Patch Day month
August 2026 vulnerabilities
A server-rendered hunting trail for August 2026: 1,834 returned patch records across 4 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.
1,834all patches
57critical
0exploitation detected
1in CISA KEV
293tracked here
Microsoft 1,222Red Hat 581Cisco 30Android 1
Page 8 of 10 · records 1,401–1,600 of 1,834
Microsoft Security Response Center
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2024-40989 ↗2025-10-08cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—KVM: arm64: Disassociate vcpus from redistributor region on teardown
CVE-2022-48816 ↗2025-10-08cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—SUNRPC: lock against ->sock changing during sysfs read
CVE-2022-50502 ↗2025-10-06azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—mm: /proc/pid/smaps_rollup: fix no vma's null-deref
CVE-2025-39940 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—dm-stripe: fix a possible integer overflow
CVE-2025-39932 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—smb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work)
CVE-2024-39508 ↗2025-10-05cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—io_uring/io-wq: Use set_bit() and test_bit() at worker->flags
CVE-2024-38620 ↗2025-10-05cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-band—Bluetooth: HCI: Remove HCI_AMP support
CVE-2025-55554 ↗2025-10-05cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-band—pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
CVE-2025-55551 ↗2025-10-05azl3 pytorch 2.2.2-7 on Azure Linux 3.0ImportantOut-of-band—An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
CVE-2024-36922 ↗2025-10-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—wifi: iwlwifi: read txq->read_ptr under lock
CVE-2024-36920 ↗2025-10-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0LowOut-of-band—scsi: mpi3mr: Avoid memcpy field-spanning write WARNING
CVE-2025-39905 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—net: phylink: add lock for serializing concurrent pl->phydev writes with resolver
CVE-2025-39901 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—i40e: remove read access to debugfs files
CVE-2025-39927 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—ceph: fix race condition validating r_parent before applying state
CVE-2024-36911 ↗2025-10-02cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—hv_netvsc: Don't free decrypted memory
CVE-2024-36909 ↗2025-10-02cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—Drivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted
CVE-2025-46150 ↗2025-10-02azl3 pytorch 2.2.2-7 on Azure Linux 3.0ModerateOut-of-band—In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
CVE-2025-46149 ↗2025-10-02cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-band—In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
CVE-2025-46153 ↗2025-10-02azl3 pytorch 2.2.2-7 on Azure Linux 3.0ModerateOut-of-band—PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True.
CVE-2025-11083 ↗2025-10-02azl3 binutils 2.41-7 on Azure Linux 3.0ModerateOut-of-band—GNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflow
CVE-2022-48744 ↗2025-10-02cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-band—net/mlx5e: Avoid field-overflowing memcpy()
CVE-2024-42861 ↗2025-10-01cbl2 linuxptp 3.1.1-1 on CBL Mariner 2.0ImportantOut-of-band—An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function
CVE-2024-45773 ↗2025-10-01azl3 thrift 0.15.0-5 on Azure Linux 3.0ImportantOut-of-band—A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2024.09.09.00.
CVE-2024-49214 ↗2025-10-01cbl2 haproxy 2.4.24-1 on CBL Mariner 2.0ModerateOut-of-band—QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a spoofed IP address. This can bypass the IP allow/block list functionality.
CVE-2023-50230 ↗2025-10-01azl3 bluez 5.63-6 on Azure Linux 3.0ImportantOut-of-band—BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-5366 ↗2025-10-01cbl2 openvswitch 2.17.9-1 on CBL Mariner 2.0ImportantOut-of-band—Openvswitch don't match packets on nd_target field
CVE-2022-43410 ↗2025-10-01azl3 mercurial 6.5.1-1 on Azure Linux 3.0ModerateOut-of-band—Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.
CVE-2022-42969 ↗2025-10-01azl3 python-py 1.11.0-1 on Azure Linux 3.0ImportantOut-of-band—The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. Note: This has been disputed by multiple third parties as not being reproduceable and they argue this is not a valid vulnerability.
