CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Vulnerabilities

August 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 1 vulnerability with exploitation detected in the wild this month. This defender-focused view covers 6,845 vulnerabilities across 17,509 returned patch records from 5 vendors. Filter the complete month, or browse the static page trail without JavaScript.

17,509all patch recordsClear filters2,377criticalShow these records1Microsoft exploitation detectedShow these records3Microsoft in the Known Exploited Vulnerabilities catalogShow these records14,331tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

My Stack only keeps records whose vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 83 of 88 · records 16,401 to 16,600 of 17,509

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-71183 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: always detect conflicting inodes when logging inode refs
CVE-2026-23371 ↗azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting
CVE-2026-23333 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nft_set_rbtree: validate open interval overlap
CVE-2026-3099 ↗azl3 libsoup 3.4.4-12 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLibsoup: libsoup: authentication bypass via digest authentication replay attack
CVE-2026-4438 ↗azl3 glibc 2.38-19 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablegethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
CVE-2026-23276 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: add xmit recursion limit to tunnel xmit functions
CVE-2026-23207 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablespi: tegra210-quad: Protect curr_xfer check in IRQ handler
CVE-2026-3644 ↗azl3 python3 3.12.9-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableIncomplete control character validation in http.cookies
CVE-2026-4224 ↗azl3 python3 3.12.9-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableStack overflow parsing XML with deeply nested DTD content models
CVE-2026-23247 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletcp: secure_seq: add back ports to TS offset
CVE-2025-71202 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableiommu/sva: invalidate stale IOTLB entries for kernel address space
CVE-2026-4105 ↗cbl2 systemd 250.3-23 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableSystemd: systemd: privilege escalation via improper access control in registermachine d-bus method
CVE-2025-69647 ↗cbl2 binutils 2.37-20 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.
CVE-2025-69649 ↗azl3 binutils 2.41-10 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.
CVE-2025-69645 ↗azl3 binutils 2.41-11 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBinutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.
CVE-2025-69646 ↗azl3 binutils 2.41-10 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBinutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.
CVE-2026-2297 ↗cbl2 python3 3.9.19-19 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableSourcelessFileLoader does not use io.open_code()
CVE-2025-71161 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm-verity: disable recursive forward error correction
CVE-2025-71150 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: Fix refcount leak when invalid session is found on session lookup
CVE-2025-71227 ↗azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mac80211: don't WARN for connections on invalid channels
CVE-2025-39770 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM
CVE-2025-71095 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: stmmac: fix the crash issue for zero copy XDP_TX action
CVE-2025-68972 ↗cbl2 gnupg2 2.4.0-3 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableIn GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.
CVE-2025-59529 ↗cbl2 avahi 0.8-4 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesimple protocol server ignores accepts unlimited connections and logs failures without limit
CVE-2025-68384 ↗azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableElasticsearch Allocation of Resources Without Limits or Throttling
CVE-2025-68390 ↗azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableElasticsearch Allocation of Resources Without Limits or Throttling
CVE-2025-68146 ↗azl3 python-filelock 3.14.0-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefilelock has TOCTOU race condition that allows symlink attacks during lock file creation
CVE-2025-37959 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Scrub packet on bpf_redirect_peer
CVE-2025-68209 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemlx5: Fix default values in create CQ
CVE-2025-40355 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesysfs: check visibility before changing group attribute ownership
CVE-2025-68230 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: fix gpu page fault after hibernation on PF passthrough
CVE-2025-68201 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: remove two invalid BUG_ON()s
CVE-2025-68223 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/radeon: delete radeon_fence_process in is_signaled, no deadlock
CVE-2025-37731 ↗azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableElasticsearch Improper Authentication
CVE-2024-58241 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: hci_core: Disable works on hci_unregister_dev
CVE-2022-50393 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: SDMA update use unlocked iterator
CVE-2023-53429 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: don't check PageError in __extent_writepage
CVE-2022-50407 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecrypto: hisilicon/qm - increase the memory of local variables
CVE-2025-40339 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: fix nullptr err of vm_handle_moved
CVE-2023-53749 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablex86: fix clear_user_rep_good() exception handling annotation
CVE-2025-40289 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM
