Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Linux — Vulnerabilities & Security Advisories 17499

Browse all 17499 CVE security advisories affecting Linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Linux serves as the foundational operating system for the majority of internet servers, cloud infrastructure, and embedded devices, powering critical global digital services. Its open-source nature and widespread deployment have historically exposed it to diverse vulnerability classes, including remote code execution, buffer overflows, and privilege escalation flaws within kernel modules and system utilities. While the project maintains rigorous security practices, the sheer volume of code contributes to a high cumulative count of recorded Common Vulnerabilities and Exposures, currently exceeding eleven thousand. Notable incidents often stem from misconfigurations or unpatched legacy components rather than fundamental architectural failures. The community responds rapidly to disclosed threats, yet the extensive attack surface necessitates continuous vigilance. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with this ubiquitous platform, ensuring stability across both enterprise and consumer environments.

CVE ID Title CVSS Severity Published
CVE-2026-98003 iommu/amd: Do not reallocate GA log buffers on resume — Linux - - 2026-09-25
CVE-2026-98002 iommu/amd: Fix ineffective error check in nested domain allocation — Linux 7.8 High 2026-09-25
CVE-2026-98000 hwmon: Fix potential UAF in pec_store — Linux - - 2026-09-25
CVE-2026-98001 hwmon: (ltc4282) Make sure clk_init_data is fully initialized — Linux - - 2026-09-25
CVE-2026-97998 netfilter: nfnetlink_log: cope with concurrent instance destruction — Linux - - 2026-09-25
CVE-2026-97996 virtio: fix use-after-free in unregister_virtio_device() — Linux - - 2026-09-25
CVE-2026-97997 virtio_ring: fix stale descriptor flags after a failed packed add — Linux - - 2026-09-25
CVE-2026-97994 vhost/vdpa: reject VRING_NUM larger than device max — Linux - - 2026-09-25
CVE-2026-97995 virtio_console: do not free control-out buffers on remove — Linux - - 2026-09-25
CVE-2026-97993 vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx — Linux - - 2026-09-25
CVE-2026-97992 vhost-vdpa: protect config_ctx from being freed under the config callback — Linux - - 2026-09-25
CVE-2026-97991 vdpa_sim_blk: reject out-of-range sector starts — Linux 7.8 High 2026-09-25
CVE-2026-97990 vdpa_sim_net: check TX pull result before RX copy — Linux 7.5 High 2026-09-25
CVE-2026-97989 vduse: validate virtqueue alignment — Linux - - 2026-09-25
CVE-2026-97988 vhost: invalidate vring access on IOTLB transitions — Linux - - 2026-09-25
CVE-2026-97986 virtio_input: stop callbacks before unregistering input device — Linux - - 2026-09-25
CVE-2026-97987 virtio_input: reset device if input_register_device() fails — Linux - - 2026-09-25
CVE-2026-97984 net: ipv6: Fix UDP length overflow with PMTU discover and big MTU — Linux - - 2026-09-25
CVE-2026-97985 af_unix: Update last skb marker in manage_oob(). — Linux - - 2026-09-25
CVE-2026-97983 vduse: return compat ioctl results directly — Linux - - 2026-09-25
CVE-2026-97982 net: ethernet: cortina: Fix budget accounting — Linux - - 2026-09-25
CVE-2026-97981 net: ethernet: cortina: Count dropped frames as NAPI work — Linux - - 2026-09-25
CVE-2026-97980 s390/debug: Fix NULL pointer dereference in debug_set_level() — Linux - - 2026-09-25
CVE-2026-97979 ice: add missing xa_destroy for sched_node_ids — Linux - - 2026-09-25
CVE-2026-97978 eth: ice: don't dereference pointers from TP_printk() — Linux - - 2026-09-25
CVE-2026-97976 Bluetooth: btintel_pcie: validate packet_len before skb_put_data — Linux - - 2026-09-25
CVE-2026-97977 Bluetooth: btusb: Fix UAF of btusb_data by rx_work — Linux - - 2026-09-25
CVE-2026-97975 Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del() — Linux - - 2026-09-25
CVE-2026-97973 net: macb: destroy the phylink instance on the probe error path — Linux - - 2026-09-25
CVE-2026-97974 ipv6: null-check fib6_node before accessing in __ip6_del_rt_siblings() — Linux - - 2026-09-25

This page lists every published CVE security advisory associated with Linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.