MSRC Reports
61 subscribers
2.99K links
Microsoft Security Response Center Reports
(Unofficial).

Reports usually come in bursts, because that's just how Microsoft releases them.
Download Telegram
CVE-2025-68817 ksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-68817
CVE-2025-68819 media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg()

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-68819
CVE-2025-71067 ntfs: set dummy blocksize to read boot_block when mounting

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-71067
CVE-2025-71066 net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-71066
CVE-2025-68808 media: vidtv: initialize local pointers upon transfer of memory ownership

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-68808
CVE-2025-68781 usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-68781
CVE-2025-68823 ublk: fix deadlock when reading partition table

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-68823
CVE-2026-22702 virtualenv Has TOCTOU Vulnerabilities in Directory Creation

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-22702
CVE-2026-21860 Werkzeug safe_join() allows Windows special device names with compound extensions

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21860
CVE-2025-14819 OpenSSL partial chain store policy bypass

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-14819
CVE-2025-15079 libssh global known_hosts override

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-15079
CVE-2025-14524 bearer token leak on cross-protocol redirect

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-14524
CVE-2025-15224 libssh key passphrase bypass without agent set

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-15224
CVE-2025-14017 broken TLS options for threaded LDAPS

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-14017
CVE-2025-13034 No QUIC certificate pinning with GnuTLS

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13034
CVE-2025-68766 irqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc()

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-68766
CVE-2025-68753 ALSA: firewire-motu: add bounds check in put_user loop for DSP events

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-68753
CVE-2025-21839 KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21839
CVE-2025-2953 PyTorch torch.mkldnn_max_pool2d denial of service

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-2953
CVE-2024-58089 btrfs: fix double accounting race when btrfs_run_delalloc_range() failed

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-58089
CVE-2020-36426 An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-36426