VulnSea

Linux has 2,768 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 1706 in the last 90 days against 308 in the 90 before. The busiest recent month was September 2026 with 1571. The median CVSS is 7.8 (high), with 153 rated critical. 0% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 255 days (6 cases). The dominant weakness classes are CWE-416 (154) and CWE-476 (112). Most affected products: Linux (1902), linux_kernel (866).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
255 d median(6)
Last 90 days
1706 prev 308

Products

  • Linux 1902
  • linux_kernel 866
2768
Total CVEs
153
Critical
6
CISA KEV
6
Exploited

linux vulnerabilities

CVEs affecting linux, newest first. Open any entry for full detail, references, and exploit status.

2768 CVEsRSS

CVE-2025-71197None
7mo ago

w1: therm: Fix off-by-one buffer overflow in alarms_store

In the Linux kernel, the following vulnerability has been resolved: w1: therm: Fix off-by-one buffer overflow in alarms_store The sysfs buffer passed to alarms_store() is allocated with 'size + 1' bytes and a NUL terminator is appended…

▾ SunlitLinux · LinuxEPSS 0.21%via CVEORG
CVE-2026-23110None
7mo ago

scsi: core: Wake up the error handler when final completions race against each other

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Wake up the error handler when final completions race against each other The fragile ordering between marking commands completed or failed so that the erro…

▾ SunlitLinux · LinuxEPSS 0.10%via CVEORG
CVE-2026-23100None
7mo ago

mm/hugetlb: fix hugetlb_pmd_shared()

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb_pmd_shared() Patch series "mm/hugetlb: fixes for PMD table sharing (incl. using mmu_gather)", v3. One functional fix, one performance regress…

▾ SunlitLinux · LinuxEPSS 0.13%via CVEORG
CVE-2026-23095High· 7.5
7mo ago

gue: Fix skb memleak with inner IP protocol 0.

In the Linux kernel, the following vulnerability has been resolved: gue: Fix skb memleak with inner IP protocol 0. syzbot reported skb memleak below. [0] The repro generated a GUE packet with its inner protocol 0. gue_udp_recv() retu…

▾ TwilightLinux · LinuxEPSS 0.25%via CVEORG
CVE-2026-23086None
7mo ago

vsock/virtio: cap TX credit to local buffer size

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: cap TX credit to local buffer size The virtio transports derives its TX credit directly from peer_buf_alloc, which is set from the remote endpoint's SO_V…

▾ SunlitLinux · LinuxEPSS 0.15%via CVEORG
CVE-2026-23074High· 7.8
7mo ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: Enforce that teql can only be used as root qdisc Design intent of teql is that it is only supposed to be used as root qdisc. We need to check for that const…

In the Linux kernel, the following vulnerability has been resolved: net/sched: Enforce that teql can only be used as root qdisc Design intent of teql is that it is only supposed to be used as root qdisc. We need to check for that const…

▾ Twilightlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-23038None
8mo ago

pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node()

In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() In nfs4_ff_alloc_deviceid_node(), if the allocation for ds_versions fails, the function jumps to the o…

▾ SunlitLinux · LinuxEPSS 0.26%via CVEORG
CVE-2026-23026None
8mo ago

dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config()

In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config() Fix a memory leak in gpi_peripheral_config() where the original memory pointed to by gchan->config cou…

▾ SunlitLinux · LinuxEPSS 0.19%via CVEORG
CVE-2026-23019None
8mo ago

net: marvell: prestera: fix NULL dereference on devlink_alloc() failure

In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix NULL dereference on devlink_alloc() failure devlink_alloc() may return NULL on allocation failure, but prestera_devlink_alloc() uncondition…

▾ SunlitLinux · LinuxEPSS 0.12%via CVEORG
CVE-2025-71191None
8mo ago

dmaengine: at_hdmac: fix device leak on of_dma_xlate()

In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_hdmac: fix device leak on of_dma_xlate() Make sure to drop the reference taken when looking up the DMA platform device during of_dma_xlate() when releasi…

▾ SunlitLinux · LinuxEPSS 0.20%via CVEORG
CVE-2025-71190None
8mo ago

dmaengine: bcm-sba-raid: fix device leak on probe

In the Linux kernel, the following vulnerability has been resolved: dmaengine: bcm-sba-raid: fix device leak on probe Make sure to drop the reference taken when looking up the mailbox device during probe on probe failures and on driver…

▾ SunlitLinux · LinuxEPSS 0.20%via CVEORG
CVE-2025-71189None
8mo ago

dmaengine: dw: dmamux: fix OF node leak on route allocation failure

In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw: dmamux: fix OF node leak on route allocation failure Make sure to drop the reference taken to the DMA master OF node also on late route allocation failu…

▾ SunlitLinux · LinuxEPSS 0.19%via CVEORG
CVE-2025-71186None
8mo ago

dmaengine: stm32: dmamux: fix device leak on route allocation

In the Linux kernel, the following vulnerability has been resolved: dmaengine: stm32: dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation…

▾ SunlitLinux · LinuxEPSS 0.20%via CVEORG
CVE-2025-71185None
8mo ago

dmaengine: ti: dma-crossbar: fix device leak on am335x route allocation

In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: dma-crossbar: fix device leak on am335x route allocation Make sure to drop the reference taken when looking up the crossbar platform device during am335…

▾ SunlitLinux · LinuxEPSS 0.20%via CVEORG
CVE-2026-23011None
8mo ago

ipv4: ip_gre: make ipgre_header() robust

In the Linux kernel, the following vulnerability has been resolved: ipv4: ip_gre: make ipgre_header() robust Analog to commit db5b4e39c4e6 ("ip6_gre: make ip6gre_header() robust") Over the years, syzbot found many ways to crash the ke…

▾ SunlitLinux · LinuxEPSS 0.21%via CVEORG
CVE-2026-23010High· 7.8PoC
8mo ago

ipv6: Fix use-after-free in inet6_addr_del().

