Linux
Linux- Software type
- —
- Catalog vulnerabilities
- 15,261
Severity across 520 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 520 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 15,261 vulnerability records affecting Linux.
Among the 520 records analyzed by CyStack, 158 are High or Critical and 2 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-80925vlan: fix skb_under_panic and races when toggling HW VLAN offload | Exploitation statusNot confirmed | FixYes | Published09/09/2026 | SeverityUnknown |
CVE-2026-80924crypto: krb5 - use kfree_sensitive() for derived key buffers | Exploitation statusNot confirmed | FixYes | Published09/09/2026 | SeverityHigh |
CVE-2026-80923xhci: dbgtty: Fix unregister on tty_register_driver() failure | Exploitation statusNot confirmed | FixYes | Published09/09/2026 | SeverityUnknown |
CVE-2026-80922crypto: qcom-rng - Allow zero as a random number | Exploitation statusNot confirmed | FixYes | Published09/09/2026 | SeverityUnknown |
CVE-2026-80921KVM: s390: vsie: zero stale crypto bits | Exploitation statusNot confirmed | FixYes | Published09/09/2026 | SeverityHigh |
CVE-2026-80920io_uring: defer eventfd signaling when queued from a wakeup handler | Exploitation statusNot confirmed | FixYes | Published09/09/2026 | SeverityUnknown |
CVE-2026-80919drm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format | Exploitation statusNot confirmed | FixYes | Published09/09/2026 | SeverityUnknown |
CVE-2026-80918HID: core: fix number/pointer type confusion on long items | Exploitation statusNot confirmed | FixYes | Published09/09/2026 | SeverityUnknown |
CVE-2026-80917PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems | Exploitation statusNot confirmed | FixYes | Published09/09/2026 | SeverityUnknown |
CVE-2026-80916kcov: fix data corruption and race conditions on PREEMPT_RT | Exploitation statusNot confirmed | FixYes | Published09/09/2026 | SeverityUnknown |
CVE-2026-80915drm/xe: Fix DPT allocation paths. | Exploitation statusNot confirmed | FixYes | Published09/09/2026 | SeverityUnknown |
CVE-2026-80914Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready | Exploitation statusNot confirmed | FixYes | Published09/09/2026 | SeverityHigh |
CVE-2026-80913selinux: require every boolean value to be defined | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80912selinux: reject an unclaimed class value in security_get_classes() | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80911ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80910ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80909drm/amdgpu: Reject UVD message with invalid number of h265 refs | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80908drm/amdgpu: Reject UVD message with dimensions above 4096 | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80907drm/amdgpu: Fix UVD dpb min size calculation for H264 | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80906net: packet: fix wrong transport_header when sending VLAN-tagged frame | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80905net: tap: fix wrong transport_header when sending VLAN-tagged frame | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80904net/tls: Fail tls_sw_splice_read() after a failed async decrypt | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80903drm/xe/oa: Fix sync entry leak on OA config emit failure | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80902dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80901ipvs: fix the checksum validations | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80900ASoC: SDCA: Make UMP message size check more robust | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80899erofs: remove fscache backend entirely | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80898netfs: clear PG_private_2 on copy-to-cache append failure | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80897netfs: release readahead folios on iterator preparation failure | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80896mshv: Fix race in mshv_irqfd_deassign | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80895mshv: Order pt_vp_array publish against irqfd assertion path | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80894iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80893mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80892erofs: cap LZMA stream pool size | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80891KVM: s390: pci: Validate AIBV and AISB before pinning guest pages | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80890sctp: reject stale cookies with mismatched verification tags | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80889can: isotp: fix timer drain order, wakeup handling and tx_gen ordering | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80888drm/vmwgfx: drop dma_buf reference on foreign-fd prime import | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80887drm/vmwgfx: use check_add_overflow for shader size+offset bound | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80886serial: msm: Disable DMA for kernel console UART | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80885afs: Fix uncancelled rxrpc OOB message handler | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80884ntb: Store original DMA address for future release | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80883drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80882crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80881ocfs2: fix buffer head management in ocfs2_read_blocks() | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80880IB/mlx5: Properly support implicit ODP rereg_mr | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80879ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80878afs: Fix leak of ungot volume | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80877afs: Fix vllist leak | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80876ring-buffer: Fix event length with forced 8-byte alignment | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80875ipvs: use parsed transport offset in TCP state lookup | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80874arm64: dts: renesas: ironhide: Describe inline ECC carveouts | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80873KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80872ALSA: hda/tas2781: Cancel async firmware request at unbind | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80871crypto: xilinx-trng - Remove crypto_rng interface | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80870drm/amdkfd: Validate CRIU-restored IDs before idr_alloc | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80869ntfs: bound the attribute-list entry in ntfs_read_inode_mount() | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80868ntfs3: Allocate iomap inline_data using alloc_page | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80867alpha/PCI: Add security_locked_down() check to pci_mmap_resource() | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80866tipc: avoid busy looping in tipc_exit_net() | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80865bpf: Add missing access_ok call to copy_user_syms | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80864RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80863RDMA/rxe: Fix OOB in free_rd_atomic_resources() | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80862nvme-tcp: fix usage of page_frag_cache | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80861usb: xhci: bail out of setup if the controller is inaccessible | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80860fuse: fix race between interrupt and resend | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80859fuse: fix missing barrier when checking io-uring readiness | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80858fuse: publish io-uring queues with release semantics | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80857fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80856fuse: fix invalidate lock leak on setattr writeback failure | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80855fuse: fix invalidate lock leak on open O_TRUNC DAX failure | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80854usb: gadget: f_tcm: keep port count until LUN teardown completes | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80853KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80852tls: device: fix out-of-bounds write in tls_append_frag() | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80851gtp: serialize PDP context updates | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80850tcp: fix AO info use-after-free in tcp_ao_connect_init() | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80849net/tcp-ao: fix use-after-free of current_key on reconnect to another peer | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80848xfrm: espintcp: fix UAF during close | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80847tcp: clamp route advmss to TCP_MIN_MSS | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80846xfrm: drop ESP-in-TCP packets with no ingress device | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80845xfrm: avoid lock inversion in nat keepalive work | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80844xfrm: ah6: validate routing header segments_left | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80843xfrm: fix xfrm_state_construct() auth-trunc leak | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80842net: bridge: mcast: fix use-after-free of a master VLAN's multicast context | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80841net/packet: defer vmalloc TX_RING free until skbs finish | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80840ipv6: seg6: clear IPv4 control block on IPIP decapsulation | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80839batman-adv: reject unrepresentable multicast TVLV offsets | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80838vxlan: keep the last remote linked during FDB flush | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80837netfilter: nf_tables: don't queue packet path object notifications | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80836crypto: virtio - bound the akcipher result length | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80835crypto: qcom-rng - Remove crypto_rng interface | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80834crypto: sun8i-ce - Remove crypto_rng interface | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80833crypto: sun8i-ss - Remove crypto_rng interface | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80832crypto: qce - fix CCM AAD buffer underallocation | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80831crypto: mxs-dcp - fix source scatterlist length access | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80830usb: core: Add lock to usb_wakeup_notification() | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80829ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80828ALSA: usb-audio: Complete cleanup after system-resume errors | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80827USB: serial: option: fix slab OOB read in interrupt URB callback | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CVE-2026-80826USB: c67x00: fix use-after-free in c67x00_add_iso_urb() | Exploitation statusNot confirmed | FixYes | Published09/04/2026 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan