VulnSea

Linux has 2,768 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 1706 in the last 90 days against 308 in the 90 before. The busiest recent month was September 2026 with 1571. The median CVSS is 7.8 (high), with 153 rated critical. 0% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 255 days (6 cases). The dominant weakness classes are CWE-416 (154) and CWE-476 (112). Most affected products: Linux (1902), linux_kernel (866).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
255 d median(6)
Last 90 days
1706 prev 308

Products

  • Linux 1902
  • linux_kernel 866
2768
Total CVEs
153
Critical
6
CISA KEV
6
Exploited

linux vulnerabilities

CVEs affecting linux, newest first. Open any entry for full detail, references, and exploit status.

2768 CVEsRSS

CVE-2025-71114None
8mo ago

via_wdt: fix critical boot hang due to unnamed resource allocation

In the Linux kernel, the following vulnerability has been resolved: via_wdt: fix critical boot hang due to unnamed resource allocation The VIA watchdog driver uses allocate_resource() to reserve a MMIO region for the watchdog control r…

▾ SunlitLinux · LinuxEPSS 0.14%via CVEORG
CVE-2025-71113None
8mo ago

crypto: af_alg - zero initialize memory allocated via sock_kmalloc

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - zero initialize memory allocated via sock_kmalloc Several crypto user API contexts and requests allocated with sock_kmalloc() were left uninitialized,…

▾ SunlitLinux · LinuxEPSS 0.14%via CVEORG
CVE-2025-71112High· 8.8
8mo ago

net: hns3: add VLAN id validation before using

In the Linux kernel, the following vulnerability has been resolved: net: hns3: add VLAN id validation before using Currently, the VLAN id may be used without validation when receive a VLAN configuration mailbox from VF. The length of v…

▾ TwilightLinux · LinuxEPSS 0.15%via CVEORG
CVE-2025-71104None
8mo ago

KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer When advancing the target expiration for the guest's APIC timer in periodic mode, set th…

▾ SunlitLinux · LinuxEPSS 0.11%via CVEORG
CVE-2025-71131High· 7.5
8mo ago

crypto: seqiv - Do not use req->iv after crypto_aead_encrypt

In the Linux kernel, the following vulnerability has been resolved: crypto: seqiv - Do not use req->iv after crypto_aead_encrypt As soon as crypto_aead_encrypt is called, the underlying request may be freed by an asynchronous completio…

▾ TwilightLinux · LinuxEPSS 0.28%via CVEORG
CVE-2025-71098None
8mo ago

ip6_gre: make ip6gre_header() robust

In the Linux kernel, the following vulnerability has been resolved: ip6_gre: make ip6gre_header() robust Over the years, syzbot found many ways to crash the kernel in ip6gre_header() [1]. This involves team or bonding drivers ability …

▾ SunlitLinux · LinuxEPSS 0.13%via CVEORG
CVE-2025-71097None
8mo ago

ipv4: Fix reference count leak when using error routes with nexthop objects

In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix reference count leak when using error routes with nexthop objects When a nexthop object is deleted, it is marked as dead and then fib_table_flush() is called…

▾ SunlitLinux · LinuxEPSS 0.13%via CVEORG
CVE-2025-71095Critical· 9.1
8mo ago

net: stmmac: fix the crash issue for zero copy XDP_TX action

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix the crash issue for zero copy XDP_TX action There is a crash issue when running zero copy XDP_TX action, the crash log is shown below. [ 216.122464]…

▾ MidnightLinux · LinuxEPSS 0.28%via CVEORG
CVE-2025-71088None
8mo ago

mptcp: fallback earlier on simult connection

In the Linux kernel, the following vulnerability has been resolved: mptcp: fallback earlier on simult connection Syzkaller reports a simult-connect race leading to inconsistent fallback status: WARNING: CPU: 3 PID: 33 at net/mptcp/s…

