CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Vulnerabilities

August 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 1 vulnerability with exploitation detected in the wild this month. This defender-focused view covers 6,845 vulnerabilities across 17,509 returned patch records from 5 vendors. Filter the complete month, or browse the static page trail without JavaScript.

17,509all patch recordsClear filters2,377criticalShow these records1Microsoft exploitation detectedShow these records3Microsoft in the Known Exploited Vulnerabilities catalogShow these records14,331tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

My Stack only keeps records whose vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 84 of 88 · records 16,601 to 16,800 of 17,509

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2024-53426 ↗cbl2 ntopng 5.2.1-3 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableA heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.
CVE-2024-26758 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemd: Don't ignore suspended array in md_check_recovery()
CVE-2024-47661 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Avoid overflow from uint32_t to uint8_t
CVE-2024-53219 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevirtiofs: use pages instead of pointer for kernel direct IO
CVE-2024-41066 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableibmvnic: Add tx check to prevent skb leak
CVE-2024-26757 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemd: Don't ignore read-only array in md_check_recovery()
CVE-2025-38359 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailables390/mm: Fix in_atomic() handling in do_secure_storage_access()
CVE-2024-46730 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Ensure array index tg_inst won't be -1
CVE-2024-57974 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableudp: Deal with race between UDP socket address change and rehash
CVE-2023-52670 ↗cbl2 kernel 5.15.182.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablerpmsg: virtio: Free driver_override when rpmsg_remove()
CVE-2025-6516 ↗cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHDF5 H5Fint.c H5F_addr_decode_len heap-based overflow
CVE-2024-57809 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePCI: imx6: Fix suspend/resume support on i.MX6QDL
CVE-2024-35999 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb3: missing lock when picking channel
CVE-2025-22108 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebnxt_en: Mask the bd_cnt field in the TX BD properly
CVE-2024-27062 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenouveau: lock the client object tree.
CVE-2024-35887 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableax25: fix use-after-free bugs caused by ax25_ds_del_timer
CVE-2024-41082 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenvme-fabrics: use reserved tag for reg read/write command
CVE-2025-8734 ↗azl3 bison 3.8.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGNU Bison scan-code.c code_free double free
CVE-2024-40969 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablef2fs: don't set RO when shutting down f2fs
CVE-2025-8733 ↗azl3 bison 3.8.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGNU Bison obprintf.c __obstack_vprintf_internal assertion
CVE-2025-38232 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNFSD: fix race between nfsd registration and exports_proc
CVE-2024-26853 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableigc: avoid returning frame twice in XDP_REDIRECT
CVE-2025-21768 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels
CVE-2024-26830 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablei40e: Do not allow untrusted VF to remove administratively set MAC
CVE-2025-38234 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesched/rt: Fix race in push_rt_task
CVE-2025-21825 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Cancel the running bpf_timer through kworker for PREEMPT_RT
CVE-2024-40977 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mt76: mt7921s: fix potential hung tasks during chip recovery
CVE-2024-41008 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: change vm->task_info handling
CVE-2025-22109 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableax25: Remove broken autobind
CVE-2025-21870 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers
CVE-2024-50177 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: fix a UBSAN warning in DML2.1
CVE-2025-21888 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/mlx5: Fix a WARN during dereg_mr for DM type
CVE-2025-45582 ↗azl3 tar 1.35-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in wh
CVE-2024-42151 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: mark bpf_dummy_struct_ops.test_1 parameter as nullable
CVE-2025-21696 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm: clear uffd-wp PTE/PMD state on mremap()
CVE-2024-56738 ↗cbl2 grub2 2.06-14 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
CVE-2024-41045 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Defer work in bpf_timer_cancel_and_free
CVE-2024-42081 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/xe/xe_devcoredump: Check NULL before assignments
CVE-2025-21976 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefbdev: hyperv_fb: Allow graceful removal of framebuffer
CVE-2025-37907 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableaccel/ivpu: Fix locking order in ivpu_job_submit
CVE-2024-44951 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableserial: sc16is7xx: fix TX fifo corruption
CVE-2024-47736 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableerofs: handle overlapped pclusters out of crafted images properly
CVE-2024-6531 ↗cbl2 opa 0.63.0-4 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.
