Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Linux — Vulnerabilities & Security Advisories 17499

Browse all 17499 CVE security advisories affecting Linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Linux serves as the foundational operating system for the majority of internet servers, cloud infrastructure, and embedded devices, powering critical global digital services. Its open-source nature and widespread deployment have historically exposed it to diverse vulnerability classes, including remote code execution, buffer overflows, and privilege escalation flaws within kernel modules and system utilities. While the project maintains rigorous security practices, the sheer volume of code contributes to a high cumulative count of recorded Common Vulnerabilities and Exposures, currently exceeding eleven thousand. Notable incidents often stem from misconfigurations or unpatched legacy components rather than fundamental architectural failures. The community responds rapidly to disclosed threats, yet the extensive attack surface necessitates continuous vigilance. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with this ubiquitous platform, ensuring stability across both enterprise and consumer environments.

CVE ID Title CVSS Severity Published
CVE-2026-90428 iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs — Linux - - 2026-09-17
CVE-2026-90429 iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init — Linux 7.8 High 2026-09-17
CVE-2026-90427 iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc() — Linux 7.4 High 2026-09-17
CVE-2026-90425 iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID — Linux 8.8 High 2026-09-17
CVE-2026-90426 iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs — Linux - - 2026-09-17
CVE-2026-90424 iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path — Linux - - 2026-09-17
CVE-2026-90423 RDMA/rxe: Fix UAF in ODP init error-handling path — Linux 7.8 High 2026-09-17
CVE-2026-90422 clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path — Linux - - 2026-09-17
CVE-2026-90420 nilfs2: fix infinite loop in nilfs_clean_segments() — Linux - - 2026-09-17
CVE-2026-90421 PCI: Fix UAF when probe runs concurrent to dyn ID removal — Linux - - 2026-09-17
CVE-2026-90419 nilfs2: prevent out-of-bounds read in super root block parsing — Linux 7.1 High 2026-09-17
CVE-2026-90418 nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch — Linux - - 2026-09-17
CVE-2026-90417 RDMA/cxgb4: Fix dereg_skb leak and double free in write_tpt_entry() — Linux - - 2026-09-17
CVE-2026-90416 RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs — Linux - - 2026-09-17
CVE-2026-90415 RDMA/cxgb4: free STAG index when TPT entry write fails — Linux - - 2026-09-17
CVE-2026-90414 IB/isert: reject PDUs declaring more data than was received — Linux 9.1 Critical 2026-09-17
CVE-2026-90412 nvmet: fix return status of RMI log page on allocation failure — Linux - - 2026-09-17
CVE-2026-90413 IB/isert: reject login PDUs declaring more data than was received — Linux 9.1 Critical 2026-09-17
CVE-2026-90411 nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request — Linux - - 2026-09-17
CVE-2026-90409 drm/panthor: Add vm_bind region with kbo range overlap check — Linux - - 2026-09-17
CVE-2026-90410 spi: davinci: switch to managed controller allocation — Linux - - 2026-09-17
CVE-2026-90408 wifi: ath12k: fix overreads in ath12k_wmi_process_csa_switch_count_event() — Linux 7.7 High 2026-09-17
CVE-2026-90407 wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() — Linux 7.7 High 2026-09-17
CVE-2026-90406 media: qcom: iris: handle runtime PM resume failure in core deinit — Linux - - 2026-09-17
CVE-2026-90405 media: stm32: dcmi: fix some error handling bugs in probe() — Linux - - 2026-09-17
CVE-2026-90404 platform/chrome: cros_ec_debugfs: Unregister panic notifier — Linux - - 2026-09-17
CVE-2026-90403 wifi: rtlwifi: pci: fix error path in rtl_pci_probe() — Linux 7.0 High 2026-09-17
CVE-2026-90402 bus: mhi: host: Fix controller cleanup on EDL sysfs failure — Linux 7.0 High 2026-09-17
CVE-2026-90401 md: remove REQ_NOWAIT support from raid1/10/456 — Linux 7.1 High 2026-09-17
CVE-2026-90400 md: recheck spare changes before starting sync — Linux - - 2026-09-17

This page lists every published CVE security advisory associated with Linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.