▾ SunlitLinux · LinuxEPSS 0.14%via CVEORG
CVE-2025-71086None
8mo ago

net: rose: fix invalid array index in rose_kill_by_device()

In the Linux kernel, the following vulnerability has been resolved: net: rose: fix invalid array index in rose_kill_by_device() rose_kill_by_device() collects sockets into a local array[] and then iterates over them to disconnect socke…

▾ SunlitLinux · LinuxEPSS 0.14%via CVEORG
CVE-2025-71085High· 7.5
8mo ago

ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()

In the Linux kernel, the following vulnerability has been resolved: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() There exists a kernel oops caused by a BUG_ON(nhead < 0) at net/core/skbuff.c:2232 in pskb_expand…

▾ TwilightLinux · LinuxEPSS 0.28%via CVEORG
CVE-2025-71079None
8mo ago

net: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write

In the Linux kernel, the following vulnerability has been resolved: net: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write A deadlock can occur between nfc_unregister_device() and rfkill_fop_write() due to lock order…

▾ SunlitLinux · LinuxEPSS 0.10%via CVEORG
CVE-2025-71075None
8mo ago

scsi: aic94xx: fix use-after-free in device removal path

In the Linux kernel, the following vulnerability has been resolved: scsi: aic94xx: fix use-after-free in device removal path The asd_pci_remove() function fails to synchronize with pending tasklets before freeing the asd_ha structure, …

▾ SunlitLinux · LinuxEPSS 0.15%via CVEORG
CVE-2025-71064None
8mo ago

net: hns3: using the num_tqps in the vf driver to apply for resources

In the Linux kernel, the following vulnerability has been resolved: net: hns3: using the num_tqps in the vf driver to apply for resources Currently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp is allocated using kinfo-…

▾ SunlitLinux · LinuxEPSS 0.21%via CVEORG
CVE-2025-68820None
8mo ago

ext4: xattr: fix null pointer deref in ext4_raw_inode()

In the Linux kernel, the following vulnerability has been resolved: ext4: xattr: fix null pointer deref in ext4_raw_inode() If ext4_get_inode_loc() fails (e.g. if it returns -EFSCORRUPTED), iloc.bh will remain set to NULL. Since ext4_x…

▾ SunlitLinux · LinuxEPSS 0.21%via CVEORG
CVE-2025-68818High· 8.8
8mo ago

scsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path"

In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path" This reverts commit 0367076b0817d5c75dfb83001ce7ce5c64d803a9. The commit being reverte…

▾ TwilightLinux · LinuxEPSS 0.29%via CVEORG
CVE-2025-68816None
8mo ago

net/mlx5: fw_tracer, Validate format string parameters

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, Validate format string parameters Add validation for format string parameters in the firmware tracer to prevent potential security vulnerabilities…

▾ SunlitLinux · LinuxEPSS 0.21%via CVEORG
CVE-2025-68814None
8mo ago

io_uring: fix filename leak in __io_openat_prep()

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix filename leak in __io_openat_prep() __io_openat_prep() allocates a struct filename using getname(). However, for the condition of the file being install…

▾ SunlitLinux · LinuxEPSS 0.21%via CVEORG
CVE-2025-68803High· 8.0
8mo ago

NFSD: NFSv4 file creation neglects setting ACL

In the Linux kernel, the following vulnerability has been resolved: NFSD: NFSv4 file creation neglects setting ACL An NFSv4 client that sets an ACL with a named principal during file creation retrieves the ACL afterwards, and finds tha…

▾ TwilightLinux · LinuxEPSS 0.44%via CVEORG
CVE-2025-68798None
8mo ago

perf/x86/amd: Check event before enable to avoid GPF

In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd: Check event before enable to avoid GPF On AMD machines cpuc->events[idx] can become NULL in a subtle race condition with NMI->throttle->x86_pmu_stop(). …

