Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Linux — Vulnerabilities & Security Advisories 15166

Browse all 15166 CVE security advisories affecting Linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Linux serves as the foundational operating system for the majority of internet servers, cloud infrastructure, and embedded devices, powering critical global digital services. Its open-source nature and widespread deployment have historically exposed it to diverse vulnerability classes, including remote code execution, buffer overflows, and privilege escalation flaws within kernel modules and system utilities. While the project maintains rigorous security practices, the sheer volume of code contributes to a high cumulative count of recorded Common Vulnerabilities and Exposures, currently exceeding eleven thousand. Notable incidents often stem from misconfigurations or unpatched legacy components rather than fundamental architectural failures. The community responds rapidly to disclosed threats, yet the extensive attack surface necessitates continuous vigilance. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with this ubiquitous platform, ensuring stability across both enterprise and consumer environments.

Found 15026 results / 15166 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2025-40279 net: sched: act_connmark: initialize struct tc_ife to fix kernel leak — Linux 5.5 - 2025-12-06
CVE-2025-40278 net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak — Linux 8.8 - 2025-12-06
CVE-2025-40277 drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE — Linux 7.8 High 2025-12-06
CVE-2025-40276 drm/panthor: Flush shmem writes before mapping buffers CPU-uncached — Linux 7.3 High 2025-12-06
CVE-2025-40275 ALSA: usb-audio: Fix NULL pointer dereference in snd_usb_mixer_controls_badd — Linux 7.1 - 2025-12-06
CVE-2025-40274 KVM: guest_memfd: Remove bindings on memslot deletion when gmem is dying — Linux 7.8 High 2025-12-06
CVE-2025-40273 NFSD: free copynotify stateid in nfs4_free_ol_stateid() — Linux 8.8 High 2025-12-06
CVE-2025-40272 mm/secretmem: fix use-after-free race in fault handler — Linux 7.8 High 2025-12-06
CVE-2025-40271 fs/proc: fix uaf in proc_readdir_de() — Linux 7.8 High 2025-12-06
CVE-2025-40270 mm, swap: fix potential UAF issue for VMA readahead — Linux 7.8 High 2025-12-06
CVE-2025-40269 ALSA: usb-audio: Fix potential overflow of PCM transfer buffer — Linux 7.8 High 2025-12-06
CVE-2025-40268 cifs: client: fix memory leak in smb3_fs_context_parse_param — Linux 5.5 - 2025-12-06
CVE-2025-40267 io_uring/rw: ensure allocated iovec gets cleared for early failure — Linux 5.5 - 2025-12-06
CVE-2025-40265 vfat: fix missing sb_min_blocksize() return value checks — Linux 6.5AI Medium AI 2025-12-04
CVE-2025-40266 KVM: arm64: Check the untrusted offset in FF-A memory share — Linux 8.2 High 2025-12-04
CVE-2025-40264 be2net: pass wrb_params in case of OS2BMC — Linux 5.5AI Medium AI 2025-12-04
CVE-2025-40263 Input: cros_ec_keyb - fix an invalid memory access — Linux 5.5AI Medium AI 2025-12-04
CVE-2025-40262 Input: imx_sc_key - fix memory corruption on unload — Linux 7.8 High 2025-12-04
CVE-2025-40260 sched_ext: Fix scx_enable() crash on helper kthread creation failure — Linux 5.5AI Medium AI 2025-12-04
CVE-2025-40261 nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl() — Linux 9.8 Critical 2025-12-04
CVE-2025-40259 scsi: sg: Do not sleep in atomic context — Linux 5.5AI Medium AI 2025-12-04
CVE-2025-40258 mptcp: fix race condition in mptcp_schedule_work() — Linux 9.8 Critical 2025-12-04
CVE-2025-40257 mptcp: fix a race in mptcp_pm_del_add_timer() — Linux 9.8 Critical 2025-12-04
CVE-2025-40256 xfrm: also call xfrm_state_delete_tunnel at destroy time for states that were never added — Linux 7.1AI High AI 2025-12-04
CVE-2025-40255 net: core: prevent NULL deref in generic_hwtstamp_ioctl_lower() — Linux 5.5AI Medium AI 2025-12-04
CVE-2025-40254 net: openvswitch: remove never-working support for setting nsh fields — Linux 7.8AI High AI 2025-12-04
CVE-2025-40253 s390/ctcm: Fix double-kfree — Linux 8.8 High 2025-12-04
CVE-2025-40252 net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() — Linux 9.8 Critical 2025-12-04
CVE-2025-40251 devlink: rate: Unset parent pointer in devl_rate_nodes_destroy — Linux 7.8 High 2025-12-04
CVE-2025-40250 net/mlx5: Clean up only new IRQ glue on request_irq() failure — Linux 7.8 High 2025-12-04

This page lists every published CVE security advisory associated with Linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.