CVE-2022-40896 ↗2025-10-01azl3 python-pygments 2.4.2-1 on Azure Linux 3.0ModerateOut-of-band—A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
CVE-2019-9192 ↗2025-10-01azl3 smartmontools 7.4-1 on Azure Linux 3.0ImportantOut-of-band—In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion
CVE-2018-20225 ↗2025-10-01azl3 python-pip 24.2-2 on Azure Linux 3.0ImportantOut-of-band—An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely
CVE-2016-2568 ↗2025-10-01azl3 polkit 123-1 on Azure Linux 3.0ImportantOut-of-band—pkexec, when used with --user nonpriv, allows local users to escape to the parent session
CVE-2007-3205 ↗2025-10-01cbl2 php 8.1.32-1 on CBL Mariner 2.0ModerateOut-of-band—The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin.
CVE-2025-10911 ↗2025-09-29cbl2 libxslt 1.1.34-8 on CBL Mariner 2.0ModerateOut-of-band—Libxslt: use-after-free with key data stored cross-rvt
CVE-2024-57945 ↗2025-09-28cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—riscv: mm: Fix the out of bound issue of vmemmap address
CVE-2024-57893 ↗2025-09-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—ALSA: seq: oss: Fix races at processing SysEx messages
CVE-2024-57843 ↗2025-09-27cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—virtio-net: fix overflow inside virtnet_rq_alloc
CVE-2024-35971 ↗2025-09-27cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—net: ks8851: Handle softirqs at the end of IRQ thread to fix hang
CVE-2024-35951 ↗2025-09-27cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—drm/panfrost: Fix the error path in panfrost_mmu_map_fault_addr()
CVE-2024-35939 ↗2025-09-27cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-band—dma-direct: Leak pages on dma_set_decrypted() failure
CVE-2024-35839 ↗2025-09-27cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—netfilter: bridge: replace physindev with physinif in nf_bridge_info
CVE-2023-52732 ↗2025-09-27cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-band—ceph: blocklist the kclient when receiving corrupted snap trace
CVE-2023-52676 ↗2025-09-27cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—bpf: Guard stack limits against 32bit overflow
CVE-2025-39789 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—crypto: x86/aegis - Add missing error checks
CVE-2025-39747 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—drm/msm: Add error handling for krealloc in metadata setup
CVE-2025-39746 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—wifi: ath10k: shutdown driver when hardware is unreliable
CVE-2025-39762 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—drm/amd/display: add null check
CVE-2025-39754 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—mm/smaps: fix race between smaps_hugetlb_range and migration
CVE-2025-39779 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—btrfs: subpage: keep TOWRITE tag until folio is cleaned
CVE-2025-9901 ↗2025-09-07azl3 libsoup 3.4.4-9 on Azure Linux 3.0ModerateOut-of-band—Libsoup: improper handling of http vary header in libsoup caching
CVE-2025-39716 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—parisc: Revise __get_user() to probe user read access
CVE-2025-38734 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—net/smc: fix UAF on smcsk after smc_listen_out()
CVE-2025-39707 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—drm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities
CVE-2025-39706 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—drm/amdkfd: Destroy KFD debugfs after destroy KFD wq
CVE-2025-39677 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—net/sched: Fix backlog accounting in qdisc_dequeue_internal
CVE-2025-39705 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—drm/amd/display: fix a Null pointer dereference vulnerability
CVE-2025-38704 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—rcu/nocb: Fix possible invalid rdp's->nocb_cb_kthread pointer access
CVE-2025-38717 ↗2025-09-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—net: kcm: Fix race condition in kcm_unattach()
CVE-2025-38722 ↗2025-09-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—habanalabs: fix UAF in export_dmabuf()
CVE-2025-38728 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band—smb3: fix for slab out of bounds on mount to ksmbd
CVE-2025-38679 ↗2025-09-06azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—media: venus: Fix OOB read due to missing payload bound check
CVE-2025-38705 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—drm/amd/pm: fix null pointer access
CVE-2025-38709 ↗2025-09-06azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—loop: Avoid updating block size under exclusive owner
CVE-2024-36921 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-band—wifi: iwlwifi: mvm: guard against invalid STA ID on removal
CVE-2025-21635 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-band—rds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy
CVE-2025-37842 ↗2025-09-04azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-band—spi: fsl-qspi: use devm function instead of driver remove
CVE-2025-38584 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band—padata: Fix pd UAF once and for all
CVE-2025-46394 ↗2025-09-04azl3 busybox 1.36.1-14 on Azure Linux 3.0LowOut-of-band—In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
CVE-2025-21693 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band—mm: zswap: properly synchronize freeing resources during CPU hotunplug
CVE-2024-58251 ↗2025-09-04azl3 busybox 1.36.1-17 on Azure Linux 3.0LowOut-of-band—In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
CVE-2024-38628 ↗2025-09-04cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0N/AOut-of-band—usb: gadget: u_audio: Fix race condition use of controls after free during gadget unbind.
