Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Linux — Vulnerabilities & Security Advisories 17499

Browse all 17499 CVE security advisories affecting Linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Linux serves as the foundational operating system for the majority of internet servers, cloud infrastructure, and embedded devices, powering critical global digital services. Its open-source nature and widespread deployment have historically exposed it to diverse vulnerability classes, including remote code execution, buffer overflows, and privilege escalation flaws within kernel modules and system utilities. While the project maintains rigorous security practices, the sheer volume of code contributes to a high cumulative count of recorded Common Vulnerabilities and Exposures, currently exceeding eleven thousand. Notable incidents often stem from misconfigurations or unpatched legacy components rather than fundamental architectural failures. The community responds rapidly to disclosed threats, yet the extensive attack surface necessitates continuous vigilance. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with this ubiquitous platform, ensuring stability across both enterprise and consumer environments.

CVE ID Title CVSS Severity Published
CVE-2026-97545 xfs: don't leak new_bp if xfs_btree_bload_drop_buf fails — Linux - - 2026-09-25
CVE-2026-97544 xfs: don't leak dqacct if rhashtable insertion fails — Linux - - 2026-09-25
CVE-2026-97542 xfs: bail out on bitmap errors in xrep_agfl_fill — Linux - - 2026-09-25
CVE-2026-97543 xfs: destroy seen inode bitmap when we fail to add a dirpath — Linux - - 2026-09-25
CVE-2026-97541 wifi: ath9k_htc: don't store usb_device_id — Linux - - 2026-09-25
CVE-2026-97540 net: usb: pegasus: don't rely on id table pointer arithmetic — Linux - - 2026-09-25
CVE-2026-97539 usb: xusbatm: don't rely on id table pointer arithmetic — Linux - - 2026-09-25
CVE-2026-97538 hwmon: (asus_rog_ryujin) Validate HID report lengths — Linux - - 2026-09-25
CVE-2026-97537 scsi: qla2xxx: Fix queue teardown NULL dma_free and bitmap locking — Linux - - 2026-09-25
CVE-2026-97536 scsi: qla2xxx: Fix use-after-free of qpair work on queue teardown — Linux 7.5 High 2026-09-25
CVE-2026-97534 f2fs: accurately adjust free_sections during free_segment_range — Linux - - 2026-09-25
CVE-2026-97535 scsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size — Linux - - 2026-09-25
CVE-2026-97532 scsi: qla2xxx: Null out freed pointers in qla2x00_mem_alloc() error path — Linux - - 2026-09-25
CVE-2026-97533 x86/mm/pat: Acquire init_mm read lock on attribute changes to avoid UAF — Linux - - 2026-09-25
CVE-2026-97531 scsi: qla2xxx: Skip vport under deletion in report ID acquisition — Linux 7.5 High 2026-09-25
CVE-2026-97529 scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[] — Linux - - 2026-09-25
CVE-2026-97530 scsi: qla2xxx: Fix soft lockup polling continuation IOCB signature — Linux - - 2026-09-25
CVE-2026-97528 scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error — Linux 8.8 High 2026-09-25
CVE-2026-97527 scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock — Linux 8.8 High 2026-09-25
CVE-2026-97526 s390/pai: Support CPU hotplug for PMU PAI — Linux - - 2026-09-25
CVE-2026-97524 mptcp: avoid unneeded actions on subflow reset — Linux 7.5 High 2026-09-25
CVE-2026-97525 x86/mm/pat: Allocate split page tables as kernel page tables — Linux 8.2 High 2026-09-25
CVE-2026-97523 mptcp: close race between scheduler and state change — Linux 7.5 High 2026-09-25
CVE-2026-97522 mptcp: fix bad accounting in __mptcp_subflow_push_pending() — Linux - - 2026-09-25
CVE-2026-97521 gfs2: fix quota init duplicate scan — Linux - - 2026-09-24
CVE-2026-97520 gfs2: move quota_init qc iterator increment — Linux 7.1 High 2026-09-24
CVE-2026-97519 drm/xe: Fix null pointer dereference in devcoredump cleanup — Linux - - 2026-09-24
CVE-2026-97518 wifi: cfg80211: reject duplicate wiphy cipher suite entries — Linux - - 2026-09-24
CVE-2026-97517 wifi: nl80211: reject beacons with bad HE operation — Linux - - 2026-09-24
CVE-2026-97516 wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result() — Linux - - 2026-09-24

This page lists every published CVE security advisory associated with Linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.