CVE-2024-46834 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableethtool: fail closed if we can't get max channel used in indirection tables
CVE-2024-42065 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/xe: Add a NULL check in xe_ttm_stolen_mgr_init
CVE-2024-49934 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefs/inode: Prevent dump_mapping() accessing invalid dentry.d_name.name
CVE-2024-43886 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Add null check in resource_log_pipe_topology_update
CVE-2024-38608 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5e: Fix netif state handling
CVE-2024-50613 ↗azl3 libsndfile 1.2.2-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.
CVE-2024-49926 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablercu-tasks: Fix access non-existent percpu rtpcp variable in rcu_tasks_need_gpcb()
CVE-2024-42253 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablegpio: pca953x: fix pca953x_irq_bus_sync_unlock race
CVE-2024-50614 ↗cbl2 tinyxml2 9.0.0-2 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableTinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
CVE-2024-43901 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Fix NULL pointer dereference for DTN log in DCN401
CVE-2022-48887 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/vmwgfx: Remove rcu locks from user resources
CVE-2025-31181 ↗cbl2 gnuplot 5.4.3-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGnuplot: gnuplot segmentation fault on x11_graphics
CVE-2024-42227 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Fix overlapping copy within dml_core_mode_programming
CVE-2023-1386 ↗azl3 qemu 8.2.0-17 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableQemu: 9pfs: suid/sgid bits not dropped on file write
CVE-2024-46842 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info
CVE-2024-44956 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/xe/preempt_fence: enlarge the fence critical section
CVE-2025-31179 ↗cbl2 gnuplot 5.4.3-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGnuplot: gnuplot segmentation fault on xstrftime
CVE-2024-52559 ↗azl3 kernel 6.6.82.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit()
CVE-2025-31176 ↗azl3 gnuplot 5.4.8-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGnuplot: gnuplot segmentation fault on plot3d_points
CVE-2024-42123 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: fix double free err_addr pointer warnings
CVE-2024-41085 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecxl/mem: Fix no cxl_nvd during pmem region auto-assembling
CVE-2024-49917 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Add NULL check for clk_mgr and clk_mgr->funcs in dcn30_init_hw
CVE-2019-20633 ↗azl3 patch 2.7.6-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.
CVE-2022-48673 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/smc: Fix possible access to freed memory in link clear
CVE-2024-49915 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Add NULL check for clk_mgr in dcn32_init_hw
CVE-2024-49923 ↗azl3 kernel 6.6.79.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Pass non-null to dcn20_validate_apply_pipe_split_flags
CVE-2024-43913 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenvme: apple: fix device reference counting
CVE-2024-46681 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepktgen: use cpus_read_lock() in pg_net_init()
CVE-2024-46705 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/xe: reset mmio mappings with devm
CVE-2024-46701 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibfs: fix infinite directory reads for offset dir
CVE-2024-41014 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablexfs: add bounds checking to xlog_recover_process_data
CVE-2024-44970 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5e: SHAMPO, Fix invalid WQ linked list unlink
CVE-2024-49898 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Check null-initialized variables
CVE-2024-42158 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailables390/pkey: Use kfree_sensitive() to fix Coccinelle warnings
CVE-2024-49911 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Add NULL check for function pointer in dcn20_set_output_transfer_func
CVE-2024-46698 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevideo/aperture: optionally match the device in sysfb_disable()
CVE-2019-11254 ↗azl3 packer 1.9.5-11 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableKubernetes API Server denial of service vulnerability from malicious YAML payloads
CVE-2024-46808 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Add missing NULL pointer check within dpcd_extend_address_range
CVE-2024-41023 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesched/deadline: Fix task_struct reference leak
CVE-2024-49909 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Add NULL check for function pointer in dcn32_set_output_transfer_func
CVE-2023-52920 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: support non-r10 register spill/fill to/from stack in precision tracking
CVE-2024-43824 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePCI: endpoint: pci-epf-test: Make use of cached 'epc_features' in pci_epf_test_core_init()
CVE-2025-38333 ↗azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablef2fs: fix to bail out in get_new_segment()
CVE-2025-38097 ↗azl3 kernel 6.6.92.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableespintcp: remove encap socket caching to avoid reference leak
CVE-2025-38127 ↗azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableice: fix Tx scheduler error handling in XDP callback
CVE-2025-38192 ↗azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: clear the dst when changing skb protocol
CVE-2025-38334 ↗azl3 kernel 6.6.92.2-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablex86/sgx: Prevent attempts to reclaim poisoned pages
CVE-2025-4432 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRing: some aes functions may panic when overflow checking is enabled in ring
CVE-2024-49569 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenvme-rdma: unquiesce admin_q before destroy it
CVE-2025-22057 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: decrease cached dst counters in dst_release
CVE-2025-37800 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledriver core: fix potential NULL pointer dereference in dev_uevent()
CVE-2025-37801 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablespi: spi-imx: Add check for spi_imx_setupxfer()
CVE-2025-37852 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create()
CVE-2025-37853 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdkfd: debugfs hang_hws skip GPU with MES
CVE-2025-37878 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableperf/core: Fix WARN_ON(!ctx) in __free_event() for partial init
CVE-2025-37884 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Fix deadlock between rcu_tasks_trace and event_mutex.
