Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Linux — Vulnerabilities & Security Advisories 17499

Browse all 17499 CVE security advisories affecting Linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Linux serves as the foundational operating system for the majority of internet servers, cloud infrastructure, and embedded devices, powering critical global digital services. Its open-source nature and widespread deployment have historically exposed it to diverse vulnerability classes, including remote code execution, buffer overflows, and privilege escalation flaws within kernel modules and system utilities. While the project maintains rigorous security practices, the sheer volume of code contributes to a high cumulative count of recorded Common Vulnerabilities and Exposures, currently exceeding eleven thousand. Notable incidents often stem from misconfigurations or unpatched legacy components rather than fundamental architectural failures. The community responds rapidly to disclosed threats, yet the extensive attack surface necessitates continuous vigilance. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with this ubiquitous platform, ensuring stability across both enterprise and consumer environments.

CVE ID Title CVSS Severity Published
CVE-2026-98324 dmaengine: pxa: fix double counting of the hw descriptors — Linux 7.8 High 2026-10-06
CVE-2026-98323 RDMA/siw: Bound fragmented header copies by the remaining length — Linux 9.8 Critical 2026-10-06
CVE-2026-98322 netfilter: nft_nat: fully initialise new_addr in netmap setup — Linux - - 2026-10-06
CVE-2026-98321 netfilter: nf_nat: unregister and release hooks on error — Linux - - 2026-10-06
CVE-2026-98320 netfilter: flowtable: hold reference on ct until flow is released — Linux 7.8 High 2026-10-06
CVE-2026-98319 drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr — Linux - - 2026-10-06
CVE-2026-98318 smb: client: validate absolute native symlink targets before NT fixups — Linux 7.8 High 2026-10-06
CVE-2026-98317 neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS. — Linux - - 2026-10-06
CVE-2026-98316 ALSA: bcd2000: Fix race between rawmidi and disconnect — Linux - - 2026-10-06
CVE-2026-98315 ntfs: protect runlist updates with the runlist lock — Linux 7.8 High 2026-10-06
CVE-2026-98314 ALSA: pcm: set timer->private_data before registering the PCM timer — Linux - - 2026-10-06
CVE-2026-98313 drm/msm/dp: skip PUSH_IDLE when the link was never enabled — Linux - - 2026-10-06
CVE-2026-98311 wifi: virt_wifi: don't transfer operstate before register — Linux 7.8 High 2026-10-06
CVE-2026-98312 ALSA: 6fire: fix OOB write from device-reported iso length — Linux - - 2026-10-06
CVE-2026-98310 drm/xe/shrinker: Take a runtime PM ref before shrinking non-system memory — Linux - - 2026-10-06
CVE-2026-98309 drm/vc4: Use managed KMS polling to fix UAF on unbind — Linux - - 2026-10-06
CVE-2026-98308 ALSA: hda: trace PCM open only after assigning a stream — Linux - - 2026-10-06
CVE-2026-98307 wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all() — Linux - - 2026-10-06
CVE-2026-98306 seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation — Linux - - 2026-10-06
CVE-2026-98305 net: dsa: mxl862xx: disable the stats poll on teardown — Linux 7.8 High 2026-10-06
CVE-2026-98303 ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup — Linux - - 2026-10-06
CVE-2026-98304 net: bcmgenet: restore the hardware filters on open — Linux - - 2026-10-06
CVE-2026-98302 net: fddi: skfp: fix NULL deref when setting the MAC address while down — Linux - - 2026-10-06
CVE-2026-98301 net: bridge: mst: move switchdev call outside rcu — Linux - - 2026-10-06
CVE-2026-98300 tcp: Don't call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv(). — Linux - - 2026-10-06
CVE-2026-98299 tcp: do not let tcp_rmem be set below 4096 — Linux - - 2026-10-06
CVE-2026-98297 Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained — Linux - - 2026-10-06
CVE-2026-98298 dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() — Linux - - 2026-10-06
CVE-2026-98296 Bluetooth: btintel_pcie: validate TX skb length in send_sync — Linux - - 2026-10-06
CVE-2026-98295 Bluetooth: coredump: Quiesce dump work on unregister — Linux - - 2026-10-06

This page lists every published CVE security advisory associated with Linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.