Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Linux — Vulnerabilities & Security Advisories 17499

Browse all 17499 CVE security advisories affecting Linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Linux serves as the foundational operating system for the majority of internet servers, cloud infrastructure, and embedded devices, powering critical global digital services. Its open-source nature and widespread deployment have historically exposed it to diverse vulnerability classes, including remote code execution, buffer overflows, and privilege escalation flaws within kernel modules and system utilities. While the project maintains rigorous security practices, the sheer volume of code contributes to a high cumulative count of recorded Common Vulnerabilities and Exposures, currently exceeding eleven thousand. Notable incidents often stem from misconfigurations or unpatched legacy components rather than fundamental architectural failures. The community responds rapidly to disclosed threats, yet the extensive attack surface necessitates continuous vigilance. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with this ubiquitous platform, ensuring stability across both enterprise and consumer environments.

CVE ID Title CVSS Severity Published
CVE-2026-93069 OPP: Fix cleanup ordering — Linux - - 2026-09-17
CVE-2026-93070 media: ipu6: Do not free aux device pdata after init — Linux 7.8 High 2026-09-17
CVE-2026-93068 drm/amd/display: Fix DM I2C teardown race — Linux - - 2026-09-17
CVE-2026-93067 drm/bridge: tc358767: clamp the reported AUX read size to the request — Linux - - 2026-09-17
CVE-2026-93066 x86/mm/pat: Take cpa_lock around large-page collapse — Linux - - 2026-09-17
CVE-2026-93065 wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs — Linux - - 2026-09-17
CVE-2026-93064 wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser — Linux - - 2026-09-17
CVE-2026-93063 wifi: iwlwifi: mei: check SAP message length before reading it — Linux 8.4 High 2026-09-17
CVE-2026-93061 gpu: host1x: Avoid stack over-read in debug output helpers — Linux - - 2026-09-17
CVE-2026-93062 wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments — Linux - - 2026-09-17
CVE-2026-93060 drm/msm/adreno: fix use after free on error path in a6xx_gpu_init() — Linux - - 2026-09-17
CVE-2026-93058 drm/msm: Only fini scheduler after successful init — Linux - - 2026-09-17
CVE-2026-93059 drm/msm: Fix task_struct reference leak in recover_worker — Linux - - 2026-09-17
CVE-2026-93057 scsi: ufs: core: Avoid possible memory reclaim deadlock in TX EQTR context — Linux - - 2026-09-17
CVE-2026-93055 UDF symlink pathComponent header OOB read — Linux - - 2026-09-17
CVE-2026-93056 usb: gadget: f_uac1_legacy: remove broken string configfs attributes — Linux - - 2026-09-17
CVE-2026-93054 uio: Fix stale info pointer in failed registration path — Linux 7.0 High 2026-09-17
CVE-2026-93052 misc: bcm-vk: Use acquire/release for msgq_inited — Linux - - 2026-09-17
CVE-2026-93053 speakup: keyhelp: guard letter_offsets possible out-of-range indexing — Linux - - 2026-09-17
CVE-2026-93051 misc: ad525x_dpot: use driver core groups for sysfs files — Linux - - 2026-09-17
CVE-2026-93049 mtd: mtdswap: Avoid freeing registered blktrans device twice — Linux - - 2026-09-17
CVE-2026-93050 ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove — Linux - - 2026-09-17
CVE-2026-93048 mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() — Linux - - 2026-09-17
CVE-2026-93046 software node: Fix software_node_get_reference_args() with index -1 — Linux 7.0 High 2026-09-17
CVE-2026-93047 drm/v3d: Associate BOs with every job that accesses them — Linux - - 2026-09-17
CVE-2026-93045 bpf: Reject arena frees below the arena base — Linux 7.8 High 2026-09-17
CVE-2026-93044 bpf: Disallow interpreter fallback for arena-related insns — Linux - - 2026-09-17
CVE-2026-93043 bpf: Disallow interpreter fallback for gotox insn — Linux - - 2026-09-17
CVE-2026-93042 dmaengine: dw-edma: Terminate all descriptors without callbacks — Linux 8.8 High 2026-09-17
CVE-2026-93041 dmaengine: dw-edma: Serialize abort state updates — Linux - - 2026-09-17

This page lists every published CVE security advisory associated with Linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.