▾ SunlitLinux · LinuxEPSS 0.20%via CVEORG
CVE-2025-68788None
8mo ago

fsnotify: do not generate ACCESS/MODIFY events on child for special files

In the Linux kernel, the following vulnerability has been resolved: fsnotify: do not generate ACCESS/MODIFY events on child for special files inotify/fanotify do not allow users with no read access to a file to subscribe to events (e.g…

▾ SunlitLinux · LinuxEPSS 0.21%via CVEORG
CVE-2025-68787None
8mo ago

netrom: Fix memory leak in nr_sendmsg()

In the Linux kernel, the following vulnerability has been resolved: netrom: Fix memory leak in nr_sendmsg() syzbot reported a memory leak [1]. When function sock_alloc_send_skb() return NULL in nr_output(), the original skb is not fre…

▾ SunlitLinux · LinuxEPSS 0.21%via CVEORG
CVE-2025-68782High· 7.5
8mo ago

scsi: target: Reset t_task_cdb pointer in error case

In the Linux kernel, the following vulnerability has been resolved: scsi: target: Reset t_task_cdb pointer in error case If allocation of cmd->t_task_cdb fails, it remains NULL but is later dereferenced in the 'err' path. In case of e…

▾ TwilightLinux · LinuxEPSS 0.59%via CVEORG
CVE-2025-68776None
8mo ago

net/hsr: fix NULL pointer dereference in prp_get_untagged_frame()

In the Linux kernel, the following vulnerability has been resolved: net/hsr: fix NULL pointer dereference in prp_get_untagged_frame() prp_get_untagged_frame() calls __pskb_copy() to create frame->skb_std but doesn't check if the alloca…

▾ SunlitLinux · LinuxEPSS 0.21%via CVEORG
CVE-2025-68773None
8mo ago

spi: fsl-cpm: Check length parity before switching to 16 bit mode

In the Linux kernel, the following vulnerability has been resolved: spi: fsl-cpm: Check length parity before switching to 16 bit mode Commit fc96ec826bce ("spi: fsl-cpm: Use 16 bit mode for large transfers with even size") failed to ma…

▾ SunlitLinux · LinuxEPSS 0.21%via CVEORG
CVE-2025-68764High· 7.8
8mo ago

NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags

In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags When a filesystem is being automounted, it needs to preserve the user-set superblock mount optio…

▾ TwilightLinux · LinuxEPSS 0.15%via CVEORG
CVE-2023-54237Critical· 9.8
9mo ago

net/smc: fix potential panic dues to unprotected smc_llc_srv_add_link()

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix potential panic dues to unprotected smc_llc_srv_add_link() There is a certain chance to trigger the following panic: PID: 5900 TASK: ffff88c1c8af4100 …

▾ MidnightLinux · LinuxEPSS 0.55%via CVEORG
CVE-2025-68371None
9mo ago

scsi: smartpqi: Fix device resources accessed after device removal

In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Fix device resources accessed after device removal Correct possible race conditions during device removal. Previously, a scheduled work item to reset …

▾ SunlitLinux · LinuxEPSS 0.19%via CVEORG
CVE-2025-68363None
9mo ago

bpf: Check skb->transport_header is set in bpf_skb_check_mtu

In the Linux kernel, the following vulnerability has been resolved: bpf: Check skb->transport_header is set in bpf_skb_check_mtu The bpf_skb_check_mtu helper needs to use skb->transport_header when the BPF_MTU_CHK_SEGS flag is used: …

▾ SunlitLinux · LinuxEPSS 0.21%via CVEORG
CVE-2025-68725None
9mo ago

bpf: Do not let BPF test infra emit invalid GSO types to stack

In the Linux kernel, the following vulnerability has been resolved: bpf: Do not let BPF test infra emit invalid GSO types to stack Yinhao et al. reported that their fuzzer tool was able to trigger a skb_warn_bad_offload() from netif_sk…

▾ SunlitLinux · LinuxEPSS 0.18%via CVEORG
linux vulnerabilities (CVEs) — page 71 · VulnSea