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix use-after-free in inet6_addr_del(). syzbot reported use-after-free of inet6_ifaddr in inet6_addr_del(). [0] The cited commit accidentally moved ipv6_del_add…

▾ MidnightLinux · LinuxEPSS 0.20%via CVEORG
CVE-2026-23005NonePoC
8mo ago

x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1

In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1 When loading guest XSAVE state via KVM_SET_XSAVE, and when updating XFD in response to a guest WRMSR…

▾ TwilightLinux · LinuxEPSS 0.22%via CVEORG
CVE-2026-23003High· 7.5PoC
8mo ago

ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv()

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() Blamed commit did not take care of VLAN encapsulations as spotted by syzbot [1]. Use skb_vlan_inet_prepare(…

▾ MidnightLinux · LinuxEPSS 0.52%via CVEORG
CVE-2025-71163None
8mo ago

dmaengine: idxd: fix device leaks on compat bind and unbind

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix device leaks on compat bind and unbind Make sure to drop the reference taken when looking up the idxd device as part of the compat bind and unbind…

▾ SunlitLinux · LinuxEPSS 0.21%via CVEORG
CVE-2025-71162High· 7.8
8mo ago

dmaengine: tegra-adma: Fix use-after-free

In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-after-free A use-after-free bug exists in the Tegra ADMA driver when audio streams are terminated, particularly during XRUN conditions. …

▾ TwilightLinux · LinuxEPSS 0.21%via CVEORG
CVE-2026-22994None
8mo ago

bpf: Fix reference count leak in bpf_prog_test_run_xdp()

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix reference count leak in bpf_prog_test_run_xdp() syzbot is reporting unregister_netdevice: waiting for sit0 to become free. Usage count = 2 problem. A debu…

▾ SunlitLinux · LinuxEPSS 0.14%via CVEORG
CVE-2026-22992High· 7.5
8mo ago

libceph: return the handler error from mon_handle_auth_done()

In the Linux kernel, the following vulnerability has been resolved: libceph: return the handler error from mon_handle_auth_done() Currently any error from ceph_auth_handle_reply_done() is propagated via finish_auth() but isn't returned…

▾ TwilightLinux · LinuxEPSS 0.32%via CVEORG
CVE-2026-22982None
8mo ago

net: mscc: ocelot: Fix crash when adding interface under a lag

In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: Fix crash when adding interface under a lag Commit 15faa1f67ab4 ("lan966x: Fix crash when adding interface under a lag") fixed a similar issue in th…

▾ SunlitLinux · LinuxEPSS 0.14%via CVEORG
CVE-2026-22980High· 7.8
8mo ago

nfsd: provide locking for v4_end_grace

In the Linux kernel, the following vulnerability has been resolved: nfsd: provide locking for v4_end_grace Writing to v4_end_grace can race with server shutdown and result in memory being accessed after it was freed - reclaim_str_hasht…

▾ TwilightLinux · LinuxEPSS 0.15%via CVEORG
CVE-2026-22979None
8mo ago

net: fix memory leak in skb_segment_list for GRO packets

In the Linux kernel, the following vulnerability has been resolved: net: fix memory leak in skb_segment_list for GRO packets When skb_segment_list() is called during packet forwarding, it handles packets that were aggregated by the GRO…

▾ SunlitLinux · LinuxEPSS 0.14%via CVEORG
CVE-2025-71161High· 7.5
8mo ago

dm-verity: disable recursive forward error correction

In the Linux kernel, the following vulnerability has been resolved: dm-verity: disable recursive forward error correction There are two problems with the recursive correction: 1. It may cause denial-of-service. In fec_read_bufs, there…

▾ TwilightLinux · LinuxEPSS 0.38%via CVEORG
CVE-2026-22977None
8mo ago

net: sock: fix hardened usercopy panic in sock_recv_errqueue

In the Linux kernel, the following vulnerability has been resolved: net: sock: fix hardened usercopy panic in sock_recv_errqueue skbuff_fclone_cache was created without defining a usercopy region, [1] unlike skbuff_head_cache which pro…

▾ SunlitLinux · LinuxEPSS 0.14%via CVEORG
CVE-2025-71142None
8mo ago

cpuset: fix warning when disabling remote partition

In the Linux kernel, the following vulnerability has been resolved: cpuset: fix warning when disabling remote partition A warning was triggered as follows: WARNING: kernel/cgroup/cpuset.c:1651 at remote_partition_disable+0xf7/0x110 RI…

▾ SunlitLinux · LinuxEPSS 0.13%via CVEORG
CVE-2025-71123None
8mo ago

ext4: fix string copying in parse_apply_sb_mount_options()

In the Linux kernel, the following vulnerability has been resolved: ext4: fix string copying in parse_apply_sb_mount_options() strscpy_pad() can't be used to copy a non-NUL-term string into a NUL-term string of possibly bigger size. C…

▾ SunlitLinux · LinuxEPSS 0.17%via CVEORG
CVE-2025-71120High· 7.5
8mo ago

SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf A zero length gss_token results in pages == 0 and in_token->pages[0] is NULL. The…

▾ TwilightLinux · LinuxEPSS 0.48%via CVEORG
linux vulnerabilities (CVEs) — page 70 · VulnSea