CVE-2024-57857 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—RDMA/siw: Remove direct link to net_device
CVE-2025-38611 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—vmci: Prevent the dispatching of uninitialized payloads
CVE-2025-45768 ↗2025-09-04azl3 python-jwt 2.8.0-1 on Azure Linux 3.0ModerateOut-of-band—pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).
CVE-2024-7598 ↗2025-09-04azl3 kubernetes 1.30.10-9 on Azure Linux 3.0LowOut-of-band—Network restriction bypass via race condition during namespace termination
CVE-2025-38585 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band—staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int()
CVE-2025-38590 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—net/mlx5e: Remove skb secpath if xfrm state is not found
CVE-2024-36024 ↗2025-09-04azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—drm/amd/display: Disable idle reallow as part of command/gpint execution
CVE-2024-26914 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—drm/amd/display: fix incorrect mpc_combine array size
CVE-2025-38591 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—bpf: Reject narrower access to pointer ctx fields
CVE-2025-21786 ↗2025-09-04azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-band—workqueue: Put the pwq after detaching the rescuer from the pool
CVE-2025-38272 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—net: dsa: b53: do not enable EEE on bcm63xx
CVE-2025-38096 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—wifi: iwlwifi: don't warn when if there is a FW error
CVE-2025-38029 ↗2025-09-04azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-band—kasan: avoid sleepable page allocation from atomic context
CVE-2025-38520 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—drm/amdkfd: Don't call mmput from MMU notifier callback
CVE-2025-38269 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—btrfs: exit after state insertion failure at btrfs_convert_extent_bit()
CVE-2025-8197 ↗2025-09-04cbl2 libsoup 3.0.4-9 on CBL Mariner 2.0ModerateOut-of-band—Rejected reason: Maintainers have included reasons at https://gitlab.gnome.org/GNOME/libsoup/-/issues/465
CVE-2025-40325 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—md/raid10: wait barrier before returning discard request with REQ_NOWAIT
CVE-2025-38279 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—bpf: Do not include stack ptr register in precision backtracking bookkeeping
CVE-2025-7069 ↗2025-09-04cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0LowOut-of-band—HDF5 H5FSsection.c H5FS__sect_link_size heap-based overflow
CVE-2024-58006 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—PCI: dwc: ep: Prevent changing BAR size/flags in pci_epc_set_bar()
CVE-2025-38303 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: eir: Fix possible crashes on eir_create_adv_data
CVE-2025-38140 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—dm: limit swapping tables for devices with zone write plugs
CVE-2025-37882 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—usb: xhci: Fix isochronous Ring Underrun/Overrun event handling
CVE-2025-21949 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-band—LoongArch: Set hugetlb mmap base address aligned with pmd size
CVE-2025-38162 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band—netfilter: nft_set_pipapo: prevent overflow in lookup table allocation
CVE-2025-37856 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—btrfs: harden block_group::bg_list against list_del() races
CVE-2025-21927 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-band—nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()
CVE-2025-2309 ↗2025-09-04cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0ModerateOut-of-band—HDF5 Type Conversion Logic H5T__bit_copy heap-based overflow
CVE-2025-38524 ↗2025-09-04cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—rxrpc: Fix recv-recv race of completed call
CVE-2025-2308 ↗2025-09-04azl3 hdf5 1.14.4.3-1 on Azure Linux 3.0ModerateOut-of-band—HDF5 Scale-Offset Filter H5Z__scaleoffset_decompress_one_byte heap-based overflow
CVE-2025-37807 ↗2025-09-04azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-band—bpf: Fix kmemleak warning for percpu hashmap
CVE-2025-38064 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—virtio: break and reset virtio devices on device_shutdown()