CVE-2025-61727 ↗cbl2 golang 1.18.8-10 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableImproper application of excluded DNS name constraints when verifying wildcard names in crypto/x509
CVE-2025-40247 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/msm: Fix pgtable prealloc error path
CVE-2023-53178 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm: fix zswap writeback race condition
CVE-2022-50350 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: target: iscsi: Fix a race condition between login_work and the login thread
CVE-2025-64713 ↗cbl2 fluent-bit 3.0.6-4 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableWebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode
CVE-2025-64704 ↗azl3 fluent-bit 3.1.9-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableWebAssembly Micro Runtime vulnerable to a segmentation fault in v128.store instruction
CVE-2025-54770 ↗cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGrub2: use-after-free in net_set_vlan
CVE-2025-54771 ↗cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGrub2: use-after-free in grub_file_close()
CVE-2022-50233 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: eir: Fix using strlen with hdev->{dev_name,short_name}
CVE-2022-50167 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: fix potential 32-bit overflow when accessing ARRAY map element
CVE-2022-50073 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null
CVE-2025-2998 ↗azl3 pytorch 2.2.2-7 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePyTorch torch.nn.utils.rnn.pad_packed_sequence memory corruption
CVE-2025-37820 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablexen-netfront: handle NULL returned by xdp_convert_buff_to_frame()
CVE-2023-53093 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletracing: Do not let histogram values have some modifiers
CVE-2023-53074 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: fix ttm_bo calltrace warning in psp_hw_fini
CVE-2023-53068 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: usb: lan78xx: Limit packet length to skb->len
CVE-2023-53042 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Do not set DRR on pipe Commit
CVE-2022-49932 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableKVM: VMX: Do _all_ initialization before exposing /dev/kvm to userspace
CVE-2025-40180 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox cleanup loop
CVE-2011-10034 ↗azl3 autogen 5.18.16-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableIRAI AUTOMGEN <= 8.0.0.7 Use-After-Free Remote DoS
CVE-2025-40146 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableblk-mq: fix potential deadlock while nr_requests grown
CVE-2025-64436 ↗cbl2 kubevirt 0.59.0-30 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableKubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
CVE-2025-22124 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemd/md-bitmap: fix wrong bitmap_limit for clustermd when write sb
CVE-2025-22090 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablex86/mm/pat: Fix VM_PAT handling when fork() fails in copy_page_range()
CVE-2025-21899 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletracing: Fix bad hist from corrupting named_triggers list
CVE-2025-21907 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm: memory-failure: update ttu flag inside unmap_poisoned_folio
CVE-2024-38595 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5: Fix peer devlink set for SF representor devlink port
CVE-2025-21881 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableuprobes: Reject the shared zeropage in uprobe_write_opcode()
CVE-2025-21872 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableefi: Don't map the entire mokvar table to determine its size
CVE-2023-53010 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebnxt: Do not read past the end of test names
CVE-2023-53009 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdkfd: Add sync after creating vram bo
CVE-2025-58186 ↗cbl2 gcc 11.2.0-8 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLack of limit when parsing cookies can cause memory exhaustion in net/http
CVE-2025-58183 ↗cbl2 cri-o 1.22.3-16 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableUnbounded allocation when parsing GNU sparse map in archive/tar
CVE-2025-21838 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableusb: gadget: core: flush gadget workqueue after device removal
CVE-2025-21831 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1
CVE-2025-21738 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableata: libata-sff: Ensure that we cannot write outside the allocated buffer
CVE-2023-52981 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/i915: Fix request ref counting during error capture & debugfs dump
CVE-2024-58053 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablerxrpc: Fix handling of received connection abort
CVE-2024-46716 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor
CVE-2025-21712 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemd/md-bitmap: Synchronize bitmap_get_stats() with bitmap lifetime
CVE-2025-62813 ↗cbl2 lz4 1.9.4-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in lib/lz4frame.c mishandles NULL checks.
CVE-2022-49562 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableKVM: x86: Use __try_cmpxchg_user() to update guest PTE A/D bits
CVE-2024-38564 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE
CVE-2024-57899 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mac80211: fix mbss changed flags corruption on 32 bit systems
CVE-2025-21629 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets
CVE-2024-56709 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableio_uring: check if iowq is killed before queuing
CVE-2024-49568 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg
CVE-2020-8130 ↗azl3 ruby 3.3.5-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableThere is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.
