kernel.org
First CVE: Feb 20, 2024Active for: 2 years
13,010
CVEs Published
More CVEs Published than 99% of tracked CNAs
4336.7
Avg CVEs / Year
More Avg CVEs / Year than 100% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 13% of tracked CNAs
0.1%
In CISA KEV
Higher KEV Rate than 78% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by kernel.org as a CNA, 86.9% affect products that kernel.org develops as a vendor.
86.9%
13.1%
Self-reported: 11,306Third-party: 1,704
Of all the CVEs published that affect products developed by kernel.org, 59.6% are self-published by kernel.org as a CNA.
59.6%
40.4%
Self-published: 11,306Published by other CNAs: 7,666
Trends Over Time
The number and severity of CVEs published by kernel.org over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 20, 2024
2 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by kernel.org as a CNA, regardless of affected vendor or product.
13,010 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31431HIGH In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the c | Apr 22, 2026 | 7.8 | 99 | YES | YES |
CVE-2026-43284HIGH In the Linux kernel, the following vulnerability has been resolved:
xfrm: esp: avoid in-place decrypt on shared skb frags
MSG_SPLICE_PAGES can attach pages from a pipe directly t | May 8, 2026 | 8.8 | 95 | NO | YES |
CVE-2026-43500HIGH In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
The DATA-packet handler in rxrpc_input_ | May 11, 2026 | 7.8 | 94 | NO | YES |
CVE-2024-53197HIGH In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
A bogus device can provide a | Dec 27, 2024 | 7.8 | 66 | YES | NO |
CVE-2024-53104HIGH In the Linux kernel, the following vulnerability has been resolved:
media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
This can lead to out of boun | Dec 2, 2024 | 7.8 | 66 | YES | NO |
CVE-2024-36971HIGH In the Linux kernel, the following vulnerability has been resolved:
net: fix __dst_negative_advice() race
__dst_negative_advice() does not enforce proper RCU rules when
sk->dst_c | Jun 10, 2024 | 7.8 | 66 | YES | NO |
CVE-2025-38352HIGH In the Linux kernel, the following vulnerability has been resolved:
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
If an exiting non-autor | Jul 22, 2025 | 7.4 | 65 | YES | NO |
CVE-2024-26594HIGH In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate mech token in session setup
If client send invalid mech token in session setup request, ksmbd
| Feb 23, 2024 | 7.1 | 65 | NO | NO |
CVE-2024-53150HIGH In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Fix out of bounds reads when finding clock sources
The current USB-audio driver code doesn't | Dec 24, 2024 | 7.1 | 63 | YES | NO |
CVE-2024-50302MEDIUM In the Linux kernel, the following vulnerability has been resolved:
HID: core: zero-initialize the report buffer
Since the report buffer is used by all kinds of drivers in variou | Nov 19, 2024 | 5.5 | 58 | YES | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA13,010 CVEs
59%
26%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCriticalUnknown
Attack Vector
Local10,797 (83.0%)
Network429 (3.3%)
Unknown1,685 (13.0%)
Physical10 (0.1%)
Adjacent Network89 (0.7%)
Attack Complexity
Low10,769 (82.8%)
High556 (4.3%)
Unknown1,685 (13.0%)
User Interaction
None11,288 (86.8%)
Unknown1,685 (13.0%)
Required37 (0.3%)
Privileges Required
Low10,705 (82.3%)
High56 (0.4%)
None564 (4.3%)
Unknown1,685 (13.0%)
Exploit Exposure
Signals from CVEs in this cna scope (13010 CVEs).
CISA KEV
7 CVEs
0.1% of CVEs· 78th percentile
Metasploit
4 CVEs
0.0% of CVEs· 77th percentile
Nuclei
1 CVE
0.0% of CVEs· 69th percentile
ExploitDB
6 CVEs
0.0% of CVEs· 73rd percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by kernel.org as a CNA.
Media Mentions
Media articles that mention a CVE ID published by kernel.org as a CNA — matched by CVE ID, not by organization name.