Linux Kernel Security Intelligence
Know your kernel's
real exposure
Upload a .config and get a CycloneDX VEX report — filtered by kernel version, build configuration, and AI‑powered context analysis. Updated in real time as new CVEs appear.
Free tier · no credit card · no invitation needed
Free CVE Database
Browse and search all kernel CVEs instantly — including AI-assessed scores where NVD is still pending. Sign up free to run your first VEX analysis.
Version & Config-Aware VEX
Filter by kernel version and .config — get a CycloneDX VEX of precisely your build's exposure. Analyses update automatically when new CVEs land.
AI-Powered Context Analysis
Model your product's deployment context and interfaces. AI rules out CVEs that don't apply to your device.
See It In Action
Explore real analysis results — no account required.
Kernel .config VEX
The same kernel .config analysed with version and config filtering only. Pure config analysis — every CVE matching an enabled subsystem is reported, without deployment context.
Product Security Assessment
The same config with deployment context, interfaces, and hardening modelled. AI contextual analysis rules out CVEs that don't apply to this device.
High severity, AI-triaged
Latest Linux kernel disclosures
-
CVSS7.8AI
vmwgfx SurfaceArray OOBCVE-2026-68446
A local user with access to the VMware graphics DRM device can supply an unchecked array size when creating GPU surfaces, potentially causing heap memory corruption. This can lead…
-
CVSS7.5AI
drm/vc4 ShaderBO BypassCVE-2026-68445
A local user with access to the vc4 DRM device (Raspberry Pi GPU) can bypass the kernel's shader validator by mapping a validated shader buffer object read-only and then upgrading…
-
CVSS7.4AI
ksmbd Transform OOBCVE-2026-68431
ksmbd SMB server fails to validate minimum PDU size for transform requests, allowing an unauthenticated network attacker to send a truncated transform packet that causes the server…
-
CVSS7.0AI
smp CsdLock RaceCVE-2026-68438
A race condition in the kernel's SMP inter-processor interrupt (IPI) infrastructure can cause a target CPU to become stuck in an infinite loop, leading to soft-lockup warnings or a…
-
CVSS7.0AI
btrfs ExtentMap UAFCVE-2026-68442
A use-after-free in the btrfs extent map handling can be triggered by any local user performing file operations on a mounted btrfs filesystem. The bug requires a race between exten…
-
CVSS7.0AI
amdkfd Checkpoint OOBCVE-2026-68447
A local user with access to an AMD GPU compute device can trigger a CRIU checkpoint operation that copies more data than was allocated for the control stack buffer, reading into ad…
-
CVSS9.8AI
libceph OSDMap OOBCVE-2026-68159
A malicious or compromised Ceph monitor can send a crafted OSDMap containing pg_temp or pg_upmap entries longer than the maximum allowed size. The Ceph client kernel code decodes t…
-
CVSS9.8AI
sctp AuthHmacs OverflowCVE-2026-68376
A network attacker can trigger a buffer overflow in the SCTP cookie's HMAC algorithm storage by sending SCTP association setup packets to a peer configured with four HMAC identifie…
-
CVSS9.8AI
ila CsumAdjust UAFCVE-2026-68127
A remote attacker can trigger a use-after-free in the kernel's ILA subsystem by sending a crafted non-linear IPv6 packet through a device with an ILA checksum-adjust-transport rout…
Linux Kernel CVE Database
Freely searchable. Sourced from NVD and kernel.org's CVE v5 git feed, AI-enriched within minutes of publication.
| CVE ID | Severity | CVSS | Description | Introduced | Published |
|---|
Plans & Pricing
From free CVE intelligence to full AI-powered security assessments.
Free
Basic
Pro
Enterprise
Enterprise is our custom tier — contact sales and we'll agree on price and features for your needs (unlimited products, any kernel version). It's also the route for analyzing kernels on behalf of clients — security consultancies, auditors, managed-service providers — which is a separate field of use under our terms. Talk to sales.
| Feature | Free | Basic | Pro | Enterprise |
|---|---|---|---|---|
| VEX analyses / month | 2 | Unlimited | Unlimited | Unlimited |
| Persistent products | — | 3 | 10 | Unlimited |
| Kernel coverage | Current LTS | Current LTS | All active LTS + stable | Any version |
| CVE database search | ✓ | ✓ | ✓ | ✓ |
| Live CVE feed (AI + Dependency-Track) | Last 60 days | All CVEs | All CVEs | All CVEs |
| API access | Throttled | Throttled | Full speed | Full speed |
| CycloneDX VEX reports | ✓ | ✓ | ✓ | ✓ |
| AI contextual assessments | — | — | ✓ | Priority |
| Security factor analysis | — | — | ✓ | ✓ |
| Dashboard & email alerts | — | ✓ | ✓ | ✓ |
| Auto-push VEX to Dependency-Track | — | — | ✓ | ✓ |
| Team Support | — | — | — | ✓ |
| On Premise | — | — | — | ✓ |