Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Linux — Vulnerabilities & Security Advisories 17499

Browse all 17499 CVE security advisories affecting Linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Linux serves as the foundational operating system for the majority of internet servers, cloud infrastructure, and embedded devices, powering critical global digital services. Its open-source nature and widespread deployment have historically exposed it to diverse vulnerability classes, including remote code execution, buffer overflows, and privilege escalation flaws within kernel modules and system utilities. While the project maintains rigorous security practices, the sheer volume of code contributes to a high cumulative count of recorded Common Vulnerabilities and Exposures, currently exceeding eleven thousand. Notable incidents often stem from misconfigurations or unpatched legacy components rather than fundamental architectural failures. The community responds rapidly to disclosed threats, yet the extensive attack surface necessitates continuous vigilance. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with this ubiquitous platform, ensuring stability across both enterprise and consumer environments.

CVE ID Title CVSS Severity Published
CVE-2026-98125 smb/client: fix stale page cache in insert/collapse range — Linux - - 2026-09-25
CVE-2026-98123 sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration — Linux - - 2026-09-25
CVE-2026-98122 vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del() — Linux 7.8 High 2026-09-25
CVE-2026-98121 watchdog: msc313e: Fix NULL pointer dereference in PM callbacks — Linux - - 2026-09-25
CVE-2026-98120 netfs: Fix subreq ref leak — Linux - - 2026-09-25
CVE-2026-98119 netfs: break unbuffered write when netfs_alloc_subrequest() fails — Linux - - 2026-09-25
CVE-2026-98118 netfs: Fix readahead synchronisation issues by loading all folios upfront — Linux - - 2026-09-25
CVE-2026-98116 ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF — Linux 7.8 High 2026-09-25
CVE-2026-98117 cachefiles: Fix potential UAF/KASAN warning — Linux - - 2026-09-25
CVE-2026-98115 ksmbd: safely drain sessions during logoff — Linux 8.8 High 2026-09-25
CVE-2026-98114 ksmbd: propagate DACL parsing errors — Linux - - 2026-09-25
CVE-2026-98113 ksmbd: rate limit unmapped SID errors — Linux - - 2026-09-25
CVE-2026-98112 ksmbd: fix listener task lifetime on netdev events — Linux 7.8 High 2026-09-25
CVE-2026-98111 Bluetooth: btintel: validate version TLV value lengths — Linux - - 2026-09-25
CVE-2026-98109 Bluetooth: hci_core: Fix race condition during device registration — Linux - - 2026-09-25
CVE-2026-98110 Bluetooth: btintel: bound firmware ID by TLV length — Linux - - 2026-09-25
CVE-2026-98108 Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan — Linux 7.5 High 2026-09-25
CVE-2026-98106 drm/pagemap: Prevent double migration of device pages — Linux - - 2026-09-25
CVE-2026-98107 Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect — Linux - - 2026-09-25
CVE-2026-98104 net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted — Linux - - 2026-09-25
CVE-2026-98105 net: ethernet: oa_tc6: Improve the error recovery — Linux - - 2026-09-25
CVE-2026-98103 igmp: convert struct ip_sf_list to RCU — Linux - - 2026-09-25
CVE-2026-98102 ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src() — Linux - - 2026-09-25
CVE-2026-98101 ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source() — Linux - - 2026-09-25
CVE-2026-98099 ipv6: mcast: use rcu_assign_pointer() for __rcu list updates — Linux - - 2026-09-25
CVE-2026-98097 tipc: Dont send random pad bytes in RESET/ACTIVATE messages — Linux - - 2026-09-25
CVE-2026-98098 tipc: fix NULL deref in tipc_named_node_up() on empty publication list — Linux - - 2026-09-25
CVE-2026-98096 ipv6: sr: restore network header before routing and forwarding — Linux 7.4 High 2026-09-25
CVE-2026-98095 af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header(). — Linux - - 2026-09-25
CVE-2026-98094 staging: fbtft: make dirty_lock IRQ-safe — Linux - - 2026-09-25

This page lists every published CVE security advisory associated with Linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.