Blog

Notes from the KernelScan team

Announcements, deep dives, and the occasional war story from building Linux kernel CVE intelligence.

  1. 10 min read

    Kernel CVE Batch Analysis: September 24-25, 2026 (606 CVEs, 36 of them remote)

    606 Linux kernel CVEs landed on September 24-25, 2026 - 7 Critical, 36 network-reachable Highs, and a new twist: the server is often the attacker.

    Read more CVE triageLinux kernelProduct security
  2. 14 min read

    Triaging kernel CVEs on a router nobody patches anymore: a FRITZ!Box 7412 walkthrough

    An EOL DSL router on Linux 3.10.73: 20,059 kernel CVEs go in, 595 come out affected, and a config-level triage narrows it to what an attacker can actually reach. Five steps, with KernelScan.

    Read more Linux kernelProduct securityReachabilityCVE triage
  3. 13 min read

    Kernel CVE Batch Analysis: September 16-17, 2026 (878 CVEs, 62 of them remote)

    878 Linux kernel CVEs landed on September 16-17, 2026 - 37 Critical, but only 62 of the 376 high-rated entries are network-reachable. A product triage.

    Read more CVE triageLinux kernelProduct security
  4. 5 min read

    Four Public Root Exploits Dropped Today. We Had the CVEs Since August.

    On September 18, working local-root exploits went public for four Linux kernel CVEs. KernelScan had ingested every one of those CVEs on its publication day — and NVD still hasn't scored one of them.

    Read more exploit-maturityreachabilityVEXlinux-kernel
  5. 11 min read

    Kernel CVE Batch Analysis: September 11, 2026 (431 CVEs, a file-server batch)

    431 Linux kernel CVEs landed on September 11, 2026 — 71 Critical, 53 of them in the NFS, Ceph, SMB and OCFS2 file-server stack. A product-triage walkthrough.

    Read more CVE triageLinux kernelProduct security
  6. 18 min read

    24 Hours to Report. Unless the Code Isn’t Reachable?

    From 11 September 2026 the Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities within 24 hours. For Linux-based products, the Commission’s own guidance says an unreachable kernel CVE isn’t reportable — here is what that actually means.

    Read more CRAComplianceLinux kernelProduct security
  7. 7 min read

    BadGarbage (CVE-2026-53361): why product security needs real-time exploit and PoC intelligence

    Two public exploits, wrong published version ranges, vendor trackers weeks behind. CVE-2026-53361 as a worked case for why product security needs a real-time source of the latest exploits and PoCs.

    Read more Linux kernelExploit maturityCVE triageReachability
  8. 7 min read

    Exploit Maturity Is Live: Public Kernel PoCs Now Surface in KernelScan

    KernelScan now distinguishes public PoCs, weaponized exploits and CISA KEV—and carries both urgency signals into owner-facing CycloneDX VEX exports.

    Read more Linux kernelCVE triageExploit maturityCISA KEV
  9. 12 min read

    Kernel CVE Batch Analysis: August 15, 2026 (848 CVEs, 338 awaiting NVD scores)

    848 Linux kernel CVEs landed on August 15. We sort all of them by severity, subsystem, and attacker reachability to expose the product-relevant queue.

    Read more CVE triageLinux kernelProduct security
  10. 11 min read

    Kernel CVE Batch Analysis: August 10, 2026 (346 CVEs, none scored by NVD)

    A product-focused triage of 346 Linux kernel CVEs published in a single day on August 10, 2026 — every one still unscored by NVD.

    Read more CVE triageLinux kernelProduct security
  11. 8 min read

    RefluXFS (CVE-2026-64600): am I actually vulnerable?

    A nine-year-old XFS reflink race just became local root on default RHEL. How to decide whether your product is actually affected — from the config symbol, through the USB-stick reflex, to the staggered backport timeline your scanner won’t show you.

    Read more Linux kernelXFSVEXReachability
  12. 14 min read

    Kernel CVE Batch Analysis: July 19, 2026 (431 CVEs, none scored by NVD)

    A product-focused triage of 431 Linux kernel CVEs published in a single day on July 19, 2026 — none scored by NVD — with a hard look at the ~72 local privilege-escalation bugs, including the keyring, statmount and block-layer ones you can't compile out.

    Read more CVE triageLinux kernelProduct security
  13. 8 min read

    Your Scanner Isn’t Wrong. Neither Is NVD. So Why Does It Flag Kernel CVEs You Don’t Have?

    We counted: on a fully-patched LTS kernel, up to 46% of scanner-reported kernel CVEs don’t apply to it. Nobody made a mistake — the cause is structural, and verifiable from public data.

    Read more SBOMCPELinux kernelCVE triageVEX
  14. 4 min read

    Introducing the KernelScan Analyzer Plugin for Dependency-Track 5

    Our open-source Dependency-Track 5 analyzer plugin surfaces KernelScan's config-aware kernel CVE analysis in DT — only the CVEs reachable in your .config, no NVD noise.

    Read more Dependency-TrackLinux kernelSBOMCVE triageOpen source
  15. 8 min read

    CVSS Said 9.8. Your Kernel Config Said “Not Affected.”

    Why NVD, Red Hat and a config-based analysis give three different answers for the same June 2026 kernel CVEs — and which one is about your system.

    Read more CVE triageLinux kernelCVSSProduct security
  16. 8 min read

    Hidden in 219 unscored kernel CVEs: CVE-2026-52943, an 8.4 local root that may not be present in your kernel at all

    Buried in 219 kernel CVEs with no NVD scores: a reliable local root in code every kernel ships — yet whether it can touch you comes down to one question the score never answers: is the gating config option, and the module that reaches it, even present in the kernel you run?

    Read more CVE heads-upPrivilege escalationLinux kernel
  17. 11 min read

    Kernel CVE Batch Analysis: June 24, 2026 (219 CVEs, none scored by NVD)

    A product-focused triage of 219 Linux kernel CVEs published in a single day on June 24, 2026 — every one still unscored by NVD.

    Read more CVE triageLinux kernelProduct security
  18. 10 min read

    Kernel CVE Batch Analysis: June 6-9, 2026 (62 CVEs)

    A product-focused triage of 62 Linux kernel CVEs published June 6-9, 2026 while NVD scoring is still pending.

    Read more CVE triageLinux kernelProduct security
  19. 2 min read

    KernelScan is open — request your invitation code

    KernelScan is live in invite-only early access. Here's what we built, why we're ramping up gradually, and how to get your invitation code.

    Read more Announcements