Linux Kernel CVE Statistics
178 Linux Kernel CVEs in March 2026
Full month · Source: NIST NVD
In March 2026, 178 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 1 was rated Critical, 61 were rated High severity and 116 Medium. No CVEs from this month have been confirmed as actively exploited via the CISA KEV catalog. March's 178 CVEs represent 3% of all 2026 Linux kernel CVEs , down from February's 220 (a 19% month-over-month decrease) .
178
Total CVEs
1
Critical
61
High
116
Medium
0
Low
0
KEV Exploited
All CVEs — March 2026
178 CVEs
| CVE ID | Package | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|---|
| CVE-2026-23240 | linux | Critical | 9.8 | 2026-03-10 | In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() … | |
| CVE-2026-23395 | linux | High | 8.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRE… | |
| CVE-2026-23246 | linux | High | 8.8 | 2026-03-18 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_m… | |
| CVE-2026-31788 | linux | High | 8.2 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: restrict usage in unprivileged domU Th… | |
| CVE-2026-23344 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix use-after-free on error path In t… | |
| CVE-2026-23390 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: tracing/dma: Cap dma_map_sg tracepoint arrays to pr… | |
| CVE-2026-23378 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ife: Fix metalist update behavior Wh… | |
| CVE-2026-23359 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stack-out-of-bounds write in devmap get_up… | |
| CVE-2026-23306 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free in pm8001_queue_co… | |
| CVE-2026-23372 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: nfc: rawsock: cancel tx_work before socket teardown… | |
| CVE-2026-23322 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix use-after-free and list corruption on sen… | |
| CVE-2026-23281 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix use-after-free in lbs_free_adap… | |
| CVE-2026-23383 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: bpf, arm64: Force 8-byte alignment for JIT buffer t… | |
| CVE-2026-23393 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: Fix race condition in peer_mep deletio… | |
| CVE-2026-23319 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_… |