Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Linux — Vulnerabilities & Security Advisories 17499

Browse all 17499 CVE security advisories affecting Linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Linux serves as the foundational operating system for the majority of internet servers, cloud infrastructure, and embedded devices, powering critical global digital services. Its open-source nature and widespread deployment have historically exposed it to diverse vulnerability classes, including remote code execution, buffer overflows, and privilege escalation flaws within kernel modules and system utilities. While the project maintains rigorous security practices, the sheer volume of code contributes to a high cumulative count of recorded Common Vulnerabilities and Exposures, currently exceeding eleven thousand. Notable incidents often stem from misconfigurations or unpatched legacy components rather than fundamental architectural failures. The community responds rapidly to disclosed threats, yet the extensive attack surface necessitates continuous vigilance. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with this ubiquitous platform, ensuring stability across both enterprise and consumer environments.

CVE ID Title CVSS Severity Published
CVE-2026-98173 smb: client: fix use-after-free of iface in cifs_try_adding_channels() — Linux 7.5 High 2026-10-06
CVE-2026-98174 smb: client: fix rlist race and missing initialization — Linux 7.5 High 2026-10-06
CVE-2026-98172 smb: client: fix smbd_connection leak on cifs_get_tcp_session() error — Linux - - 2026-10-06
CVE-2026-98171 smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs — Linux 8.8 High 2026-10-06
CVE-2026-98170 smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() — Linux - - 2026-10-06
CVE-2026-98169 smb: client: fix potential OOB read in smb3_enum_snapshots() — Linux 7.1 High 2026-10-06
CVE-2026-98168 smb: client: fix reparse buffer bounds in cifs_query_reparse_point() — Linux - - 2026-10-06
CVE-2026-98167 smb: client: fix server->total_read for compound encrypted PDUs — Linux - - 2026-10-06
CVE-2026-98166 drm/ttm: fix swapped-out resources never leaving their bulk_move range — Linux 7.8 High 2026-10-06
CVE-2026-98165 drm/amdgpu: restrict BAR0 fallback read to SR-IOV VFs only — Linux - - 2026-10-06
CVE-2026-98164 KVM: x86/mmu: Check write tracking in all address spaces — Linux 7.1 High 2026-09-29
CVE-2026-98163 cgroup: Avoid iteration of dying tasks with zero refcount — Linux 7.8 High 2026-09-26
CVE-2026-98162 smb/server: fix tree connection leak in smb2_tree_connect() — Linux - - 2026-09-25
CVE-2026-98161 nvdimm: pmem: keep PREFLUSH before data writes — Linux - - 2026-09-25
CVE-2026-98160 staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() — Linux - - 2026-09-25
CVE-2026-100079 usb: typec: ucsi: unregister debugfs entries on teardown — Linux - - 2026-09-25
CVE-2026-100078 wifi: iwlwifi: mei: pass correct argument to function — Linux - - 2026-09-25
CVE-2026-100077 drm/msm: Recover HW before retire hung submit — Linux - - 2026-09-25
CVE-2026-100076 staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths — Linux - - 2026-09-25
CVE-2026-100075 RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters — Linux 9.8 Critical 2026-09-25
CVE-2026-100074 bpf: Mark bpf_refcount field as unique — Linux - - 2026-09-25
CVE-2026-100072 ACPI: platform: Use acpi_bus_get_primary_device() — Linux - - 2026-09-25
CVE-2026-100073 ext4: fix transaction overflow during writeback — Linux - - 2026-09-25
CVE-2026-100071 net: hsr: free learned nodes on device setup failure — Linux - - 2026-09-25
CVE-2026-100070 netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet — Linux - - 2026-09-25
CVE-2026-98159 wifi: mt76: mt7921: validate CLC firmware records — Linux - - 2026-09-25
CVE-2026-98158 ppp_async: drop the errored frame instead of resetting its headroom — Linux - - 2026-09-25
CVE-2026-98157 EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation — Linux - - 2026-09-25
CVE-2026-98156 drm/virtio: use the DMA API for resource backing on Xen — Linux 7.8 High 2026-09-25
CVE-2026-98155 accel/qaic: Address potential out-of-bounds read in resp_worker() — Linux - - 2026-09-25

This page lists every published CVE security advisory associated with Linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.