Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Linux — Vulnerabilities & Security Advisories 17499

Browse all 17499 CVE security advisories affecting Linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Linux serves as the foundational operating system for the majority of internet servers, cloud infrastructure, and embedded devices, powering critical global digital services. Its open-source nature and widespread deployment have historically exposed it to diverse vulnerability classes, including remote code execution, buffer overflows, and privilege escalation flaws within kernel modules and system utilities. While the project maintains rigorous security practices, the sheer volume of code contributes to a high cumulative count of recorded Common Vulnerabilities and Exposures, currently exceeding eleven thousand. Notable incidents often stem from misconfigurations or unpatched legacy components rather than fundamental architectural failures. The community responds rapidly to disclosed threats, yet the extensive attack surface necessitates continuous vigilance. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with this ubiquitous platform, ensuring stability across both enterprise and consumer environments.

CVE ID Title CVSS Severity Published
CVE-2026-97440 net: qrtr: fix node refcount leak on ctrl packet alloc failure — Linux - - 2026-09-24
CVE-2026-97439 fs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib — Linux - - 2026-09-24
CVE-2026-97438 fs/ntfs3: validate index entry key bounds — Linux 7.1 High 2026-09-24
CVE-2026-97437 ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e() — Linux 7.1 High 2026-09-24
CVE-2026-97436 dpaa2-switch: rework FDB management on the bridge leave path — Linux - - 2026-09-24
CVE-2026-97435 net: dsa: sja1105: flower: reject cross-chip redirect — Linux - - 2026-09-24
CVE-2026-97434 dpaa2-switch: fix handling of NAPI on the remove path — Linux - - 2026-09-24
CVE-2026-97433 nvme: validate FDP configuration descriptor sizes — Linux 8.2 High 2026-09-24
CVE-2026-97432 wifi: iwlwifi: mvm: fix P2P-Device binding handling — Linux - - 2026-09-24
CVE-2026-97431 drm/amd/display: Avoid DPMS-on for phantom stream — Linux - - 2026-09-24
CVE-2026-97430 xhci: Prevent queuing new commands if xhci is inaccessible — Linux - - 2026-09-24
CVE-2026-97429 drm/amdkfd: fix UAF race in destroy_queue_cpsch — Linux 7.8 High 2026-09-24
CVE-2026-97428 drm/amdgpu: harden FRU PIA parsing with bounded helpers — Linux 7.7 High 2026-09-24
CVE-2026-97427 drm/amd/pm: bound pp_dpm_set_pp_table() memcpy — Linux - - 2026-09-24
CVE-2026-97426 drm/amdgpu/pm: fix SmartShift bias sysfs store PM refcount on parse error — Linux - - 2026-09-24
CVE-2026-97425 drm/amdgpu: fix buffer overflow during vBIOS update — Linux - - 2026-09-24
CVE-2026-97424 drm/amdgpu/ras: add ras_suspend callback and use it for cp_ecc_error_irq — Linux - - 2026-09-24
CVE-2026-97423 cxl/region: Validate partition index before array access — Linux - - 2026-09-24
CVE-2026-97422 drm/amdkfd: fix SMI event cross-process information leak — Linux - - 2026-09-24
CVE-2026-97421 RDMA/umem: Be careful about boundary conditions in ib_umem_find_best_pgsz() — Linux 7.8 High 2026-09-24
CVE-2026-97420 bpf: NUL-terminate replaced sysctl value — Linux - - 2026-09-24
CVE-2026-97419 hsr: broadcast netlink notifications in the device's net namespace — Linux - - 2026-09-24
CVE-2026-97418 ALSA: es18xx: check control allocation before private data setup — Linux - - 2026-09-24
CVE-2026-97417 netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() — Linux 7.5 High 2026-09-24
CVE-2026-97416 btrfs: balance: fix potential bg lookup failure in btrfs_may_alloc_data_chunk() — Linux - - 2026-09-24
CVE-2026-97415 btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF — Linux 7.8 High 2026-09-24
CVE-2026-97414 ASoC: mediatek: mt8365-afe-pcm: fix possible NULL-pointer dereferences in mt8365_afe_suspend() — Linux - - 2026-09-24
CVE-2026-97413 RDMA/rtrs-srv: Fix integer underflow in process_read and process_write — Linux 9.8 Critical 2026-09-24
CVE-2026-97412 pds_core: quiesce DMA before freeing resources — Linux - - 2026-09-24
CVE-2026-97411 net: ibm: emac: mal: fix potential system hang in mal_remove() — Linux - - 2026-09-24

This page lists every published CVE security advisory associated with Linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.