CVE-2024-42317 ↗2025-09-04azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—mm/huge_memory: avoid PMD-size page cache if needed
CVE-2025-38041 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band—clk: sunxi-ng: h616: Reparent GPU clock during frequency changes
CVE-2025-38678 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—netfilter: nf_tables: reject duplicate device on updates
CVE-2024-47794 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—bpf: Prevent tailcall infinite loop caused by freplace
CVE-2024-24856 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-band—NULL pointer deference in acpi_db_convert_to_package of Linux acpi module
CVE-2024-57898 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—wifi: cfg80211: clear link ID from bitmap during link delete after clean up
CVE-2024-26759 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—mm/swap: fix race when skipping swapcache
CVE-2025-1180 ↗2025-09-04cbl2 gdb 11.2-6 on CBL Mariner 2.0LowOut-of-band—GNU Binutils ld elf-eh-frame.c _bfd_elf_write_section_eh_frame memory corruption
CVE-2024-41067 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—btrfs: scrub: handle RST lookup error correctly
CVE-2025-22115 ↗2025-09-04azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-band—btrfs: fix block group refcount race in btrfs_create_pending_block_groups()
CVE-2025-37745 ↗2025-09-04azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-band—PM: hibernate: Avoid deadlock in hibernate_compressor_param_set()
CVE-2025-23167 ↗2025-09-04azl3 nodejs 20.14.0-9 on Azure Linux 3.0ModerateOut-of-band—A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`.
This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests.
The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination.
Impact:
* This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.
CVE-2025-21885 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—RDMA/bnxt_re: Fix the page details for the srq created by kernel consumers
CVE-2024-57804 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—scsi: mpi3mr: Fix corrupt config pages PHY state is switched in sysfs
CVE-2023-52939 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-band—mm: memcg: fix NULL pointer in mem_cgroup_track_foreign_dirty_slowpath()
CVE-2025-21892 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—RDMA/mlx5: Fix the recovery flow of the UMR QP
CVE-2025-55199 ↗2025-09-04cbl2 helm 3.14.2-7 on CBL Mariner 2.0ModerateOut-of-band—Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion
CVE-2025-1150 ↗2025-09-04azl3 binutils 2.41-7 on Azure Linux 3.0LowOut-of-band—GNU Binutils ld libbfd.c bfd_malloc memory leak
CVE-2025-21985 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—drm/amd/display: Fix out-of-bound accesses
CVE-2024-26756 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—md: Don't register sync_thread for reshape directly
CVE-2025-21732 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—RDMA/mlx5: Fix a race for an ODP MR which leads to CQE with error
CVE-2025-22121 ↗2025-09-04azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-band—ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all()
CVE-2025-4802 ↗2025-09-04cbl2 glibc 2.35-7 on CBL Mariner 2.0ImportantOut-of-band—Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
CVE-2022-49531 ↗2025-09-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-band—loop: implement ->free_disk
CVE-2024-41932 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—sched: fix warning in sched_setaffinity
CVE-2025-21891 ↗2025-09-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0N/AOut-of-band—ipvlan: ensure network headers are in skb linear part
CVE-2024-44939 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—jfs: fix null ptr deref in dtInsertEntry
CVE-2022-49750 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-band—cpufreq: CPPC: Add u64 casts to avoid overflowing
CVE-2025-38250 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band—Bluetooth: hci_core: Fix use-after-free in vhci_flush()
CVE-2023-53002 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-band—drm/i915: Fix a memory leak with reused mmap_offset
CVE-2025-52194 ↗2025-09-03cbl2 libsndfile 1.0.31-3 on CBL Mariner 2.0ImportantOut-of-band—A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, leading to memory corruption and potential code execution.