CVE-2024-50615 ↗azl3 tinyxml2 9.0.0-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableTinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
CVE-2025-21947 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: fix type confusion via race condition when using ipc_msg_send_request
CVE-2025-21969 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd
CVE-2025-21792 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableax25: Fix refcount leak caused by setting SO_BINDTODEVICE sockopt
CVE-2025-21667 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableiomap: avoid avoid truncating 64-bit offset to 32 bits
CVE-2025-21673 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb: client: fix double free of TCP_Server_Info::hostname
CVE-2024-47141 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepinmux: Use sequential access to access desc->pinmux data
CVE-2024-47809 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledlm: fix possible lkb_resource null dereference
CVE-2024-48875 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: don't take dev_replace rwsem on task already holding it
CVE-2024-56665 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf,perf: Fix invalid prog_array access in perf_event_detach_bpf_prog
CVE-2024-56703 ↗azl3 kernel 6.6.78.1-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipv6: Fix soft lockups in fib6_select_path under high next hop churn
CVE-2024-56719 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: stmmac: fix TSO DMA API usage causing oops
CVE-2024-50248 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablentfs3: Add bounds checking to mi_enum_attr()
CVE-2024-50256 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nf_reject_ipv6: fix potential crash in nf_send_reset6()
CVE-2024-50284 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: Fix the missing xa_store error check
CVE-2024-50285 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: check outstanding simultaneous SMB operations
CVE-2024-53079 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm/thp: fix deferred split unqueue naming and locking
CVE-2024-53091 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Add sk_is_inet and IS_ICSK check in tls_sw_has_ctx_tx/rx
CVE-2024-53093 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenvme-multipath: defer partition scanning
CVE-2024-53094 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES
CVE-2024-53100 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenvme: tcp: avoid race between queue_lock lock and destroy
CVE-2024-1543 ↗azl3 mariadb 10.11.6-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableAES T-Table sub-cache-line leakage
CVE-2024-1544 ↗azl3 mariadb 10.11.6-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableECDSA nonce bias caused by truncation
CVE-2024-5288 ↗azl3 mariadb 10.11.6-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableSafe-error attack on TLS 1.3 Protocol
CVE-2024-49978 ↗azl3 kernel 6.6.57.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablegso: fix udp gso fraglist segmentation after pull from frag_list
CVE-2024-49987 ↗azl3 kernel 6.6.57.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpftool: Fix undefined behavior in qsort(NULL 0 ...)
