Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Linux — Vulnerabilities & Security Advisories 17499

Browse all 17499 CVE security advisories affecting Linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Linux serves as the foundational operating system for the majority of internet servers, cloud infrastructure, and embedded devices, powering critical global digital services. Its open-source nature and widespread deployment have historically exposed it to diverse vulnerability classes, including remote code execution, buffer overflows, and privilege escalation flaws within kernel modules and system utilities. While the project maintains rigorous security practices, the sheer volume of code contributes to a high cumulative count of recorded Common Vulnerabilities and Exposures, currently exceeding eleven thousand. Notable incidents often stem from misconfigurations or unpatched legacy components rather than fundamental architectural failures. The community responds rapidly to disclosed threats, yet the extensive attack surface necessitates continuous vigilance. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with this ubiquitous platform, ensuring stability across both enterprise and consumer environments.

CVE ID Title CVSS Severity Published
CVE-2026-98384 bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() — Linux - - 2026-10-09
CVE-2026-98383 bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL — Linux - - 2026-10-09
CVE-2026-98382 bpf: Reject dev-bound-only programs on other devices — Linux - - 2026-10-09
CVE-2026-98381 veth: manage XDP program pointers during channel resize — Linux - - 2026-10-09
CVE-2026-98380 net/sched: reject IDR error pointers when deleting actions — Linux - - 2026-10-09
CVE-2026-98378 bpf: Skip unsettled links in link iterator — Linux - - 2026-10-09
CVE-2026-98379 netfilter: ip6t_rpfilter: reject routes without inet6_dev — Linux - - 2026-10-09
CVE-2026-98377 vlan: require the MAC header to be present in __vlan_insert_inner_tag() — Linux - - 2026-10-09
CVE-2026-98376 bpf: Use array_map_meta_equal for percpu array inner map replacement — Linux - - 2026-10-09
CVE-2026-98375 xen/netfront: drop RX packets with a short Ethernet header — Linux - - 2026-10-09
CVE-2026-98374 tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() — Linux - - 2026-10-07
CVE-2026-98373 mm/hugetlb: preserve mremap address delta when skipping page tables — Linux - - 2026-10-07
CVE-2026-98372 xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk() — Linux - - 2026-10-06
CVE-2026-98371 xfrm: iptfs: fix runt reassembly panic from short inner tot_len — Linux - - 2026-10-06
CVE-2026-98370 xfrm: fix compat ALLOCSPI request use-after-free — Linux - - 2026-10-06
CVE-2026-98369 xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() — Linux 7.8 High 2026-10-06
CVE-2026-98368 esp: downgrade zerocopy managed frags before mutating skb frags — Linux 7.8 High 2026-10-06
CVE-2026-98367 RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept — Linux 7.8 High 2026-10-06
CVE-2026-98366 RDMA/rxe: validate access flags before swapping the MR's PD — Linux 7.8 High 2026-10-06
CVE-2026-98365 RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access — Linux 9.8 Critical 2026-10-06
CVE-2026-98364 xfrm: hold net_device reference under RCU in bundle creation — Linux 7.8 High 2026-10-06
CVE-2026-98363 firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS — Linux - - 2026-10-06
CVE-2026-98362 clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate — Linux - - 2026-10-06
CVE-2026-98361 RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths — Linux 7.8 High 2026-10-06
CVE-2026-98360 RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds — Linux 7.0 High 2026-10-06
CVE-2026-98359 RDMA/core: Reject unregistering netdevs in ib_get_eth_speed — Linux 7.0 High 2026-10-06
CVE-2026-98358 IB/iser: reject a remote invalidation of an unregistered direction — Linux - - 2026-10-06
CVE-2026-98357 IB/isert: wait for deferred control PDU completions before releasing the connection — Linux 8.1 High 2026-10-06
CVE-2026-98355 RDMA/rtrs: guard against null kobj name — Linux - - 2026-10-06
CVE-2026-98356 RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup — Linux - - 2026-10-06

This page lists every published CVE security advisory associated with Linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.