Linux kernel
This hub aggregates every CVE we track for Linux kernel, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
20,455
CVEs tracked
940
Critical
7,902
High
36
In CISA KEV
Severity distribution
MEDIUM8,538HIGH7,902CRITICAL940LOW435
Monthly trend
415
280
356
229
910
207
280
551
376
404
188
738
651
104
1056
246
222
178
377
1029
513
836
1644
1741
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Linux kernel.
- CVE-2026-97521gfs2: fix quota init duplicate scan
- CVE-2026-97520gfs2: move quota_init qc iterator increment
- CVE-2026-97519drm/xe: Fix null pointer dereference in devcoredump cleanup
- CVE-2026-97518wifi: cfg80211: reject duplicate wiphy cipher suite entries
- CVE-2026-97517wifi: nl80211: reject beacons with bad HE operation
- CVE-2026-97516wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result()
- CVE-2026-97515i3c: master: svc: Prevent IRQ storm from false SLVSTART on NPCM845
- CVE-2026-97514media: chips-media: wave5: Fix Reports from Kernel Lock Validator
- CVE-2026-97513media: chips-media: wave5: Release m2m_ctx after Instance Removed from List
- CVE-2026-97512spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM
- CVE-2026-97511wifi: mac80211: avoid out-of-bounds access in monitor
- CVE-2026-97510thunderbolt: Release request if tb_cfg_request() fails in __tb_xdomain_response()
- CVE-2026-97509thunderbolt: Keep XDomain reference during the lifetime of a service
- CVE-2026-97508thunderbolt: Set tb->root_switch to NULL when domain is stopped
- CVE-2026-97507media: dm1105: fix missing error check for dma_alloc_coherent
Product normalization is registry-driven with AI assist and human review. How it works