Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Linux — Vulnerabilities & Security Advisories 15166

Browse all 15166 CVE security advisories affecting Linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Linux serves as the foundational operating system for the majority of internet servers, cloud infrastructure, and embedded devices, powering critical global digital services. Its open-source nature and widespread deployment have historically exposed it to diverse vulnerability classes, including remote code execution, buffer overflows, and privilege escalation flaws within kernel modules and system utilities. While the project maintains rigorous security practices, the sheer volume of code contributes to a high cumulative count of recorded Common Vulnerabilities and Exposures, currently exceeding eleven thousand. Notable incidents often stem from misconfigurations or unpatched legacy components rather than fundamental architectural failures. The community responds rapidly to disclosed threats, yet the extensive attack surface necessitates continuous vigilance. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with this ubiquitous platform, ensuring stability across both enterprise and consumer environments.

Found 15026 results / 15166 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-63915 nfc: hci: fix out-of-bounds read in HCP header parsing — Linux 8.8 High 2026-07-19
CVE-2026-63914 xfrm: route MIGRATE notifications to caller's netns — Linux 7.3 High 2026-07-19
CVE-2026-63913 netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check — Linux 8.2 High 2026-07-19
CVE-2026-63912 xfrm: esp: restore combined single-frag length gate — Linux 9.8 Critical 2026-07-19
CVE-2026-63911 xfrm: iptfs: reset runtime state when cloning SAs — Linux 7.8 High 2026-07-19
CVE-2026-63910 dma-buf: fix UAF in dma_buf_fd() tracepoint — Linux 7.8 High 2026-07-19
CVE-2026-63909 ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops — Linux 8.1 High 2026-07-19
CVE-2026-63908 Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem — Linux - - 2026-07-19
CVE-2026-63907 uio: uio_pci_generic_sva: fix double free of devm_kzalloc() memory — Linux - - 2026-07-19
CVE-2026-63906 usb: musb: omap2430: Fix use-after-free in omap2430_probe() — Linux 8.4 High 2026-07-19
CVE-2026-63904 usb: usbtmc: check URB actual_length for interrupt-IN notifications — Linux - - 2026-07-19
CVE-2026-63905 usbip: vudc: Fix use after free bug in vudc_remove due to race condition — Linux - - 2026-07-19
CVE-2026-63903 USB: serial: belkin_sa: validate interrupt status length — Linux - - 2026-07-19
CVE-2026-63902 USB: serial: cypress_m8: validate interrupt packet headers — Linux - - 2026-07-19
CVE-2026-63901 USB: serial: digi_acceleport: fix memory corruption with small endpoints — Linux - - 2026-07-19
CVE-2026-63900 USB: serial: keyspan: fix missing indat transfer sanity check — Linux - - 2026-07-19
CVE-2026-63899 USB: serial: mxuport: fix memory corruption with small endpoint — Linux - - 2026-07-19
CVE-2026-63898 USB: serial: mct_u232: fix memory corruption with small endpoint — Linux - - 2026-07-19
CVE-2026-63897 USB: serial: mct_u232: fix missing interrupt-in transfer sanity check — Linux - - 2026-07-19
CVE-2026-63896 usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling — Linux - - 2026-07-19
CVE-2026-63894 usb: gadget: f_fs: serialize DMABUF cancel against request completion — Linux 7.8 High 2026-07-19
CVE-2026-63895 usb: gadget: f_fs: copy only received bytes on short ep0 read — Linux - - 2026-07-19
CVE-2026-63893 thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() — Linux 8.1 High 2026-07-19
CVE-2026-63892 thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow — Linux - - 2026-07-19
CVE-2026-63891 thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() — Linux - - 2026-07-19
CVE-2026-63890 scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker — Linux - - 2026-07-19
CVE-2026-63889 scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 — Linux 8.1 High 2026-07-19
CVE-2026-63888 scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() — Linux 9.8 Critical 2026-07-19
CVE-2026-63887 scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf — Linux 9.8 Critical 2026-07-19
CVE-2026-63886 scsi: target: iscsi: Validate CHAP_R length before base64 decode — Linux 9.8 Critical 2026-07-19

This page lists every published CVE security advisory associated with Linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.