CVE-2026-53403 fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
Information published.
Categories: Microsoft
CVE-2026-53374 drm/amdgpu: zero-initialize GART table on allocation
Information published.
Categories: Microsoft
CVE-2026-53392 NFSv4/flexfiles: reject zero filehandle version count
Information published.
Categories: Microsoft
CVE-2026-63811 f2fs: read COW data with the original inode during atomic write
Information published.
Categories: Microsoft
CVE-2026-53401 fbdev: omap2: fix use-after-free in omapfb_mmap
Information published.
Categories: Microsoft
CVE-2026-63810 block: Avoid mounting the bdev pseudo-filesystem in userspace
Information published.
Categories: Microsoft
CVE-2026-63819 f2fs: fix to do sanity check on f2fs_get_node_folio_ra()
Information published.
Categories: Microsoft
CVE-2026-53402 fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
Information published.
Categories: Microsoft
CVE-2026-63853 drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring
Information published.
Categories: Microsoft
CVE-2026-53386 iio: adc: ti-ads1298: add bounds check to pga_settings index
Information published.
Categories: Microsoft
CVE-2026-63825 gcov: use atomic counter updates to fix concurrent access crashes
Information published.
Categories: Microsoft
CVE-2026-63816 f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
Information published.
Categories: Microsoft
CVE-2026-63805 crypto: nx - fix nx_crypto_ctx_exit argument
Information published.
Categories: Microsoft
CVE-2026-63815 f2fs: bound i_inline_xattr_size for non-inline-xattr inodes
Information published.
Categories: Microsoft
CVE-2026-50012 Squid: Memory corruption in cache_digest reply handling
Information published.
Categories: Microsoft
CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record
Information published.
Categories: Microsoft
CVE-2026-62309 CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS
Information published.
Categories: Microsoft
Chromium: CVE-2026-15905 Use after free in Aura
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft


