Linux Kernel Security Intelligence
Know your kernel's
real exposure
Upload a .config and get a CycloneDX VEX report — filtered by kernel version, build configuration, and AI‑powered context analysis. Updated in real time as new CVEs appear.
Free tier · no credit card · no invitation needed
Free CVE Database
Browse and search all kernel CVEs instantly — including AI-assessed scores where NVD is still pending. Sign up free to run your first VEX analysis.
Version & Config-Aware VEX
Filter by kernel version and .config — get a CycloneDX VEX of precisely your build's exposure. Analyses update automatically when new CVEs land.
AI-Powered Context Analysis
Model your product's deployment context and interfaces. AI rules out CVEs that don't apply to your device.
See It In Action
Explore real analysis results — no account required.
Kernel .config VEX
The same kernel .config analysed with version and config filtering only. Pure config analysis — every CVE matching an enabled subsystem is reported, without deployment context.
Product Security Assessment
The same config with deployment context, interfaces, and hardening modelled. AI contextual analysis rules out CVEs that don't apply to this device.
High severity, AI-triaged
Latest Linux kernel disclosures
-
CVSS8.8NVD
bluetooth ISOListener UAFCVE-2026-80914
A user who can manipulate Bluetooth ISO sockets on the target can exploit a race against an incoming connection from a nearby Bluetooth device to trigger a use-after-free in the ke…
-
CVSS8.8NVD
kvm CryptoBits LeakCVE-2026-80921
A nested guest running on an s390x KVM host with nested virtualization enabled can retain access to cryptographic devices that have been revoked or were never assigned, due to stal…
-
CVSS7.5NVD
krb5 DerivedKey LeakCVE-2026-80924
The Kerberos crypto subsystem frees buffers containing freshly derived encryption and checksum keys without zeroing them, leaving sensitive key material in freed kernel slab object…
-
CVSS7.0AI
kcov RemoteCoverage RaceCVE-2026-80916
A race condition in the KCOV subsystem on PREEMPT_RT kernels allows a local unprivileged user to corrupt kernel memory by triggering nested softirq preemption during remote coverag…
-
CVSS9.8AI
seg6 IPIPDecap OOBCVE-2026-80840
A remote, unauthenticated attacker can send a crafted IPv6 Segment Routing packet to a target with seg6local End.DX4 or End.DT4 actions configured, causing a heap out-of-bounds wri…
-
CVSS9.1AI
ipvs Checksum BypassCVE-2026-80901
IPVS on Linux kernels since 2.6.28 fails to validate checksums for ICMPv6 packets from clients and for ICMPv6 replies from real servers when hardware checksum offload is not availa…
-
CVSS8.8AI
nfc TargetList OOBCVE-2026-80795
A missing bounds check in the NFC NCI subsystem allows a nearby NFC device to overflow a fixed-size kernel target array by repeatedly triggering discovery and auto-activation. This…
-
CVSS8.8AI
batman-adv MulticastTvlv OOBCVE-2026-80839
A remote attacker on the same batman-adv mesh network can send a crafted multicast TVLV packet with an oversized offset, causing the kernel to access memory beyond the packet buffe…
-
CVSS8.8AI
nfc SensfRes OverflowCVE-2026-80803
A nearby malicious NFC-F device can send an oversized SENSF_RES polling response that overflows a fixed-size stack buffer in the kernel's NFC digital layer. This stack overflow can…
Linux Kernel CVE Database
Freely searchable. Sourced from NVD and kernel.org's CVE v5 git feed, AI-enriched within minutes of publication.
| CVE ID | Severity | CVSS | Description | Introduced | Published |
|---|
Plans & Pricing
From free CVE intelligence to full AI-powered security assessments.
Free
Basic
Pro
Enterprise
Price & features agreed with you · billed by invoice against a contract — no credit card
Enterprise is our custom tier — contact sales and we'll agree on price and features for your needs (unlimited products, any kernel version). Unlike Basic and Pro, Enterprise is billed by invoice against a written contract: you get a quote, we agree the terms, and you pay by bank transfer on an invoice carrying your purchase-order number — no credit card anywhere in the process. It's also the route for analyzing kernels on behalf of clients — security consultancies, auditors, managed-service providers — which is a separate field of use under our terms. Talk to sales.
| Feature | Free | Basic | Pro | Enterprise |
|---|---|---|---|---|
| VEX analyses / month | 2 | Unlimited | Unlimited | Unlimited |
| Persistent products | — | 3 | 10 | Unlimited |
| Kernel coverage | Current LTS | Current LTS | All active LTS + stable | Any version |
| CVE database search | ✓ | ✓ | ✓ | ✓ |
| Live CVE feed (AI + Dependency-Track) | Last 60 days | All CVEs | All CVEs | All CVEs |
| API access | Throttled | Throttled | Full speed | Full speed |
| CycloneDX VEX reports | ✓ | ✓ | ✓ | ✓ |
| AI contextual assessments | — | — | ✓ | Priority |
| Security factor analysis | — | — | ✓ | ✓ |
| Dashboard & email alerts | — | ✓ | ✓ | ✓ |
| Auto-push VEX to Dependency-Track | — | — | ✓ | ✓ |
| Team Support | — | — | — | ✓ |
| On Premise | — | — | — | ✓ |