.kata0-1 on Azure Linux 3.0ModerateOut-of-band—NULL Pointer Dereference in CRMF EncryptedValue Decryption
CVE-2026-42766 ↗2026-06-13azl3 kata-containers 3.32.0.kata0-1 on Azure Linux 3.0ModerateOut-of-band—Possible NULL Dereference in Password-Based CMS Decryption
CVE-2026-42764 ↗2026-06-13azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0ImportantOut-of-band—NULL Pointer Dereference in QUIC Server Initial Packet Handling
CVE-2026-45446 ↗2026-06-13azl3 kata-containers 3.32.0.kata0-1 on Azure Linux 3.0ModerateOut-of-band—Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
CVE-2026-9076 ↗2026-06-13azl3 kata-containers 3.32.0.kata0-1 on Azure Linux 3.0ImportantOut-of-band—Out-of-Bounds Read in CMS Password-Based Decryption
CVE-2026-42768 ↗2026-06-13azl3 openssl 3.3.7-1 on Azure Linux 3.0LowOut-of-band—Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
CVE-2026-7383 ↗2026-06-13azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0ImportantOut-of-band—Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion
CVE-2026-34182 ↗2026-06-13azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0CriticalOut-of-band—CMS AuthEnvelopedData Processing May Accept Forged Messages
CVE-2026-34183 ↗2026-06-13azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0ImportantOut-of-band—Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
CVE-2026-45447 ↗2026-06-13azl3 openssl 3.3.7-3 on Azure Linux 3.0ImportantOut-of-band—Heap Use-After-Free in the PKCS7_verify() Function
CVE-2026-45445 ↗2026-06-13azl3 openssl 3.3.7-1 on Azure Linux 3.0ImportantOut-of-band—AES-OCB IV Ignored on EVP_Cipher() Path
CVE-2026-44839 ↗2026-05-31azl3 rabbitmq-server 3.13.7-6 on Azure Linux 3.0ModerateOut-of-band—RabbitMQ: Unsanitized vhost names allow for XSS in management UI
CVE-2026-48864 ↗2026-05-31azl3 libsolv 0.7.28-3 on Azure Linux 3.0ImportantOut-of-band—Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
CVE-2026-9804 ↗2026-05-31azl3 kubevirt 1.7.1-8 on Azure Linux 3.0ImportantOut-of-band—Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read
CVE-2026-46181 ↗2026-05-29azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()
CVE-2026-46130 ↗2026-05-29azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—dm-verity-fec: fix reading parity bytes split across blocks (take 3)
CVE-2026-46147 ↗2026-05-29azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ModerateOut-of-band—KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu()
CVE-2026-46241 ↗2026-05-29azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—spi: mpc52xx: fix use-after-free on registration failure
CVE-2026-46153 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—8021q: delete cleared egress QoS mappings
CVE-2026-46175 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—f2fs: fix fsck inconsistency caused by FGGC of node block
CVE-2026-46171 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—riscv: kvm: fix vector context allocation leak
CVE-2026-46200 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—spi: mpc52xx: fix controller deregistration
CVE-2026-46076 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1
CVE-2026-46090 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ALSA: aloop: Fix peer runtime UAF during format-change stop
CVE-2026-45963 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—ASoC: nau8821: Cancel delayed work on component remove
CVE-2026-45934 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—btrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation
CVE-2026-45861 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—gfs2: Fix slab-use-after-free in qd_put
CVE-2026-46014 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—KVM: SVM: Add missing save/restore handling of LBR MSRs
CVE-2026-46044 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-band—ipmi:ssif: Clean up kthread on errors
CVE-2026-45949 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—hwrng: core - use RCU and work_struct to fix race condition
CVE-2026-46032 ↗2026-05-28azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—KVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT
CVE-2026-45859 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation
CVE-2026-46017 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—mm: fix deferred split queue races during migration
CVE-2026-45897 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: nft_counter: serialize reset with spinlock
CVE-2026-45943 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—erofs: fix inline data read failure for ztailpacking pclusters
CVE-2026-45893 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-band—apparmor: Fix & Optimize table creation from possibly unaligned memory
CVE-2026-45940 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net: stmmac: fix oops when split header is enabled
CVE-2026-45961 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—gfs2: fix memory leaks in gfs2_fill_super error path
CVE-2026-45932 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—bpf: Fix tcx/netkit detach permissions when prog fd isn't given
CVE-2026-45944 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—iommu/vt-d: Clear Present bit before tearing down context entry