CVE-2024-57875 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—block: RCU protect disk->conv_zones_bitmap
CVE-2025-6856 ↗2025-09-03cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0ModerateOut-of-band—HDF5 H5FL.c H5FL__reg_gc_list use after free
CVE-2025-38380 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—i2c/designware: Fix an initialization issue
CVE-2025-29477 ↗2025-09-03cbl2 fluent-bit 3.0.6-2 on CBL Mariner 2.0LowOut-of-band—An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.
CVE-2023-53008 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-band—cifs: fix potential memory leaks in session setup
CVE-2025-38248 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band—bridge: mcast: Fix use-after-free during router port configuration
CVE-2024-56591 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—Bluetooth: hci_conn: Use disable_delayed_work_sync
CVE-2024-26706 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—parisc: Fix random data corruption from exception handler
CVE-2022-49742 ↗2025-09-03cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0N/AOut-of-band—f2fs: initialize locks earlier in f2fs_fill_super()
CVE-2025-6817 ↗2025-09-03cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0ModerateOut-of-band—HDF5 H5Centry.c H5C__load_entry resource consumption
CVE-2024-57976 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—btrfs: do proper folio cleanup when cow_file_range() failed
CVE-2025-37826 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—scsi: ufs: core: Add NULL check in ufshcd_mcq_compl_pending_transfer()
CVE-2025-21961 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-band—eth: bnxt: fix truesize for mb-xdp-pass case
CVE-2025-38264 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band—nvme-tcp: sanitize request list handling
CVE-2025-37877 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—iommu: Clear iommu-dma ops on cleanup
CVE-2024-58089 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—btrfs: fix double accounting race when btrfs_run_delalloc_range() failed
CVE-2024-39478 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-band—crypto: starfive - Do not free stack buffer
CVE-2024-35865 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—smb: client: fix potential UAF in smb2_is_valid_oplock_break()
CVE-2025-38643 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—wifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac()
CVE-2024-46754 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—bpf: Remove tst_run from lwt_seg6local_prog_ops.
CVE-2023-52624 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-band—drm/amd/display: Wake DMCUB before executing GPINT commands
CVE-2025-21801 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—net: ravb: Fix missing rtnl lock in suspend/resume path
CVE-2024-43819 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—kvm: s390: Reject memory region operations for ucontrol VMs
CVE-2024-56712 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-band—udmabuf: fix memory leak on last export_udmabuf() error path
CVE-2024-35931 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—drm/amdgpu: Skip do PCI error slot reset during RAS recovery
CVE-2024-50009 ↗2025-09-03azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-band—cpufreq: amd-pstate: add check for cpufreq_cpu_get's return value
CVE-2024-42118 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band—drm/amd/display: Do not return negative stream id for array
CVE-2024-43872 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—RDMA/hns: Fix soft lockup under heavy CEQE load
CVE-2025-29478 ↗2025-09-03cbl2 fluent-bit 3.0.6-2 on CBL Mariner 2.0LowOut-of-band—An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.