CVE-2025-37727 ↗azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableElasticsearch Insertion of sensitive information in log file
CVE-2025-11413 ↗cbl2 binutils 2.37-16 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGNU Binutils Linker elflink.c elf_link_add_object_symbols out-of-bounds
CVE-2024-46717 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5e: SHAMPO, Fix incorrect page release
CVE-2024-41079 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenvmet: always initialize cqe.result
CVE-2024-56641 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/smc: initialize close_work early to avoid warning
CVE-2024-40989 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableKVM: arm64: Disassociate vcpus from redistributor region on teardown
CVE-2022-48816 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableSUNRPC: lock against ->sock changing during sysfs read
CVE-2022-50502 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm: /proc/pid/smaps_rollup: fix no vma's null-deref
CVE-2025-39940 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm-stripe: fix a possible integer overflow
CVE-2025-39932 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work)
CVE-2024-39508 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableio_uring/io-wq: Use set_bit() and test_bit() at worker->flags
CVE-2025-55554 ↗cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
CVE-2024-36922 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: iwlwifi: read txq->read_ptr under lock
CVE-2025-39927 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableceph: fix race condition validating r_parent before applying state
CVE-2024-36911 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablehv_netvsc: Don't free decrypted memory
CVE-2024-36909 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableDrivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted
CVE-2025-46150 ↗azl3 pytorch 2.2.2-7 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableIn PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
CVE-2025-46149 ↗cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableIn PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
CVE-2025-46153 ↗azl3 pytorch 2.2.2-7 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True.
CVE-2025-11083 ↗azl3 binutils 2.41-7 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflow
CVE-2024-49214 ↗cbl2 haproxy 2.4.24-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableQUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a spoofed IP address. This can bypass the IP allow/block list functionality.
CVE-2022-43410 ↗azl3 mercurial 6.5.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableJenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.
CVE-2022-40896 ↗azl3 python-pygments 2.4.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableA ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
CVE-2007-3205 ↗cbl2 php 8.1.32-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableThe parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin.
CVE-2025-10911 ↗cbl2 libxslt 1.1.34-8 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLibxslt: use-after-free with key data stored cross-rvt
CVE-2024-57945 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableriscv: mm: Fix the out of bound issue of vmemmap address
CVE-2024-57893 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: seq: oss: Fix races at processing SysEx messages
CVE-2024-57843 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevirtio-net: fix overflow inside virtnet_rq_alloc
CVE-2024-35971 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: ks8851: Handle softirqs at the end of IRQ thread to fix hang
CVE-2024-35951 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/panfrost: Fix the error path in panfrost_mmu_map_fault_addr()
CVE-2024-35939 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledma-direct: Leak pages on dma_set_decrypted() failure
CVE-2024-35839 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: bridge: replace physindev with physinif in nf_bridge_info
CVE-2023-52732 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableceph: blocklist the kclient when receiving corrupted snap trace
CVE-2023-52676 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Guard stack limits against 32bit overflow
CVE-2025-39789 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecrypto: x86/aegis - Add missing error checks
CVE-2025-39747 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/msm: Add error handling for krealloc in metadata setup
CVE-2025-39762 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: add null check
CVE-2025-39754 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm/smaps: fix race between smaps_hugetlb_range and migration
CVE-2025-39779 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: subpage: keep TOWRITE tag until folio is cleaned
CVE-2025-9901 ↗azl3 libsoup 3.4.4-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLibsoup: improper handling of http vary header in libsoup caching
CVE-2025-39716 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableparisc: Revise __get_user() to probe user read access
CVE-2025-39707 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities
CVE-2025-39706 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdkfd: Destroy KFD debugfs after destroy KFD wq
CVE-2025-39677 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: Fix backlog accounting in qdisc_dequeue_internal
CVE-2025-39705 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: fix a Null pointer dereference vulnerability
CVE-2025-38717 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: kcm: Fix race condition in kcm_unattach()
CVE-2025-38705 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/pm: fix null pointer access
CVE-2025-38709 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableloop: Avoid updating block size under exclusive owner
CVE-2025-37842 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablespi: fsl-qspi: use devm function instead of driver remove
CVE-2024-57857 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/siw: Remove direct link to net_device
CVE-2025-38611 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevmci: Prevent the dispatching of uninitialized payloads
CVE-2025-38590 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5e: Remove skb secpath if xfrm state is not found
CVE-2024-36024 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Disable idle reallow as part of command/gpint execution
CVE-2025-38591 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Reject narrower access to pointer ctx fields
CVE-2025-38272 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: dsa: b53: do not enable EEE on bcm63xx
CVE-2025-38029 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablekasan: avoid sleepable page allocation from atomic context
