Articles from May 2026
Browse all Windows news articles published in May 2026
Linux spidev deadlock CVE-2026-43319 freezes WSL2, Hyper-V VMs using SPI devices
A newly disclosed Linux kernel vulnerability—CVE-2026-43319—exposes a nasty deadlock in the spidev subsystem, one that could freeze systems that rely on SPI devices. Published on May 8, 2026, the...
CVE-2026-43306: New Linux BPF Crypto Bug Triggers Kernel Crash Under CFI — WSL2 and Azure at Risk
The Linux kernel’s BPF crypto subsystem contains a type-mismatch vulnerability that instantly crashes the host when Control Flow Integrity (CFI) enforcement is active. Tracked as CVE-2026-43306 and...
CVE-2026-43300: Linux DRM NULL Pointer Flaw Flagged by Microsoft for Windows Environments
Microsoft's Security Update Guide has brought an unusual Linux kernel vulnerability into the spotlight on May 8, 2026. CVE-2026-43300, a NULL pointer dereference in the Direct Rendering Manager (DRM)...
Azure Linux 3.0 Admins: Patch Critical AMD eDP Kernel Flaw Now
Microsoft has released an out-of-band patch for a critical kernel vulnerability tracked as CVE-2026-43320, which threatens Azure Linux 3.0 virtual machines equipped with AMD graphics processors. The...
CVE-2026-43474: Why This Linux Kernel Bug Is on Microsoft’s Radar and What Windows Teams Need to Do
Microsoft’s Security Update Guide now tracks a newly disclosed Linux kernel vulnerability, CVE-2026-43474, published in early May 2026. The flaw stems from an uninitialized flags_valid field before...
CVE-2026-43010: Critical Linux Kernel eBPF Flaw Exposes WSL and Container Workloads to Privilege Escalation
The National Vulnerability Database published CVE-2026-43010 on May 1, 2026, flagging a serious flaw in the Linux kernel's BPF subsystem. The vulnerability resides in the kprobe.multi attachment...
CVE-2026-43052 Linux Wi‑Fi Flaw Threatens Windows Fleets via WSL
On May 1, 2026, kernel.org published a security advisory for CVE-2026-43052, a high-severity vulnerability in the Linux kernel’s Wi-Fi stack. The flaw, rated “High” with a local attack vector,...
Linux Kernel Bluetooth Zero-Day Exploits WSL2 and Azure VMs
A high-severity vulnerability in the Linux kernel’s Bluetooth stack, tracked as CVE-2026-31771, was publicly disclosed on May 1, 2026. The flaw exposes millions of devices—including those running...
Linux Kernel CVE-2026-43036 Leaks Memory via TCP GSO Packet Flaw
A medium-severity vulnerability in the Linux kernel’s network stack exposes systems to a subtle information leak, exploiting the way the kernel handles segmented TCP packets. CVE-2026-43036,...
CVE-2026-31724: Linux Kernel USB Gadget Flaw Causes DoS — No Risk to Windows
The Linux kernel’s security team has published details of a newly assigned vulnerability, CVE-2026-31724, that targets the USB gadget subsystem. The flaw, rated medium severity, resides in the...
CVE-2026-31723: Linux Kernel Patch Fixes Dangling sysfs Links in USB Gadget Driver – Why Windows Users Should Care
A new Linux kernel vulnerability, CVE-2026-31723, has been disclosed, drawing attention to a subtle bug in the USB gadget subsystem's f_subset driver. Published on May 1, 2026, the medium-severity...
Big Tech, Epic Battle for Trust in 2026 Health AI Copilot Push
Microsoft, Amazon, and Epic Systems are plunging into a 2026 arms race to build patient-facing AI copilots that can decode sprawling medical records, lab results, and reams of wearable device data....