Articles from May 2026
Browse all Windows news articles published in May 2026
KVM AMD Nested VM Bug Risks Data Leak and Host Crashes; Patch Released
The National Vulnerability Database published CVE-2026-46014 on May 27, 2026, detailing a flaw in the Linux kernel's Kernel-based Virtual Machine (KVM) that affects AMD Secure Virtual Machine (SVM)...
Linux Kernel Patch for CVE-2026-46101 Fixes Zero-Bit Shift in nftables After Undefined Behavior Risk
A newly published Linux kernel vulnerability exposes a dangerous oversight in nftables bitwise operations where a zero-bit shift could trigger undefined behavior inside the network packet filtering...
KVM AMD Bug Lets Guest Escape VM via CR3 Failure on Nested Virtualization
The National Vulnerability Database published CVE-2026-46032 on May 27, 2026, detailing a flaw in the Linux kernel's KVM subsystem affecting AMD processors with nested virtualization enabled. The...
CVE-2026-45859: Linux Netfilter nfnetlink_queue Flaw Drops UDP GSO Packets, Impacts Windows Subsystem for Linux
The National Vulnerability Database published CVE-2026-45859 on May 27, 2026, revealing a regression in the Linux kernel’s netfilter nfnetlink_queue subsystem that can silently drop certain UDP...
Linux mwifiex Driver Bug: Wakeup Timer Race Leads to Use-After-Free
The National Vulnerability Database (NVD) published details on May 27, 2026, about a race condition in the Linux kernel's mwifiex Wi-Fi driver cleanup routine. Tracked as CVE-2026-46069, the...
CVE-2026-46047 Linux QRTR Bug Threatens Windows Teams via WSL
A newly disclosed Linux kernel vulnerability tracked as CVE-2026-46047 exposes a serious use-after-free flaw in the Qualcomm QRTR subsystem. The bug, entered into the National Vulnerability Database...
CVE-2026-45986: Critical Memory Leak in Linux ccree Crypto Driver—What Windows Admins Must Do Now
A high-severity memory leak in the Linux kernel’s ccree crypto driver, tracked as CVE-2026-45986, was published on kernel.org and recorded by the National Vulnerability Database on May 27, 2026....
CVE-2026-45997 Linux SCSI Bug Threatens WSL, Hyper-V, and Dual-Boot Users
A newly published Linux kernel vulnerability, CVE-2026-45997, exposes a subtle but dangerous reference-counting flaw in the SCSI subsystem. The National Vulnerability Database (NVD) posted the entry...
CVE-2026-45897: The Linux Kernel Spinlock Fix That Shows Why Firewall Metrics Can't Be Trusted
On May 27, 2026, the Linux kernel project disclosed CVE-2026-45897, a race condition in the nftables firewall subsystem that could corrupt counter values when multiple processes reset them...
Kernel Oops in stmmac Driver Puts Network Appliances at Risk: Patch Now
A recently disclosed vulnerability in the Linux kernel’s stmmac Ethernet driver can trigger a kernel crash when processing network packets with split header mode enabled on GMAC4 hardware. The bug,...
CVE-2026-45839: Linux eBPF Parsing Bug Crashes Kernels — What Windows Users Need to Do
On May 27, 2026, Linux kernel maintainers disclosed a vulnerability that exposes a fundamental parsing mistake in the kernel's eBPF subsystem. Tracked as CVE-2026-45839, the bug allows any local user...
CVE-2026-45836: The Linux Kernel Bluetooth Flaw That Windows Users Can't Ignore
On May 26, 2026, a null-pointer dereference in the Linux kernel's Bluetooth L2CAP subsystem hit the public vulnerability database as CVE-2026-45836. The bug itself is unglamorous—a missing safety...