CVE-2025-38520 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdkfd: Don't call mmput from MMU notifier callback
CVE-2025-38269 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: exit after state insertion failure at btrfs_convert_extent_bit()
CVE-2025-8197 ↗cbl2 libsoup 3.0.4-9 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRejected reason: Maintainers have included reasons at https://gitlab.gnome.org/GNOME/libsoup/-/issues/465
CVE-2025-40325 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemd/raid10: wait barrier before returning discard request with REQ_NOWAIT
CVE-2024-58006 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePCI: dwc: ep: Prevent changing BAR size/flags in pci_epc_set_bar()
CVE-2025-38303 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: eir: Fix possible crashes on eir_create_adv_data
CVE-2025-37856 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: harden block_group::bg_list against list_del() races
CVE-2025-2309 ↗cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHDF5 Type Conversion Logic H5T__bit_copy heap-based overflow
CVE-2025-38524 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablerxrpc: Fix recv-recv race of completed call
CVE-2025-2308 ↗azl3 hdf5 1.14.4.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHDF5 Scale-Offset Filter H5Z__scaleoffset_decompress_one_byte heap-based overflow
CVE-2025-38064 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevirtio: break and reset virtio devices on device_shutdown()
CVE-2024-42317 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm/huge_memory: avoid PMD-size page cache if needed
CVE-2025-38678 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nf_tables: reject duplicate device on updates
CVE-2024-47794 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Prevent tailcall infinite loop caused by freplace
CVE-2024-57898 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: cfg80211: clear link ID from bitmap during link delete after clean up
CVE-2024-26759 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm/swap: fix race when skipping swapcache
CVE-2024-41067 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: scrub: handle RST lookup error correctly
CVE-2025-22115 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: fix block group refcount race in btrfs_create_pending_block_groups()
CVE-2025-37745 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePM: hibernate: Avoid deadlock in hibernate_compressor_param_set()
CVE-2025-23167 ↗azl3 nodejs 20.14.0-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableA flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.
CVE-2025-21885 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/bnxt_re: Fix the page details for the srq created by kernel consumers
CVE-2024-57804 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: mpi3mr: Fix corrupt config pages PHY state is switched in sysfs
CVE-2025-21892 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/mlx5: Fix the recovery flow of the UMR QP
CVE-2025-55199 ↗cbl2 helm 3.14.2-7 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHelm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion
CVE-2024-26756 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemd: Don't register sync_thread for reshape directly
CVE-2025-21732 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/mlx5: Fix a race for an ODP MR which leads to CQE with error
CVE-2022-49531 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableloop: implement ->free_disk
CVE-2024-41932 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesched: fix warning in sched_setaffinity
CVE-2024-44939 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablejfs: fix null ptr deref in dtInsertEntry
CVE-2024-57875 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableblock: RCU protect disk->conv_zones_bitmap
CVE-2025-6856 ↗cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHDF5 H5FL.c H5FL__reg_gc_list use after free
CVE-2025-38380 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablei2c/designware: Fix an initialization issue
CVE-2024-56591 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: hci_conn: Use disable_delayed_work_sync
CVE-2024-26706 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableparisc: Fix random data corruption from exception handler
CVE-2025-6817 ↗cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHDF5 H5Centry.c H5C__load_entry resource consumption
CVE-2024-57976 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: do proper folio cleanup when cow_file_range() failed
CVE-2025-37826 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: ufs: core: Add NULL check in ufshcd_mcq_compl_pending_transfer()
CVE-2025-37877 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableiommu: Clear iommu-dma ops on cleanup
CVE-2024-58089 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: fix double accounting race when btrfs_run_delalloc_range() failed
CVE-2024-35865 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb: client: fix potential UAF in smb2_is_valid_oplock_break()
CVE-2025-38643 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac()
CVE-2024-46754 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Remove tst_run from lwt_seg6local_prog_ops.
CVE-2025-21801 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: ravb: Fix missing rtnl lock in suspend/resume path
CVE-2024-43819 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablekvm: s390: Reject memory region operations for ucontrol VMs
CVE-2024-35931 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: Skip do PCI error slot reset during RAS recovery
CVE-2024-50009 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecpufreq: amd-pstate: add check for cpufreq_cpu_get's return value
CVE-2024-43872 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/hns: Fix soft lockup under heavy CEQE load
CVE-2025-37920 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablexsk: Fix race condition in AF_XDP generic RX path
CVE-2024-40999 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: ena: Add validation for completion descriptors consistency
CVE-2024-49897 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Check phantom_stream before it is used
CVE-2025-37870 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: prevent hang on link training fail
CVE-2023-51580 ↗azl3 bluez 5.63-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBlueZ Audio Profile AVRCP avrcp_parse_attribute_list Out-Of-Bounds Read Information Disclosure Vulnerability
CVE-2025-37834 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm/vmscan: don't try to reclaim hwpoison folio
CVE-2023-51589 ↗cbl2 bluez 5.63-6 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability
CVE-2024-46727 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Add otg_master NULL check within resource_log_pipe_topology_update

Glossary