Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Linux — Vulnerabilities & Security Advisories 17499

Browse all 17499 CVE security advisories affecting Linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Linux serves as the foundational operating system for the majority of internet servers, cloud infrastructure, and embedded devices, powering critical global digital services. Its open-source nature and widespread deployment have historically exposed it to diverse vulnerability classes, including remote code execution, buffer overflows, and privilege escalation flaws within kernel modules and system utilities. While the project maintains rigorous security practices, the sheer volume of code contributes to a high cumulative count of recorded Common Vulnerabilities and Exposures, currently exceeding eleven thousand. Notable incidents often stem from misconfigurations or unpatched legacy components rather than fundamental architectural failures. The community responds rapidly to disclosed threats, yet the extensive attack surface necessitates continuous vigilance. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with this ubiquitous platform, ensuring stability across both enterprise and consumer environments.

CVE ID Title CVSS Severity Published
CVE-2026-92498 wifi: ath6kl: avoid buffer overreads in WMI event handlers — Linux - - 2026-09-17
CVE-2026-92499 ext4: validate readdir offset before accessing dirent — Linux - - 2026-09-17
CVE-2026-92497 wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() — Linux - - 2026-09-17
CVE-2026-92496 wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() — Linux - - 2026-09-17
CVE-2026-92495 RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap — Linux - - 2026-09-17
CVE-2026-92494 ext4: fix buffer_head leak in ext4_init_orphan_info — Linux - - 2026-09-17
CVE-2026-92493 cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active — Linux - - 2026-09-17
CVE-2026-92492 cpufreq/amd-pstate: handle missing policy in dynamic EPP callbacks — Linux - - 2026-09-17
CVE-2026-92491 firmware: arm_scmi: Roll back partial protocol table registration — Linux - - 2026-09-17
CVE-2026-92490 firmware: arm_scmi: Unrequest devices if driver registration fails — Linux - - 2026-09-17
CVE-2026-92489 xfrm: Fix skb double-free in xfrm_dev_direct_output() — Linux 9.8 Critical 2026-09-17
CVE-2026-92488 RDMA/erdma: complete object teardown when the destroy command fails — Linux 7.0 High 2026-09-17
CVE-2026-92486 bpf: Fix CFI mismatch in task work callback — Linux - - 2026-09-17
CVE-2026-92487 exfat: fix valid_size extension over a shared writable mapping — Linux - - 2026-09-17
CVE-2026-92485 bpf: Fix WARNING in bpf_tracing_link_release — Linux 7.8 High 2026-09-17
CVE-2026-92484 cxl/region: Fix use-after-free in find_pos_and_ways() error path — Linux - - 2026-09-17
CVE-2026-92483 liveupdate: Remember FLB retrieve() status — Linux - - 2026-09-17
CVE-2026-92482 pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip — Linux - - 2026-09-17
CVE-2026-92480 scsi: ufs: core: Validate string descriptors — Linux - - 2026-09-17
CVE-2026-92481 pinctrl: mediatek: free EINT resources on unbind — Linux - - 2026-09-17
CVE-2026-92479 scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags — Linux - - 2026-09-17
CVE-2026-92477 scsi: ufs: debugfs: Reserve space for a string terminator — Linux - - 2026-09-17
CVE-2026-92478 scsi: ufs: core: Validate connected lane counts — Linux - - 2026-09-17
CVE-2026-92476 crypto: keembay - Initialize completion before requesting IRQ — Linux - - 2026-09-17
CVE-2026-90434 isofs: release zisofs block pointer buffer head — Linux - - 2026-09-17
CVE-2026-90435 RDMA/mlx5: Fix integer overflow of user QP buffer size — Linux 7.8 High 2026-09-17
CVE-2026-90433 spi: oc-tiny: switch to managed controller allocation — Linux - - 2026-09-17
CVE-2026-90432 sched_ext: Abort directly from the hardlockup handler — Linux - - 2026-09-17
CVE-2026-90431 remoteproc: Prevent crash handling to race with rproc_del() — Linux - - 2026-09-17
CVE-2026-90430 iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized — Linux - - 2026-09-17

This page lists every published CVE security advisory associated with Linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.