CVE-2025-38449 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band—drm/gem: Acquire references on GEM handles for framebuffers
CVE-2025-37920 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—xsk: Fix race condition in AF_XDP generic RX path
CVE-2024-50217 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-band—btrfs: fix use-after-free of block device file in __btrfs_free_extra_devids()
CVE-2024-40999 ↗2025-09-03azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—net: ena: Add validation for completion descriptors consistency
CVE-2024-49897 ↗2025-09-03azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-band—drm/amd/display: Check phantom_stream before it is used
CVE-2025-37870 ↗2025-09-03azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/amd/display: prevent hang on link training fail
CVE-2023-51580 ↗2025-09-03azl3 bluez 5.63-6 on Azure Linux 3.0ModerateOut-of-band—BlueZ Audio Profile AVRCP avrcp_parse_attribute_list Out-Of-Bounds Read Information Disclosure Vulnerability
CVE-2024-49937 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-band—wifi: cfg80211: Set correct chandef when starting CAC
CVE-2025-37834 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—mm/vmscan: don't try to reclaim hwpoison folio
CVE-2023-51589 ↗2025-09-03cbl2 bluez 5.63-6 on CBL Mariner 2.0ModerateOut-of-band—BlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability
CVE-2024-46727 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—drm/amd/display: Add otg_master NULL check within resource_log_pipe_topology_update
CVE-2024-53426 ↗2025-09-03cbl2 ntopng 5.2.1-3 on CBL Mariner 2.0ModerateOut-of-band—A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.
CVE-2024-26758 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—md: Don't ignore suspended array in md_check_recovery()
CVE-2024-49939 ↗2025-09-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0N/AOut-of-band—wifi: rtw89: avoid to add interface to list twice when SER
CVE-2024-47661 ↗2025-09-03azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-band—drm/amd/display: Avoid overflow from uint32_t to uint8_t
CVE-2024-53114 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-band—x86/CPU/AMD: Clear virtualized VMLOAD/VMSAVE on Zen4 client
CVE-2024-53219 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—virtiofs: use pages instead of pointer for kernel direct IO
CVE-2025-38636 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—rv: Use strings in da monitors tracepoints
CVE-2024-41066 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—ibmvnic: Add tx check to prevent skb leak
CVE-2024-26757 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—md: Don't ignore read-only array in md_check_recovery()
CVE-2025-38359 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—s390/mm: Fix in_atomic() handling in do_secure_storage_access()
CVE-2024-46730 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—drm/amd/display: Ensure array index tg_inst won't be -1
CVE-2024-42134 ↗2025-09-03azl3 kernel 6.6.112.1-2 on Azure Linux 3.0N/AOut-of-band—virtio-pci: Check if is_avq is NULL
CVE-2024-49920 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-band—drm/amd/display: Check null pointers before multiple uses
CVE-2023-45927 ↗2025-09-03azl3 slang 2.3.3-1 on Azure Linux 3.0ModerateOut-of-band—S-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf().
CVE-2024-57974 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—udp: Deal with race between UDP socket address change and rehash
CVE-2023-52670 ↗2025-09-03cbl2 kernel 5.15.182.1-1 on CBL Mariner 2.0ModerateOut-of-band—rpmsg: virtio: Free driver_override when rpmsg_remove()
CVE-2025-6516 ↗2025-09-03cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0ModerateOut-of-band—HDF5 H5Fint.c H5F_addr_decode_len heap-based overflow
CVE-2024-57809 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-band—PCI: imx6: Fix suspend/resume support on i.MX6QDL
CVE-2024-35999 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—smb3: missing lock when picking channel
CVE-2025-22108 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—bnxt_en: Mask the bd_cnt field in the TX BD properly
CVE-2024-27062 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—nouveau: lock the client object tree.
CVE-2024-53133 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band—drm/amd/display: Handle dml allocation failure to avoid crash
CVE-2024-35887 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band—ax25: fix use-after-free bugs caused by ax25_ds_del_timer
CVE-2023-51592 ↗2025-09-03cbl2 bluez 5.63-6ModerateOut-of-band—BlueZ Audio Profile AVRCP parse_media_folder Out-Of-Bounds Read Information Disclosure Vulnerability
CVE-2024-49925 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-band—fbdev: efifb: Register sysfs groups through driver core
CVE-2024-41082 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band—nvme-fabrics: use reserved tag for reg read/write command
The next page could not be added in place. The ordinary page link remains available; try it again to navigate normally.