Linux Kernel CVE Statistics
178 Linux Kernel CVEs in March 2026
Full month · Source: NIST NVD
In March 2026, 178 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 1 was rated Critical, 61 were rated High severity and 116 Medium. No CVEs from this month have been confirmed as actively exploited via the CISA KEV catalog. March's 178 CVEs represent 6% of all 2026 Linux kernel CVEs , down from February's 220 (a 19% month-over-month decrease) .
178
Total CVEs
1
Critical
61
High
116
Medium
0
Low
0
KEV Exploited
All CVEs — March 2026
178 CVEs
| CVE ID | Package | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|---|
| CVE-2026-23240 | linux | Critical | 9.8 | 2026-03-10 | In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() … | |
| CVE-2026-23395 | linux | High | 8.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRE… | |
| CVE-2026-23246 | linux | High | 8.8 | 2026-03-18 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_m… | |
| CVE-2026-31788 | linux | High | 8.2 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: restrict usage in unprivileged domU Th… | |
| CVE-2026-23359 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stack-out-of-bounds write in devmap get_up… | |
| CVE-2026-23319 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_… | |
| CVE-2026-23391 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_CT: drop pending enqueued packets on … | |
| CVE-2026-23378 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ife: Fix metalist update behavior Wh… | |
| CVE-2026-23361 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: PCI: dwc: ep: Flush MSI-X write before unmapping it… | |
| CVE-2026-23340 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: net: sched: avoid qdisc_reset_all_tx_gt() vs dequeu… | |
| CVE-2026-23387 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43… | |
| CVE-2026-23326 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: xsk: Fix fragment node deletion to prevent buffer l… | |
| CVE-2026-23343 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: xdp: produce a warning when calculated tailroom is … | |
| CVE-2026-23323 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (macsmc) Fix regressions in Apple Silicon SM… | |
| CVE-2026-23306 | linux | High | 7.8 | 2026-03-25 | In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free in pm8001_queue_co… |