CVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi object Microsoft Security 9 Augustus 2026 om 10:43 Information published.
CVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown Microsoft Security 9 Augustus 2026 om 10:43 Information published.
CVE-2026-64604 KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode Microsoft Security 9 Augustus 2026 om 10:43 Information published.
CVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning Microsoft Security 9 Augustus 2026 om 10:43 Information published.
CVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp() Microsoft Security 9 Augustus 2026 om 10:43 Information published.
CVE-2026-64567 btrfs: reject free space cache with more entries than pages Microsoft Security 9 Augustus 2026 om 10:43 Information published.
CVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n Microsoft Security 9 Augustus 2026 om 10:43 Information published.
CVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error path Microsoft Security 9 Augustus 2026 om 10:42 Information published.
CVE-2026-64573 Bluetooth: qca: fix NVM tag length underflow in TLV parser Microsoft Security 9 Augustus 2026 om 10:42 Information published.
CVE-2026-64574 wifi: mac80211: tear down new links on vif update error path Microsoft Security 9 Augustus 2026 om 10:42 Information published.
CVE-2026-64580 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() Microsoft Security 9 Augustus 2026 om 10:42 Information published.
CVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate() Microsoft Security 9 Augustus 2026 om 10:42 Information published.
CVE-2026-64579 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert Microsoft Security 9 Augustus 2026 om 10:42 Information published.
CVE-2026-64571 wifi: p54: validate RX frame length in p54_rx_eeprom_readback() Microsoft Security 9 Augustus 2026 om 10:42 Information published.
CVE-2026-64578 ksmbd: validate compound request size before reading StructureSize2 Microsoft Security 9 Augustus 2026 om 10:42 Information published.
CVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEAR Microsoft Security 9 Augustus 2026 om 10:41 Information published.
CVE-2026-64565 Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() Microsoft Security 9 Augustus 2026 om 10:41 Information published.
CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing Microsoft Security 9 Augustus 2026 om 10:41 Information published.
CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Microsoft Security 9 Augustus 2026 om 10:41 Information published.
CVE-2026-64560 posix-cpu-timers: Prevent UAF caused by non-leader exec() race Microsoft Security 9 Augustus 2026 om 10:41 Information published.
CVE-2026-64542 ipv6: ndisc: fix NULL deref in accept_untracked_na() Microsoft Security 9 Augustus 2026 om 10:41 Information published.
CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root Microsoft Security 9 Augustus 2026 om 10:41 Information published.
CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. Microsoft Security 9 Augustus 2026 om 10:40 Information published.
CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected. Microsoft Security 9 Augustus 2026 om 10:40 Information published.
CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering Microsoft Security 9 Augustus 2026 om 10:40 Information published.
CVE-2026-63308 Helm Files.Lines Denial of Service via Empty Chart Files Microsoft Security 9 Augustus 2026 om 10:40 Information published.
CVE-2026-53910 Heap-based Buffer Overflow in GNU diffutils Microsoft Security 9 Augustus 2026 om 10:40 Information published.
CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin Microsoft Security 9 Augustus 2026 om 10:40 Information published.
CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service Microsoft Security 9 Augustus 2026 om 10:40 Information published.
CVE-2026-63263 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service Microsoft Security 9 Augustus 2026 om 10:40 Information published.