CVE-2024-49988 ↗azl3 kernel 6.6.57.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: add refcnt to ksmbd_conn struct
CVE-2024-47678 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableicmp: change the order of rate limits
CVE-2024-47683 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Skip Recompute DSC Params if no Stream on Link
CVE-2024-47704 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Check link_res->hpo_dp_link_enc before using it
CVE-2024-47728 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Zero former ARG_PTR_TO_{LONGINT} args in case of error
CVE-2024-49859 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablef2fs: fix to check atomic_file in f2fs ioctl interfaces
CVE-2024-49905 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Add null check for 'afb' in amdgpu_dm_plane_handle_cursor_update (v2)
CVE-2024-49912 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Handle null 'stream_status' in 'planes_changed_for_existing_stream'
CVE-2024-46678 ↗azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebonding: change ipsec_lock from spin lock to mutex
CVE-2024-46762 ↗azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablexen: privcmd: Fix possible access to a freed kirqfd instance
CVE-2024-46765 ↗azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableice: protect XDP configuration with a mutex
CVE-2024-46803 ↗azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdkfd: Check debug trap enable before write dbg_ev_file
CVE-2024-27005 ↗azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableinterconnect: Don't access req_list while it's being manipulated
CVE-2024-35794 ↗azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm-raid: really frozen sync_thread during suspend
CVE-2024-35808 ↗azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemd/dm-raid: don't call md_reap_sync_thread() directly
CVE-2024-42067 ↗azl3 kernel 6.6.43.1-7 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Take return from set_memory_rox() into account with bpf_jit_binary_lock_ro()
CVE-2024-1151 ↗azl3 hyperv-daemons 6.6.22.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableKernel: stack overflow problem in open vswitch kernel module leading to dos
CVE-2024-36009 ↗azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableax25: Fix netdev refcount issue
CVE-2021-20227 ↗sqlite-3.34.1-1.cm1.x86_64.rpm on CBL Mariner 1.0 x64ModerateOut-of-bandNot availableMicrosoft rating unavailableA flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
CVE-2020-15358 ↗cm1 mysql 8.0.26-1 on CBL Mariner 1.0ModerateOut-of-bandNot availableMicrosoft rating unavailableIn SQLite before 3.32.3 select.c mishandles query-flattener optimization leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
CVE-2026-80628 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailableALSA: seq: oss: Serialize readq reset state with q->lock
CVE-2026-80598 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailablentfs3: fix out-of-bounds read in decompress_lznt
CVE-2026-80707 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band1%Microsoft rating unavailablecan: j1939: transport: j1939_session_fresh_new(): initialize receive buffer
CVE-2026-80634 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band1%Microsoft rating unavailablenetfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag
CVE-2026-80670 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band1%Microsoft rating unavailableperf tools: Use perf_env__get_cpu_topology() in machine__resolve()
CVE-2026-80585 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band1%Microsoft rating unavailablemptcp: fastopen: only mark MPTFO subflows with SYN data
CVE-2026-80580 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailablefbdev: bound mode sysfs output to the sysfs buffer
CVE-2026-80547 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailables390/vfio_ccw: Implement a crw lock
CVE-2026-80540 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailabledrm/amdgpu: Fix UVD decode image min size calculation
CVE-2026-80565 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailablecrypto: qce - fix error path in devm_qce_register_algs
CVE-2026-80583 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailableASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
CVE-2026-74711 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailablehwmon: (pmbus) Fix type confusion in notification logic
CVE-2026-74733 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailablegpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock
CVE-2026-74603 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailableptp: ocp: Fix board ID over-read
CVE-2026-74655 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailableserial: qcom-geni: fix TX DMA buffer flush
CVE-2026-74678 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band1%Microsoft rating unavailablenet: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
CVE-2026-74567 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailablekeys: fix out-of-bounds read in keyring_get_key_chunk()
