kernel.org

First CVE: Feb 20, 2024Active for: 2 years
13,010
CVEs Published
More CVEs Published than 99% of tracked CNAs
4336.7
Avg CVEs / Year
More Avg CVEs / Year than 100% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 13% of tracked CNAs
0.1%
In CISA KEV
Higher KEV Rate than 78% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by kernel.org as a CNA, 86.9% affect products that kernel.org develops as a vendor.

86.9%
13.1%
Self-reported: 11,306Third-party: 1,704

Of all the CVEs published that affect products developed by kernel.org, 59.6% are self-published by kernel.org as a CNA.

59.6%
40.4%
Self-published: 11,306Published by other CNAs: 7,666

Trends Over Time

The number and severity of CVEs published by kernel.org over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 20, 2024
2 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by kernel.org as a CNA, regardless of affected vendor or product.

13,010 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the c
Apr 22, 20267.899YESYES
In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly t
May 8, 20268.895NOYES
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_
May 11, 20267.894NOYES
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a
Dec 27, 20247.866YESNO
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of boun
Dec 2, 20247.866YESNO
In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_c
Jun 10, 20247.866YESNO
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autor
Jul 22, 20257.465YESNO
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session setup request, ksmbd
Feb 23, 20247.165NONO
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't
Dec 24, 20247.163YESNO
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in variou
Nov 19, 20245.558YESNO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA13,010 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCriticalUnknown
Attack Vector
Local10,797 (83.0%)
Network429 (3.3%)
Unknown1,685 (13.0%)
Physical10 (0.1%)
Adjacent Network89 (0.7%)
Attack Complexity
Low10,769 (82.8%)
High556 (4.3%)
Unknown1,685 (13.0%)
User Interaction
None11,288 (86.8%)
Unknown1,685 (13.0%)
Required37 (0.3%)
Privileges Required
Low10,705 (82.3%)
High56 (0.4%)
None564 (4.3%)
Unknown1,685 (13.0%)

Exploit Exposure

Signals from CVEs in this cna scope (13010 CVEs).

CISA KEV
7 CVEs
0.1% of CVEs· 78th percentile
Metasploit
4 CVEs
0.0% of CVEs· 77th percentile
Nuclei
1 CVE
0.0% of CVEs· 69th percentile
ExploitDB
6 CVEs
0.0% of CVEs· 73rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by kernel.org as a CNA.

Media Mentions

Media articles that mention a CVE ID published by kernel.org as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs