Linux Kernel CVE Statistics
1,034 Linux Kernel CVEs in May 2026
Full month · Source: NIST NVD
In May 2026, 1,034 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 42 were rated Critical, 398 were rated High severity and 592 Medium. No CVEs from this month have been confirmed as actively exploited via the CISA KEV catalog. May's 1,034 CVEs represent 33% of all 2026 Linux kernel CVEs , up from April's 379 (a 173% month-over-month increase) .
1034
Total CVEs
42
Critical
398
High
592
Medium
1
Low
0
KEV Exploited
All CVEs — May 2026
1034 CVEs
| CVE ID | Package | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|---|
| CVE-2026-45992 | linux | Awaiting NVD | — | 2026-05-27 | In the Linux kernel, the following vulnerability has been resolved: ALSA: caiaq: Fix potentially leftover ep1_in_urb at… | |
| CVE-2026-46137 | linux | Critical | 9.8 | 2026-05-28 | In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-race Th… | |
| CVE-2026-46135 | linux | Critical | 9.8 | 2026-05-28 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queu… | |
| CVE-2026-46115 | linux | Critical | 9.8 | 2026-05-28 | In the Linux kernel, the following vulnerability has been resolved: block: add pgmap check to biovec_phys_mergeable bio… | |
| CVE-2026-46195 | linux | Critical | 9.8 | 2026-05-28 | In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before building DA… | |
| CVE-2026-45972 | linux | Critical | 9.8 | 2026-05-27 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF and double free in s… | |
| CVE-2026-45898 | linux | Critical | 9.8 | 2026-05-27 | In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix workqueue list corruption by removin… | |
| CVE-2026-45988 | linux | Critical | 9.8 | 2026-05-27 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of RESPONSE packets If a R… | |
| CVE-2026-46039 | linux | Critical | 9.8 | 2026-05-27 | In the Linux kernel, the following vulnerability has been resolved: rxgk: Fix potential integer overflow in length chec… | |
| CVE-2026-43501 | linux | Critical | 9.8 | 2026-05-21 | In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompress… | |
| CVE-2026-43493 | linux | Critical | 9.8 | 2026-05-19 | In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG reques… | |
| CVE-2026-43341 | linux | Critical | 9.8 | 2026-05-08 | In the Linux kernel, the following vulnerability has been resolved: net/ipv6: ioam6: prevent schema length wraparound i… | |
| CVE-2026-43402 | linux | Critical | 9.8 | 2026-05-08 | In the Linux kernel, the following vulnerability has been resolved: kthread: consolidate kthread exit paths to prevent … | |
| CVE-2026-43465 | linux | Critical | 9.8 | 2026-05-08 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for … | |
| CVE-2026-43304 | linux | Critical | 9.8 | 2026-05-08 | In the Linux kernel, the following vulnerability has been resolved: libceph: define and enforce CEPH_MAX_KEY_LEN When d… |