CVE-2026-45855 ↗2026-05-28azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—ata: libata-scsi: avoid Non-NCQ command starvation
CVE-2026-46066 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ceph: fix num_ops off-by-one when crypto allocation fails
CVE-2026-45894 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—iommu/vt-d: Clear Present bit before tearing down PASID entry
CVE-2026-45901 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: nf_tables: revert commit_mutex usage in reset path
CVE-2026-46059 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN
CVE-2026-46071 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12
CVE-2026-45973 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—RDMA/mlx5: Fix UMR hang in LAG error state unload
CVE-2026-45917 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—ipvs: do not keep dest_dst if dev is going down
CVE-2026-45877 ↗2026-05-28azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ModerateOut-of-band—HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients
CVE-2026-39824 ↗2026-05-27azl3 application-gateway-kubernetes-ingress 1.7.7-3 on Azure Linux 3.0CriticalOut-of-band—Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows
CVE-2026-43029 ↗2026-05-25azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—mptcp: fix soft lockup in mptcp_recvmsg()
CVE-2025-68251 ↗2026-05-25azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—erofs: avoid infinite loops due to corrupted subpage compact indexes
CVE-2026-43414 ↗2026-05-25azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—scsi: qla2xxx: Completely fix fcport double free
CVE-2025-38675 ↗2026-05-25azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—xfrm: state: initialize state_ptrs earlier in xfrm_state_find
CVE-2025-21752 ↗2026-05-25azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-band—btrfs: don't use btrfs_set_item_key_safe on RAID stripe-extents
CVE-2026-43465 ↗2026-05-22azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band—net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ
CVE-2026-43464 ↗2026-05-22azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—net/mlx5e: RX, Fix XDP multi-buf frag counting for legacy RQ
CVE-2026-43970 ↗2026-05-21azl3 rabbitmq-server 3.13.7-3 on Azure Linux 3.0ModerateOut-of-band—Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame
CVE-2026-43969 ↗2026-05-15azl3 rabbitmq-server 3.13.7-3 on Azure Linux 3.0LowOut-of-band—Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
CVE-2026-44307 ↗2026-05-14azl3 python-mako 1.2.4-3 on Azure Linux 3.0ImportantOut-of-band—Mako: Path traversal via backslash URI on Windows in TemplateLookup
CVE-2026-43249 ↗2026-05-13azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-band—9p/xen: protect xen_9pfs_front_free against concurrent calls
CVE-2026-31767 ↗2026-05-13azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode
CVE-2026-43308 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref()
CVE-2026-43294 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels
CVE-2026-43299 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure()
CVE-2026-43298 ↗2026-05-09azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-band—drm/amdgpu: Skip vcn poison irq release on VF
CVE-2026-43456 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—bonding: fix type confusion in bond_setup_by_slave()
CVE-2026-43344 ↗2026-05-09azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—perf/x86/intel/uncore: Fix die ID init and look up bugs
CVE-2026-43416 ↗2026-05-09azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—powerpc, perf: Check that current->mm is alive before getting user callchain
CVE-2026-43309 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—md raid: fix hang when stopping arrays with metadata through dm-raid
CVE-2026-43318 ↗2026-05-09azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-band—drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify
CVE-2026-43338 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—btrfs: reserve enough transaction items for qgroup ioctls
CVE-2026-6383 ↗2026-05-07cbl2 kubevirt 0.59.0-38 on CBL Mariner 2.0ModerateOut-of-band—Kubevirt: kubevirt: unauthorized subresource access due to improper rbac evaluation
CVE-2026-33857 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-band—Apache HTTP Server: Off-by-one OOB reads in AJP getter functions
CVE-2026-29168 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-band—Apache HTTP Server: mod_md unrestricted OCSP response
CVE-2026-29169 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-band—Apache HTTP Server: mod_dav_lock indirect lock crash
CVE-2026-33007 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-band—Apache HTTP Server: mod_authn_socache crash
CVE-2026-33006 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-band—Apache HTTP Server: mod_auth_digest timing attack
CVE-2026-24072 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-band—Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr
CVE-2026-34032 ↗2026-05-07azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-band—Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)
