Linux Kernel CVE Statistics
514 Linux Kernel CVEs in June 2026
Full month · Source: NIST NVD
In June 2026, 514 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 40 were rated Critical, 238 were rated High severity and 236 Medium. No CVEs from this month have been confirmed as actively exploited via the CISA KEV catalog. June's 514 CVEs represent 17% of all 2026 Linux kernel CVEs , down from May's 1,034 (a 50% month-over-month decrease) .
514
Total CVEs
40
Critical
238
High
236
Medium
0
Low
0
KEV Exploited
All CVEs — June 2026
514 CVEs
| CVE ID | Package | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|---|
| CVE-2026-53309 | linux | Critical | 9.8 | 2026-06-26 | In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() re… | |
| CVE-2026-53221 | linux | Critical | 9.8 | 2026-06-25 | In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_… | |
| CVE-2026-53216 | linux | Critical | 9.8 | 2026-06-25 | In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer m… | |
| CVE-2026-53260 | linux | Critical | 9.8 | 2026-06-25 | In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk… | |
| CVE-2026-53246 | linux | Critical | 9.8 | 2026-06-25 | In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COO… | |
| CVE-2026-53247 | linux | Critical | 9.8 | 2026-06-25 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in m… | |
| CVE-2026-53215 | linux | Critical | 9.8 | 2026-06-25 | In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use… | |
| CVE-2026-53176 | linux | Critical | 9.8 | 2026-06-25 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADE… | |
| CVE-2026-53151 | linux | Critical | 9.8 | 2026-06-25 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table… | |
| CVE-2026-53175 | linux | Critical | 9.8 | 2026-06-25 | In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir… | |
| CVE-2026-53228 | linux | Critical | 9.8 | 2026-06-25 | In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offlo… | |
| CVE-2026-52989 | linux | Critical | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() er… | |
| CVE-2026-52924 | linux | Critical | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling … | |
| CVE-2026-53006 | linux | Critical | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching sadd… | |
| CVE-2026-52914 | linux | Critical | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounti… |