Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Linux — Vulnerabilities & Security Advisories 15166

Browse all 15166 CVE security advisories affecting Linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Linux serves as the foundational operating system for the majority of internet servers, cloud infrastructure, and embedded devices, powering critical global digital services. Its open-source nature and widespread deployment have historically exposed it to diverse vulnerability classes, including remote code execution, buffer overflows, and privilege escalation flaws within kernel modules and system utilities. While the project maintains rigorous security practices, the sheer volume of code contributes to a high cumulative count of recorded Common Vulnerabilities and Exposures, currently exceeding eleven thousand. Notable incidents often stem from misconfigurations or unpatched legacy components rather than fundamental architectural failures. The community responds rapidly to disclosed threats, yet the extensive attack surface necessitates continuous vigilance. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with this ubiquitous platform, ensuring stability across both enterprise and consumer environments.

Found 15026 results / 15166 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-31723 usb: gadget: f_subset: Fix net_device lifecycle with device_move — Linux 7.3 - 2026-05-01
CVE-2026-31722 usb: gadget: f_rndis: Fix net_device lifecycle with device_move — Linux 7.3 - 2026-05-01
CVE-2026-31720 usb: gadget: f_uac1_legacy: validate control request size — Linux 6.1 - 2026-05-01
CVE-2026-31721 usb: gadget: f_hid: move list and spinlock inits from bind to alloc — Linux 7.8 - 2026-05-01
CVE-2026-31718 ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger — Linux 9.8 Critical 2026-05-01
CVE-2026-31719 crypto: krb5enc - fix async decrypt skipping hash verification — Linux 7.5 High 2026-05-01
CVE-2026-31717 ksmbd: validate owner of durable handle on reconnect — Linux 8.8 High 2026-05-01
CVE-2026-31716 fs/ntfs3: validate rec->used in journal-replay file record check — Linux 7.8 High 2026-05-01
CVE-2026-31715 f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io() — Linux 5.5 - 2026-05-01
CVE-2026-31714 f2fs: fix to avoid memory leak in f2fs_rename() — Linux 5.5 - 2026-05-01
CVE-2026-31713 fuse: abort on fatal signal during sync init — Linux 6.5 - 2026-05-01
CVE-2026-31712 ksmbd: require minimum ACE size in smb_check_perm_dacl() — Linux 8.3 High 2026-05-01
CVE-2026-31711 smb: server: fix active_num_conn leak on transport allocation failure — Linux 7.5 High 2026-05-01
CVE-2026-31710 smb: client: fix dir separator in SMB1 UNIX mounts — Linux 5.5 - 2026-05-01
CVE-2026-31709 smb: client: validate the whole DACL before rewriting it in cifsacl — Linux 8.8 High 2026-05-01
CVE-2026-31708 smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path — Linux 8.1 High 2026-05-01
CVE-2026-31706 ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl() — Linux 8.8 High 2026-05-01
CVE-2026-31707 ksmbd: validate response sizes in ipc_validate_msg() — Linux 7.1 High 2026-05-01
CVE-2026-31705 ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment — Linux 9.8 Critical 2026-05-01
CVE-2026-31704 ksmbd: use check_add_overflow() to prevent u16 DACL size overflow — Linux 8.4 - 2026-05-01
CVE-2026-31702 f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io() — Linux 7.1 - 2026-05-01
CVE-2026-31703 writeback: Fix use after free in inode_switch_wbs_work_fn() — Linux 7.8 High 2026-05-01
CVE-2026-31701 ALSA: caiaq: take a reference on the USB device in create_card() — Linux 7.1 - 2026-05-01
CVE-2026-31700 net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() — Linux 7.8 High 2026-05-01
CVE-2026-31699 crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed — Linux 7.1 High 2026-05-01
CVE-2026-31698 crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed — Linux 7.1 High 2026-05-01
CVE-2026-31697 crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed — Linux 7.1 High 2026-05-01
CVE-2026-31696 rxrpc: Fix missing validation of ticket length in non-XDR key preparsing — Linux 7.8 - 2026-05-01
CVE-2026-31695 wifi: virt_wifi: remove SET_NETDEV_DEV to avoid use-after-free — Linux 7.8 High 2026-05-01
CVE-2026-31694 fuse: reject oversized dirents in page cache — Linux 7.8 High 2026-05-01

This page lists every published CVE security advisory associated with Linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.