Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

linux — Vulnerabilities & Security Advisories 13564

Browse all 13564 CVE security advisories affecting linux. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Linux serves as the foundational operating system for the majority of internet servers, cloud infrastructure, and embedded devices, powering critical global digital services. Its open-source nature and widespread deployment have historically exposed it to diverse vulnerability classes, including remote code execution, buffer overflows, and privilege escalation flaws within kernel modules and system utilities. While the project maintains rigorous security practices, the sheer volume of code contributes to a high cumulative count of recorded Common Vulnerabilities and Exposures, currently exceeding eleven thousand. Notable incidents often stem from misconfigurations or unpatched legacy components rather than fundamental architectural failures. The community responds rapidly to disclosed threats, yet the extensive attack surface necessitates continuous vigilance. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with this ubiquitous platform, ensuring stability across both enterprise and consumer environments.

CVE IDTitleCVSSSeverityPublished
CVE-2025-40182 crypto: skcipher - Fix reqsize handling — Linux 7.8 High2025-11-12
CVE-2025-40181 x86/kvm: Force legacy PCI hole to UC when overriding MTRRs for TDX/SNP — Linux 7.8 -2025-11-12
CVE-2025-40179 ext4: verify orphan file size is not too big — Linux 5.5 -2025-11-12
CVE-2025-40180 mailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox cleanup loop — Linux 7.1 -2025-11-12
CVE-2025-40178 pid: Add a judgment for ns null in pid_nr_ns — Linux 5.5 -2025-11-12
CVE-2025-40177 accel/qaic: Fix bootlog initialization ordering — Linux 6.3 -2025-11-12
CVE-2025-40174 x86/mm: Fix SMP ordering in switch_mm_irqs_off() — Linux 7.8 High2025-11-12
CVE-2025-40175 idpf: cleanup remaining SKBs in PTP flows — Linux 7.1 -2025-11-12
CVE-2025-40176 tls: wait for pending async decryptions if tls_strp_msg_hold fails — Linux 9.8 Critical2025-11-12
CVE-2025-40173 net/ip6_tunnel: Prevent perpetual tunnel growth — Linux 7.8 High2025-11-12
CVE-2025-40172 accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages() — Linux 7.8 High2025-11-12
CVE-2025-40171 nvmet-fc: move lsop put work to nvmet_fc_ls_req_op — Linux 7.5 High2025-11-12
CVE-2025-40169 bpf: Reject negative offsets for ALU ops — Linux 7.8 High2025-11-12
CVE-2025-40170 net: use dst_dev_rcu() in sk_setup_caps() — Linux 7.8 High2025-11-12
CVE-2025-40168 smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). — Linux 8.1 High2025-11-12
CVE-2025-40167 ext4: detect invalid INLINE_DATA + EXTENTS flag combination — Linux 7.8 High2025-11-12
CVE-2025-40166 drm/xe/guc: Check GuC running state before deregistering exec queue — Linux 7.8 High2025-11-12
CVE-2025-40165 media: nxp: imx8-isi: m2m: Fix streaming cleanup on release — Linux 7.8 High2025-11-12
CVE-2025-40163 sched/deadline: Stop dl_server before CPU goes offline — Linux 5.5 -2025-11-12
CVE-2025-40162 ASoC: amd/sdw_utils: avoid NULL deref when devm_kasprintf() fails — Linux 5.5 -2025-11-12
CVE-2025-40164 usbnet: Fix using smp_processor_id() in preemptible code warnings — Linux 7.1 -2025-11-12
CVE-2025-40161 mailbox: zynqmp-ipi: Fix SGI cleanup on unbind — Linux 5.5 -2025-11-12
CVE-2025-40160 xen/events: Return -EEXIST for bound VIRQs — Linux 5.5 -2025-11-12
CVE-2025-40159 xsk: Harden userspace-supplied xdp_desc validation — Linux 7.8 High2025-11-12
CVE-2025-40158 ipv6: use RCU in ip6_output() — Linux 8.1 High2025-11-12
CVE-2025-40156 PM / devfreq: mtk-cci: Fix potential error pointer dereference in probe() — Linux 5.5 -2025-11-12
CVE-2025-40155 iommu/vt-d: debugfs: Fix legacy mode page table dump logic — Linux 7.3 High2025-11-12
CVE-2025-40157 EDAC/i10nm: Skip DIMM enumeration on a disabled memory controller — Linux 7.1 -2025-11-12
CVE-2025-40153 mm: hugetlb: avoid soft lockup when mprotect to large memory area — Linux 5.5 -2025-11-12
CVE-2025-40151 LoongArch: BPF: No support of struct argument in trampoline programs — Linux 7.8 High2025-11-12

This page lists every published CVE security advisory associated with linux. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.