Linux Kernel CVE Tracker

18,243 vulnerabilities indexed - updated daily from NIST NVD

LinuxCVETracker is a free, searchable database of 18,243 Linux kernel CVEs, sourced daily from the NIST National Vulnerability Database and the CISA Known Exploited Vulnerabilities catalog. Of these, 537 are rated Critical severity and 28 have been confirmed as actively exploited. Use it to search, filter, and monitor Linux kernel security vulnerabilities by severity, year, affected package, or exploitation status.

CVE Statistics

18,243
Total CVEs
537
Critical
5,847
High
28
KEV - Actively Exploited

Linux Kernel CVE Database

All time 2026 2025 2024 2023 2022 2021 2020 2019 2018 2017 2016 2015 2014 2013 2012 2011 2010 2009 2008 2007 2006 2005 2004 2003 2002 2001 2000 1999 1998
18,243 vulnerabilities
Page 1 of 913
CVE ID Package Severity CVSS Published Description
CVE-2026-80925 linux Awaiting NVD 2026-09-09 In the Linux kernel, the following vulnerability has been resolved: vlan: fix skb_under_panic and races when toggling H…
CVE-2026-80924 linux High 7.5 2026-09-09 In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - use kfree_sensitive() for derived ke…
CVE-2026-80923 linux Awaiting NVD 2026-09-09 In the Linux kernel, the following vulnerability has been resolved: xhci: dbgtty: Fix unregister on tty_register_driver…
CVE-2026-80922 linux Awaiting NVD 2026-09-09 In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - Allow zero as a random number Ze…
CVE-2026-80921 linux High 8.8 2026-09-09 In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadow…
CVE-2026-80920 linux Awaiting NVD 2026-09-09 In the Linux kernel, the following vulnerability has been resolved: io_uring: defer eventfd signaling when queued from …
CVE-2026-80919 linux Awaiting NVD 2026-09-09 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix recursive ww_mutex acquire in amdgp…
CVE-2026-80918 linux Awaiting NVD 2026-09-09 In the Linux kernel, the following vulnerability has been resolved: HID: core: fix number/pointer type confusion on lon…
CVE-2026-80917 linux Awaiting NVD 2026-09-09 In the Linux kernel, the following vulnerability has been resolved: PCI: host-generic: Fix NULL pointer dereference on …
CVE-2026-80916 linux Awaiting NVD 2026-09-09 In the Linux kernel, the following vulnerability has been resolved: kcov: fix data corruption and race conditions on PR…
CVE-2026-80915 linux Awaiting NVD 2026-09-09 In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix DPT allocation paths. Remove the fallba…
CVE-2026-80914 linux High 8.8 2026-09-09 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix use-after-free of listener sock…
CVE-2026-80913 linux Awaiting NVD 2026-09-04 In the Linux kernel, the following vulnerability has been resolved: selinux: require every boolean value to be defined …
CVE-2026-80912 linux Awaiting NVD 2026-09-04 In the Linux kernel, the following vulnerability has been resolved: selinux: reject an unclaimed class value in securit…
CVE-2026-80911 linux Awaiting NVD 2026-09-04 In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: sof-audio: Fix error path in sof_widget_…
CVE-2026-80910 linux Awaiting NVD 2026-09-04 In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol ac…
CVE-2026-80909 linux Awaiting NVD 2026-09-04 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Reject UVD message with invalid number …
CVE-2026-80908 linux Awaiting NVD 2026-09-04 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Reject UVD message with dimensions abov…
CVE-2026-80907 linux Awaiting NVD 2026-09-04 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix UVD dpb min size calculation for H2…
CVE-2026-80906 linux Awaiting NVD 2026-09-04 In the Linux kernel, the following vulnerability has been resolved: net: packet: fix wrong transport_header when sendin…

Frequently Asked Questions

How many Linux kernel CVEs have been published in total?

As of today, 18,243 Linux kernel CVEs have been published and indexed in this database. The Linux kernel is one of the most widely tracked packages in the NIST National Vulnerability Database due to its use in servers, cloud infrastructure, Android devices, and embedded systems. View full statistics →

How many Linux kernel CVEs are actively exploited?

28 Linux kernel CVEs are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning they have been confirmed as actively exploited in the wild. These are the highest-priority vulnerabilities for patching. View all actively exploited CVEs →

How often is this database updated?

The database is updated daily from the NIST NVD API. New CVEs are typically added within 24–48 hours of NVD publication. CISA KEV status is also checked daily. Affected version data is sourced from the CVE.org API and refreshed regularly.

What is a CVSS score?

CVSS (Common Vulnerability Scoring System) is a standardised 0–10 score assigned to each CVE, measuring its technical severity. Scores 9.0–10.0 are Critical, 7.0–8.9 are High, 4.0–6.9 are Medium, and 0.1–3.9 are Low. CVSS scores are assigned by NIST analysts and updated as new information emerges.

What is the CISA KEV catalog?

The CISA Known Exploited Vulnerabilities (KEV) catalog is maintained by the US Cybersecurity and Infrastructure Security Agency. It lists CVEs confirmed as actively exploited in real-world attacks. US federal agencies are required to patch KEV-listed vulnerabilities within a defined deadline. The catalog is a high-signal filter for security teams prioritising patching efforts.