CVE-2026-34059 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-band—Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()
CVE-2026-23918 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-band—Apache HTTP Server: http2: double free and possible RCE on early reset
CVE-2026-33523 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-band—Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line
CVE-2026-3832 ↗2026-05-07cbl2 gnutls 3.7.11-6 on CBL Mariner 2.0LowOut-of-band—Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response
CVE-2026-3833 ↗2026-05-07cbl2 gnutls 3.7.11-6 on CBL Mariner 2.0ModerateOut-of-band—Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison
CVE-2026-43083 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—net: ioam6: fix OOB and missing lock
CVE-2026-43199 ↗2026-05-07azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-band—net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query
CVE-2026-43101 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data()
CVE-2026-43119 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: hci_sync: annotate data-races around hdev->req_status
CVE-2026-43216 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—net: Drop the lock in skb_may_tx_timestamp()
CVE-2026-43250 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—usb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke()
CVE-2026-43107 ↗2026-05-07azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—xfrm: account XFRMA_IF_ID in aevent size calculation
CVE-2025-71289 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—fs/ntfs3: handle attr_set_size() errors when truncating files
CVE-2026-43258 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-band—alpha: fix user-space corruption during memory compaction
CVE-2026-43244 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—kcm: fix zero-frag skb in frag_list on partial sendmsg error
CVE-2026-43153 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—xfs: remove xfs_attr_leaf_hasname
CVE-2026-43118 ↗2026-05-07azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—btrfs: fix zero size inode with non-zero size after log replay
CVE-2025-71273 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()
CVE-2026-43197 ↗2026-05-07azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band—netconsole: avoid OOB reads, msg is not nul-terminated
CVE-2025-71285 ↗2026-05-07azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band—net: qrtr: Drop the MHI auto_queue feature for IPCR DL channels
CVE-2026-43172 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—wifi: iwlwifi: fix 22000 series SMEM parsing
CVE-2026-43234 ↗2026-05-07azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—team: avoid NETDEV_CHANGEMTU event when unregistering slave
CVE-2026-43198 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—tcp: fix potential race in tcp_v6_syn_recv_sock()
CVE-2026-43161 ↗2026-05-07azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band—iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode
CVE-2026-43127 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—ntfs3: fix circular locking dependency in run_unpack_ex
CVE-2026-43131 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-band—drm/amd/pm: Fix null pointer dereference issue
CVE-2026-43248 ↗2026-05-07azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-band—vhost: move vdpa group bound check to vhost_vdpa
CVE-2026-43125 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-band—dlm: validate length in dlm_search_rsb_tree
CVE-2026-30656 ↗2026-05-03azl3 fio 3.37-3 on Azure Linux 3.0ImportantOut-of-band—A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup() on a NULL value when the option is specified without an argument. This results in a segmentation fault and process crash.
CVE-2026-6846 ↗2026-05-03azl3 gdb 13.2-7 on Azure Linux 3.0ImportantOut-of-band—Binutils: binutils: arbitrary code execution via malformed xcoff object file processing
CVE-2026-6845 ↗2026-05-03cbl2 binutils 2.37-20 on CBL Mariner 2.0ModerateOut-of-band—Binutils: binutils: denial of service via crafted elf file
CVE-2026-43009 ↗2026-05-02azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-band—bpf: Fix incorrect pruning due to atomic fetch precision tracking
CVE-2026-31771 ↗2026-05-02azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-band—Bluetooth: hci_event: move wake reason storage into validated event handlers
CVE-2026-43042 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-band—mpls: add seqcount to protect the platform_label{,s} pair
CVE-2026-43022 ↗2026-05-02azl3 kernel 6.6.141.1-1 on Azure Linux 3.0N/AOut-of-band—Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists
CVE-2026-43049 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-band—HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure
CVE-2026-43036 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-band—net: use skb_header_pointer() for TCPv4 GSO frag_off check
The next page could not be added in place. The ordinary page link remains available; try it again to navigate normally.