Linux Kernel CVE Tracker

20,370 vulnerabilities indexed - updated daily from NIST NVD

LinuxCVETracker is a free, searchable database of 20,370 Linux kernel CVEs, sourced daily from the NIST National Vulnerability Database and the CISA Known Exploited Vulnerabilities catalog. Of these, 650 are rated Critical severity and 31 have been confirmed as actively exploited. Use it to search, filter, and monitor Linux kernel security vulnerabilities by severity, year, affected package, or exploitation status.

CVE Statistics

20,370
Total CVEs
650
Critical
6,516
High
31
KEV - Actively Exploited

Linux Kernel CVE Database

All time 2026 2025 2024 2023 2022 2021 2020 2019 2018 2017 2016 2015 2014 2013 2012 2011 2010 2009 2008 2007 2006 2005 2004 2003 2002 2001 2000 1999 1998
20,370 vulnerabilities
Page 1 of 1019
CVE ID Package Severity CVSS Published Description
CVE-2026-98372 linux Awaiting NVD — 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_…
CVE-2026-98371 linux Awaiting NVD — 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix runt reassembly panic from short i…
CVE-2026-98370 linux Awaiting NVD — 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: xfrm: fix compat ALLOCSPI request use-after-free xf…
CVE-2026-98369 linux High 7.8 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: xfrm: add missing rcu_read_lock(), skb_dst_force() …
CVE-2026-98368 linux High 7.8 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: esp: downgrade zerocopy managed frags before mutati…
CVE-2026-98367 linux High 7.8 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Clear association under lock if siw_qp_mo…
CVE-2026-98366 linux High 7.8 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: validate access flags before swapping the…
CVE-2026-98365 linux Critical 9.8 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix integer overflow in mr_check_range() …
CVE-2026-98364 linux High 7.8 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: xfrm: hold net_device reference under RCU in bundle…
CVE-2026-98363 linux Awaiting NVD — 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: reject DVFS OPP count above MAX…
CVE-2026-98362 linux Awaiting NVD — 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: clk: scpi: bound-check DVFS index in scpi_dvfs_reca…
CVE-2026-98361 linux High 7.8 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write …
CVE-2026-98360 linux High 7.0 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: insert mcg into mcg_tree only after rxe_m…
CVE-2026-98359 linux High 7.0 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Reject unregistering netdevs in ib_get_e…
CVE-2026-98358 linux Awaiting NVD — 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: IB/iser: reject a remote invalidation of an unregis…
CVE-2026-98357 linux High 8.1 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: IB/isert: wait for deferred control PDU completions…
CVE-2026-98356 linux Awaiting NVD — 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: check create_singlethread_workqueue()…
CVE-2026-98355 linux Awaiting NVD — 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: guard against null kobj name In the clie…
CVE-2026-98354 linux Awaiting NVD — 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: RDMA/mad: Fix receive buffer leak when PKey enforce…
CVE-2026-98353 linux Awaiting NVD — 2026-10-06 In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Use IRQ-safe XArray helpers for QP and …

Frequently Asked Questions

How many Linux kernel CVEs have been published in total?

As of today, 20,370 Linux kernel CVEs have been published and indexed in this database. The Linux kernel is one of the most widely tracked packages in the NIST National Vulnerability Database due to its use in servers, cloud infrastructure, Android devices, and embedded systems. View full statistics →

How many Linux kernel CVEs are actively exploited?

31 Linux kernel CVEs are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning they have been confirmed as actively exploited in the wild. These are the highest-priority vulnerabilities for patching. View all actively exploited CVEs →

How often is this database updated?

The database is updated daily from the NIST NVD API. New CVEs are typically added within 24–48 hours of NVD publication. CISA KEV status is also checked daily. Affected version data is sourced from the CVE.org API and refreshed regularly.

What is a CVSS score?

CVSS (Common Vulnerability Scoring System) is a standardised 0–10 score assigned to each CVE, measuring its technical severity. Scores 9.0–10.0 are Critical, 7.0–8.9 are High, 4.0–6.9 are Medium, and 0.1–3.9 are Low. CVSS scores are assigned by NIST analysts and updated as new information emerges.

What is the CISA KEV catalog?

The CISA Known Exploited Vulnerabilities (KEV) catalog is maintained by the US Cybersecurity and Infrastructure Security Agency. It lists CVEs confirmed as actively exploited in real-world attacks. US federal agencies are required to patch KEV-listed vulnerabilities within a defined deadline. The catalog is a high-signal filter for security teams prioritising patching efforts.