MSRC Reports
61 subscribers
2.97K links
Microsoft Security Response Center Reports
(Unofficial).

Reports usually come in bursts, because that's just how Microsoft releases them.
Download Telegram
CVE-2026-22999 net/sched: sch_qfq: do not free existing class in qfq_change_class()

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-22999
CVE-2026-22991 libceph: make free_choose_arg_map() resilient to partial allocation

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-22991
CVE-2026-22990 libceph: replace overzealous BUG_ON in osdmap_apply_incremental()

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-22990
CVE-2026-22984 libceph: prevent potential out-of-bounds reads in handle_auth_done()

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-22984
CVE-2026-22982 net: mscc: ocelot: Fix crash when adding interface under a lag

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-22982
CVE-2026-22980 nfsd: provide locking for v4_end_grace

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-22980
CVE-2026-22979 net: fix memory leak in skb_segment_list for GRO packets

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-22979
CVE-2025-71162 dmaengine: tegra-adma: Fix use-after-free

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-71162
CVE-2025-71150 ksmbd: Fix refcount leak when invalid session is found on session lookup

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-71150
CVE-2025-71089 iommu: disable SVA when CONFIG_X86 is set

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-71089
CVE-2026-22998 nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-22998
CVE-2026-22997 net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session upon receiving the second rts

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-22997
CVE-2026-22996 net/mlx5e: Don't store mlx5e_priv in mlx5e_dev devlink priv

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-22996
CVE-2026-28420 Vim has Heap-based Buffer Overflow and OOB Read in :terminal

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-28420
CVE-2026-27969 Vitess users with backup storage access can write to arbitrary file paths on restore

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27969
CVE-2026-28422 Vim has stack-buffer-overflow in build_stl_str_hl()

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-28422
CVE-2026-28419 Vim has Heap-based Buffer Underflow in Emacs tags parsing

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-28419
CVE-2026-28418 Vim has Heap-based Buffer Overflow in Emacs tags parsing

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-28418
CVE-2026-28421 Vim has a heap-buffer-overflow and a segmentation fault

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-28421
CVE-2026-28417 Vim has OS Command Injection in netrw

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-28417
CVE-2023-45231 Out-of-Bounds Read in EDK II Network Package

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-45231