CVE-2026-72495 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailableRDMA/bnxt_re: Avoid repeated requests to allocate WC pages
CVE-2026-72438 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0LowOut-of-band1%Microsoft rating unavailablemd/raid10: fix writes_pending and barrier reference leaks on discard failures
CVE-2026-74268 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band1%Microsoft rating unavailabletcp: clear sock_ops cb flags before force-closing a child socket
CVE-2026-72315 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailablesmb: client: fix busy dentry warning on unmount after DIO
CVE-2026-74338 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailablebpf: Reject sleepable BPF_LSM_CGROUP programs at load time
CVE-2026-74475 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band1%Microsoft rating unavailablevxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-74456 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailablecan: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error
CVE-2026-74544 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailablenet/sched: cls_u32: validate offshift to prevent shift-out-of-bounds
CVE-2026-74317 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailableixgbe: do not configure xps for XDP queues
CVE-2026-74495 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band1%Microsoft rating unavailableigbvf: Fix leak in TX DMA error cleanup
CVE-2026-74564 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailablenetfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
CVE-2026-74579 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailablenetfilter: nft_payload: fix mask build for partial field offload

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
SuseCVE-2026-38752trackedCVSS 3.3SUSE Linux Enterprise High Performance Computing 12 SP5busybox-0:1.35.0-10.9.1.x86_64no patch linkAdvisory ↗
SuseCVE-2026-38755trackedCVSS 3.3SUSE Linux Enterprise High Performance Computing 12 SP5busybox-0:1.35.0-10.9.1.x86_64no patch linkAdvisory ↗
SuseCVE-2026-9944trackedCVSS 3.1openSUSE Leap 16.0chromedriver-0:148.0.7778.215-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-34181trackedCVSS 3.1openSUSE Tumbleweedlibopenssl-3-devel-0:3.5.3-8.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-38752trackedCVSS 3.3openSUSE Tumbleweedbusybox-0:1.38.0-2.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-38755trackedCVSS 3.3openSUSE Tumbleweedbusybox-0:1.38.0-2.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-5773trackedCVSS 3.7SUSE Linux Micro 6.1curl-0:8.14.1-slfo.1.1_9.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-5773trackedCVSS 3.7SUSE Linux Micro 6.0curl-0:8.14.1-8.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-63869trackedCVSS 3.3SUSE Linux Enterprise Live Patching 15 SP7kernel-livepatch-6_4_0-150700_7_72-rt-0:1-150700.1.5.1.x86_64no patch linkAdvisory ↗
SuseCVE-2026-64330trackedCVSS 3.5SUSE Linux Enterprise Live Patching 15 SP7kernel-livepatch-6_4_0-150700_7_72-rt-0:1-150700.1.5.1.x86_64no patch linkAdvisory ↗
SuseCVE-2026-5773trackedCVSS 3.7Open Enterprise Server 25.4curl-0:8.14.1-150700.7.23.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-6276trackedCVSS 3.7Open Enterprise Server 25.4curl-0:8.14.1-150700.7.23.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-63869trackedCVSS 3.3Open Enterprise Server 25.4kernel-64kb-0:6.4.0-150700.53.78.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-64330trackedCVSS 3.5Open Enterprise Server 25.4kernel-64kb-0:6.4.0-150700.53.78.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-75803trackedCVSS 3.7Red Hat Hardened Imagesbootupd-0:0.2.36-3.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-75803trackedCVSS 3.7Red Hat Hardened Imagesopenssl3-0:3.5.8-0.1.hum1@srcPatch ↗Advisory ↗
Red HatCVE-2026-75803trackedCVSS 3.7Red Hat Hardened Imagesopenssl-0:3.5.8-0.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-74983trackedCVSS 3.4Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.14.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-74983trackedCVSS 3.4Red Hat Enterprise Linux AppStream (v. 8)firefox-0:140.14.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-74983trackedCVSS 3.4Red Hat Enterprise Linux AppStream (v. 10)firefox-0:140.14.0-1.el10_2.aarch64Patch ↗Advisory ↗
SuseCVE-2026-46068trackedCVSS 3.3SUSE Linux Micro 6.1kernel-devel-rt-0:6.4.0-51.1.noarchno patch linkAdvisory ↗
SuseCVE-2026-46068trackedCVSS 3.3SUSE Linux Micro 6.1kernel-default-0:6.4.0-51.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-46068trackedCVSS 3.3SUSE Linux Micro 6.0kernel-devel-rt-0:6.4.0-51.1.noarchno patch linkAdvisory ↗
SuseCVE-2026-46068trackedCVSS 3.3SUSE Linux Micro 6.0kernel-default-0:6.4.0-51.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-52981trackedCVSS 3.7SUSE Linux Micro 6.1kernel-devel-rt-0:6.4.0-51.1.noarchno patch linkAdvisory ↗
SuseCVE-2026-52981trackedCVSS 3.7SUSE Linux Micro 6.1kernel-default-0:6.4.0-51.1.aarch64no patch linkAdvisory ↗

Glossary