Linux Kernel CVE Tracker

16,436 vulnerabilities indexed - updated daily from NIST NVD

LinuxCVETracker is a free, searchable database of 16,436 Linux kernel CVEs, sourced daily from the NIST National Vulnerability Database and the CISA Known Exploited Vulnerabilities catalog. Of these, 324 are rated Critical severity and 25 have been confirmed as actively exploited. Use it to search, filter, and monitor Linux kernel security vulnerabilities by severity, year, affected package, or exploitation status.

CVE Statistics

16,436
Total CVEs
324
Critical
5,037
High
25
KEV - Actively Exploited

Linux Kernel CVE Database

All time 2026 2025 2024 2023 2022 2021 2020 2019 2018 2017 2016 2015 2014 2013 2012 2011 2010 2009 2008 2007 2006 2005 2004 2003 2002 2001 2000 1999 1998
16,436 vulnerabilities
Page 1 of 822
CVE ID Package Severity CVSS Published Description
CVE-2026-68480 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt in…
CVE-2026-64604 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update if…
CVE-2026-64603 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handle…
CVE-2026-64602 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before reque…
CVE-2026-64601 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant us…
CVE-2026-64599 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: crypto: amlogic - avoid double cleanup in meson_cry…
CVE-2026-64598 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc()…
CVE-2026-64597 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay…
CVE-2026-64596 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: libfs: set SB_I_NOEXEC and SB_I_NODEV by default in…
CVE-2026-64595 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: HID: hid-lenovo-go: cancel cfg_setup work in hid_go…
CVE-2026-64594 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: initialize reset_work at allocat…
CVE-2026-64593 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: btrfs: do not trim a device which is not writeable …
CVE-2026-64592 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: riscv: mm: Unconditionally sfence.vma for spurious …
CVE-2026-64591 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid WARNING in sva unbind path The In…
CVE-2026-64590 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: dma-buf/udmabuf: skip redundant cpu sync to fix cac…
CVE-2026-64589 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix NULL-deref on adapter registration f…
CVE-2026-64588 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix data races on ring->ready On weakly…
CVE-2026-64587 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: net: ethernet: arc: emac: quiesce interrupts before…
CVE-2026-64586 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device remo…
CVE-2026-64585 linux Awaiting NVD 2026-08-06 In the Linux kernel, the following vulnerability has been resolved: can: esd_usb: kill anchored URBs before freeing net…

Frequently Asked Questions

How many Linux kernel CVEs have been published in total?

As of today, 16,436 Linux kernel CVEs have been published and indexed in this database. The Linux kernel is one of the most widely tracked packages in the NIST National Vulnerability Database due to its use in servers, cloud infrastructure, Android devices, and embedded systems. View full statistics →

How many Linux kernel CVEs are actively exploited?

25 Linux kernel CVEs are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning they have been confirmed as actively exploited in the wild. These are the highest-priority vulnerabilities for patching. View all actively exploited CVEs →

How often is this database updated?

The database is updated daily from the NIST NVD API. New CVEs are typically added within 24–48 hours of NVD publication. CISA KEV status is also checked daily. Affected version data is sourced from the CVE.org API and refreshed regularly.

What is a CVSS score?

CVSS (Common Vulnerability Scoring System) is a standardised 0–10 score assigned to each CVE, measuring its technical severity. Scores 9.0–10.0 are Critical, 7.0–8.9 are High, 4.0–6.9 are Medium, and 0.1–3.9 are Low. CVSS scores are assigned by NIST analysts and updated as new information emerges.

What is the CISA KEV catalog?

The CISA Known Exploited Vulnerabilities (KEV) catalog is maintained by the US Cybersecurity and Infrastructure Security Agency. It lists CVEs confirmed as actively exploited in real-world attacks. US federal agencies are required to patch KEV-listed vulnerabilities within a defined deadline. The catalog is a high-signal filter for security teams prioritising patching efforts.