LIVE · cybersecurity feed
Live wire
vendor

Linux

300 CVEs published in the last four months and 12 stories. Exploited flaws first.

Critical106
High194
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-6379510criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() e48d ago
CVE-2026-641509.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: release local_lock befor48d ago
CVE-2026-532469.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length i72d ago
CVE-2026-640559.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counte48d ago
CVE-2026-642169.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_aband43d ago
CVE-2026-643039.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX42d ago
CVE-2026-643839.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() r42d ago
CVE-2026-638009.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout48d ago
CVE-2026-435019.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recom107d ago
CVE-2026-459889.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of RESPONSE packets I101d ago
CVE-2026-461379.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-ra100d ago
CVE-2026-533989.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup48d ago
CVE-2026-643859.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() r42d ago
CVE-2026-640479.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: net: tls: fix off-by-one in sg_chain entry cou48d ago
CVE-2026-463259.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR pag88d ago
CVE-2026-641369.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count increment in smb48d ago
CVE-2026-533849.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_n48d ago
CVE-2026-530869.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The 73d ago
CVE-2026-529869.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_73d ago
CVE-2026-529829.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8173d ago
CVE-2026-530109.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during 73d ago
CVE-2026-529249.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO hand73d ago
CVE-2026-529149.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length acc73d ago
CVE-2026-530069.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching73d ago
CVE-2026-434939.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG r109d ago
CVE-2026-643999.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ksmbd: add permission checks for FSCTL_DUPLICA42d ago
CVE-2026-462899.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in ex89d ago
CVE-2026-532219.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti672d ago
CVE-2026-530459.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: memory: tegra124-emc: Fix dll_change check The73d ago
CVE-2026-640469.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: net: tls: prevent chain-after-chain in plain t48d ago
CVE-2026-643559.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap42d ago
CVE-2026-530499.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gf73d ago
CVE-2026-642329.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_43d ago
CVE-2026-641429.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ksmbd: close durable scavenger races against m48d ago
CVE-2026-641259.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setti48d ago
CVE-2026-641139.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast 48d ago
CVE-2026-461359.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and100d ago
CVE-2026-529319.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit send73d ago
CVE-2026-640569.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port T48d ago
CVE-2026-533639.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in ip57d ago
CVE-2026-461959.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before buildi100d ago
CVE-2026-640619.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: netfs: Fix early put of sink folio in netfs_re48d ago
CVE-2026-641229.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix use-after-free in mlx5e_tx_repo48d ago
CVE-2026-641609.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential for tearing in ->remote_i48d ago
CVE-2026-532169.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buf72d ago
CVE-2026-529559.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in73d ago
CVE-2026-459729.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF and double free101d ago
CVE-2026-533559.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RD66d ago
CVE-2026-532479.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free72d ago
CVE-2026-533099.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions71d ago
CVE-2026-530029.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Rep73d ago
CVE-2026-531759.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the 72d ago
CVE-2026-643879.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double42d ago
CVE-2026-460399.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: rxgk: Fix potential integer overflow in length101d ago
CVE-2026-532159.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or sk72d ago
CVE-2026-530889.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_73d ago
CVE-2026-643849.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-f42d ago
CVE-2026-532289.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO 72d ago
CVE-2026-640669.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_read_to_pagecache() to pause 48d ago
CVE-2026-533999.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure 48d ago
CVE-2026-530469.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free from async crypto on73d ago
CVE-2026-531519.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK 72d ago
CVE-2026-532609.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in 72d ago
CVE-2026-529939.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tip73d ago
CVE-2026-461159.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: block: add pgmap check to biovec_phys_mergeabl100d ago
CVE-2026-531769.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_72d ago
CVE-2026-644109.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: IPIP tunnel hardware off42d ago
CVE-2026-642689.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the42d ago
CVE-2026-529899.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec73d ago
CVE-2026-641629.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: idpf: fix read_dev_clk_lock spinlock init in i48d ago
CVE-2026-644399.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - filter out async aead implement42d ago
CVE-2026-458989.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix workqueue list corruption by re101d ago
CVE-2026-643919.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alte42d ago
CVE-2026-530559.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-afte73d ago
CVE-2026-640689.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing locking around retry adding48d ago
CVE-2026-640679.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing barriers when accessing str48d ago
CVE-2026-641029.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Reject MPA FPDU length underflow bef48d ago
CVE-2026-643979.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per 42d ago
CVE-2026-640919.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported v48d ago
CVE-2026-643869.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-fr42d ago
CVE-2026-640699.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: netfs: Fix cancellation of a DIO and single re48d ago
CVE-2026-640899.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative last_changeset_le48d ago
CVE-2026-641329.8criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: refresh hdr pointer before ioam6_e48d ago
CVE-2026-531319.4criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before 72d ago
CVE-2026-463169.3criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cac88d ago
CVE-2026-640809.3criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Snapshot notifier callbacks48d ago
CVE-2026-462669.1criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop 94d ago
CVE-2026-530439.1criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match73d ago
CVE-2026-462449.1criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff des94d ago
CVE-2026-461859.1criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_100d ago
CVE-2026-644509.1criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: tipc: fix out-of-bounds read in broadcast Gap 42d ago
CVE-2026-461559.1criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_com100d ago
CVE-2026-532249.1criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address72d ago
CVE-2026-643929.1criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for delete-on-cl42d ago
CVE-2026-643199.1criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bou42d ago
CVE-2026-642699.1criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chun42d ago
CVE-2026-642579.1criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in 42d ago
CVE-2026-461199.1criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access in auth100d ago
CVE-2026-460439.1criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate pad and ICRC before payload101d ago
CVE-2026-643939.1criticallinux kernelIn the Linux kernel, the following vulnerability has been resolved: ksmbd: run set info with opener credentials SM42d ago

Filter the full tracker by Linux

Our coverage of Linux

ai

Linux Foundation Introduces TRACE Standard for AI Runtime Evidence

This new open standard offers hardware-attested runtime and compliance evidence for AI agents

ai

Linux Foundation takes on TRACE, a hardware-backed runtime evidence specification for AI agents

The Linux Foundation has adopted TRACE, a new hardware-backed specification for generating runtime evidence for AI agents and confidential workloads. Developed by major tech companies, TRACE aims to provide a standardized, cryptographically verifiable record of an AI agent's execution environment, policies, and data handling. This initiative seeks to build trust and enable independent verification of AI operations across different cloud and computing infrastructures.

ai

Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek.

ai

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open

npmhigh

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Researchers have identified 14 malicious npm packages disguised as calendar and streak utilities that deliver a sophisticated Linux backdoor known as RedC2 4.0. These packages, once imported, stealthily execute a Linux implant that communicates with a command-and-control server for post-exploitation activities. The RedC2 framework, marketed as a cross-platform toolkit, features AI-assisted capabilities for orchestrating complex intrusions using natural language commands.

security

Researcher tricks Apple’s Find My into sharing location data with Linux

Clever protocol wrangling gets iBiz-only people tracking working on a non-iGadget

security

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.

vulnerability

Exclusive: Linux Foundation's Akrites to Go Live in September

The Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projects

malware

New Mirai-Based Evooo1Bot Botnet Targets Linux Devices

Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a [

malware

Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.

malware

New Evooo1Bot Linux botnet turns routers into traffic relay nodes

A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]

malware

New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies

Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies