Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Linux — Vulnerabilities & Security Advisories 11132

Browse all 11132 CVE security advisories affecting Linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2026-23009 xhci: sideband: don't dereference freed ring when removing sideband endpoint — Linux 5.5 -2026-01-25
CVE-2026-23008 drm/vmwgfx: Fix KMS with 3D on HW version 10 — Linux 5.5 -2026-01-25
CVE-2026-23007 block: zero non-PI portion of auto integrity buffer — Linux 6.1 -2026-01-25
CVE-2026-23006 ASoC: tlv320adcx140: fix null pointer — Linux 5.5 -2026-01-25
CVE-2026-23005 x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1 — Linux 5.5 -2026-01-25
CVE-2026-23004 dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() — Linux 4.7 -2026-01-25
CVE-2026-23003 ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() — Linux 7.1 -2026-01-25
CVE-2026-23002 lib/buildid: use __kernel_read() for sleepable context — Linux 7.1 -2026-01-25
CVE-2026-23001 macvlan: fix possible UAF in macvlan_forward_source() — Linux 7.8 -2026-01-25
CVE-2026-23000 net/mlx5e: Fix crash on profile change rollback failure — Linux 5.5 -2026-01-25
CVE-2026-22999 net/sched: sch_qfq: do not free existing class in qfq_change_class() — Linux 7.8 -2026-01-25
CVE-2026-22998 nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec — Linux 6.5 -2026-01-25
CVE-2026-22997 net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session upon receiving the second rts — Linux--2026-01-25
CVE-2026-22996 net/mlx5e: Don't store mlx5e_priv in mlx5e_dev devlink priv — Linux 7.1 -2026-01-25
CVE-2025-71163 dmaengine: idxd: fix device leaks on compat bind and unbind — Linux 5.5 -2026-01-25
CVE-2025-71162 dmaengine: tegra-adma: Fix use-after-free — Linux 6.3 -2026-01-25
CVE-2026-22995 ublk: fix use-after-free in ublk_partition_scan_work — Linux 7.0 -2026-01-23
CVE-2026-22994 bpf: Fix reference count leak in bpf_prog_test_run_xdp() — Linux 7.1 -2026-01-23
CVE-2026-22993 idpf: Fix RSS LUT NULL ptr issue after soft reset — Linux 8.1 -2026-01-23
CVE-2026-22992 libceph: return the handler error from mon_handle_auth_done() — Linux 6.5 -2026-01-23
CVE-2026-22991 libceph: make free_choose_arg_map() resilient to partial allocation — Linux 7.1 -2026-01-23
CVE-2026-22989 nfsd: check that server is running in unlock_filesystem — Linux 6.5 -2026-01-23
CVE-2026-22990 libceph: replace overzealous BUG_ON in osdmap_apply_incremental() — Linux 7.1 -2026-01-23
CVE-2026-22988 arp: do not assume dev_hard_header() does not change skb->head — Linux 7.1 -2026-01-23
CVE-2026-22987 net/sched: act_api: avoid dereferencing ERR_PTR in tcf_idrinfo_destroy — Linux 6.5 -2026-01-23
CVE-2026-22986 gpiolib: fix race condition for gdev->srcu — Linux 6.3 -2026-01-23
CVE-2026-22985 idpf: Fix RSS LUT NULL pointer crash on early ethtool operations — Linux 5.5 -2026-01-23
CVE-2026-22984 libceph: prevent potential out-of-bounds reads in handle_auth_done() — Linux 8.8 -2026-01-23
CVE-2026-22982 net: mscc: ocelot: Fix crash when adding interface under a lag — Linux 5.5 -2026-01-23
CVE-2026-22983 net: do not write to msg_get_inq in callee — Linux 7.8 -2026-01-23

This page lists every published CVE security advisory associated with Linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.