838 Linux Kernel CVEs in July 2026
Full month · Source: NIST NVD
In July 2026, 838 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 88 were rated Critical, 409 were rated High severity and 196 Medium. CVE-2026-53362 was confirmed as actively exploited in the wild and added to the CISA Known Exploited Vulnerabilities catalog. July's 838 CVEs represent 11% of all 2026 Linux kernel CVEs , up from June's 514 (a 63% month-over-month increase) .
Actively Exploited CVEs — July 2026
1 CVE in CISA KEVCVE-2026-53362 is the only Linux kernel CVE from July 2026 confirmed as actively exploited in the wild. It carries a CVSS score of 7.8 (High severity) and is listed in the CISA Known Exploited Vulnerabilities catalog.
| CVE ID | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|
| CVE-2026-53362 | High KEV | 7.8 | 2026-07-04 | In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on th… |
| CVE ID | Package | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|---|
| CVE-2022-4994 | linux | Awaiting NVD | — | 2026-07-30 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emulator_pio_in Use __e… | |
| CVE-2026-64542 | linux | Awaiting NVD | — | 2026-07-27 | In the Linux kernel, the following vulnerability has been resolved: ipv6: ndisc: fix NULL deref in accept_untracked_na(… | |
| CVE-2026-64544 | linux | Awaiting NVD | — | 2026-07-27 | In the Linux kernel, the following vulnerability has been resolved: crypto: asymmetric_keys - fix OOB read in pefile_di… | |
| CVE-2026-64538 | linux | Awaiting NVD | — | 2026-07-27 | In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). f… | |
| CVE-2026-64553 | linux | Awaiting NVD | — | 2026-07-27 | In the Linux kernel, the following vulnerability has been resolved: net: psample: fix info leak in PSAMPLE_ATTR_DATA ps… | |
| CVE-2026-64537 | linux | Awaiting NVD | — | 2026-07-27 | In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: reject invalid CCM interval at configu… | |
| CVE-2026-64549 | linux | Awaiting NVD | — | 2026-07-27 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bpa10x: avoid OOB read of revision strin… | |
| CVE-2026-64505 | linux | Awaiting NVD | — | 2026-07-25 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: function: rndis: add length check for … | |
| CVE-2026-64454 | linux | Awaiting NVD | — | 2026-07-25 | In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: run gadget disconnect from sleepable sus… | |
| CVE-2026-64486 | linux | Awaiting NVD | — | 2026-07-25 | In the Linux kernel, the following vulnerability has been resolved: ALSA: cmipci: check snd_ctl_new1() return value snd… | |
| CVE-2026-64457 | linux | Awaiting NVD | — | 2026-07-25 | In the Linux kernel, the following vulnerability has been resolved: virtio_pci: fix vq info pointer lookup via wrong in… | |
| CVE-2026-64480 | linux | Awaiting NVD | — | 2026-07-25 | In the Linux kernel, the following vulnerability has been resolved: ALSA: ice1712: check snd_ctl_new1() return value sn… | |
| CVE-2026-64484 | linux | Awaiting NVD | — | 2026-07-25 | In the Linux kernel, the following vulnerability has been resolved: ALSA: es1938: check snd_ctl_new1() return value snd… | |
| CVE-2026-64492 | linux | Awaiting NVD | — | 2026-07-25 | In the Linux kernel, the following vulnerability has been resolved: iio: temperature: tmp006: use devm_iio_trigger_regi… | |
| CVE-2026-64528 | linux | Awaiting NVD | — | 2026-07-25 | In the Linux kernel, the following vulnerability has been resolved: tty: serial: samsung: Remove redundant port lock ac… |