Skip to main content

TECH VEDA

Embedded Linux on Edge-AI 23rd Sept 2026 enrollingLinux kernel & Device drivers starts on 24th Oct 2026 enrollingCorporate on-site training - Submit proposal Pick your modulesSharpen your kernel skills: deep dives, drivers, Yocto, CVEs, careers — updated daily. Read the blog →Embedded Linux fast track starts 30th sept 2026 enrollingEmbedded Linux Mastery track starts 30th sept 2026 enrollingLinux systems engineering starts 30th sept 2026 enrolling

BSP Tracker  /  Kernel CVEs

What the kernel published, and whether the fix reached you

The Linux kernel CNA publishes CVEs at a rate that swings by two orders of magnitude from one week to the next, and a fix landing upstream is not the same event as a fix landing in the tree your product builds from. This page tracks both halves.

Last checked 19 September 20262,875 CVEs in the last 7 weeksNewest stable cycle 14 September 2026Source linux-cve-announce, NVD

Reading this page

The kernel project assigns no CVSS scores, by policy. Severity in the kernel is a function of what you build and where the device sits, and a single number cannot carry that. Where a score appears in a kernel record it is the CNA’s own secondary metric, not NVD’s. NVD analysis for a large batch can trail publication by weeks. Prioritise by reachability, not by a number.

Weekly volume is not a quality signal. The 7 windows on record run from 6 to 1,086. A spike is usually the CNA catching up — a backlog of older assignments published in one batch, or a full stable cycle landing at once — not a week when the kernel got worse. Each row says which.

A commit date proves a branch is alive, not that a fix is in it. The second table measures the gap between the newest upstream release in a series and the last commit on the vendor branch that pins it. A branch that moved yesterday may still not carry this cycle’s backports — the date narrows where to look, it does not close the question. Read the branch log before you ship.

The per-CVE detail lives in the weekly advisory, linked from each row. This page carries what stays true between them.

Kernel CVE publication, by week

September 20262 weeks · 1,321 CVEs · range 443–878

Linux kernel CVEs published per week in September 2026, with the reason for each change in volume
WindowCVEs publishedRejectedScored in recordWhat moved the number
13 – 19 Sep 20268782319 of 878Roughly double the previous week by volume, but with fewer CRITICAL records: 35 against 54. The IDs are not one continuous run — they arrive in four blocks, CVE-2026-89774 to 90435, 92476 to 92525, 93037 to 93086 and 93089 to 93204 — so computing IDs across the range produces CVEs that do not exist. The 35 CRITICAL records are spread across NVMe over Fabrics, ksmbd, NFS server and client, Ceph, IPsec, KVM on arm64 and x86, NTFS3, ISO9660, iSER and qla2xxx rather than clustered in one area as last week. Every branch target equals the current kernel.org release for that branch, so the patch table is a confirmed ceiling. 7.1 reached end of life at 7.1.13 and takes no fixes from this set. Count is single-sourced to NVD; lore.kernel.org was unreachable behind Anubis. Full advisory →
6 – 12 Sep 2026443174 of 443The largest ordinary week of the year so far, and by a wide margin the most severe. Unlike the 1,086 below this is genuine weekly output, not a backlog: two ID blocks, CVE-2026-80914 to CVE-2026-81018 and CVE-2026-89436 to CVE-2026-89773. 54 records carry a CRITICAL score from the CNA. Almost all of them sit in network filesystem and RPC code — NFSD, ceph, SMB client and ksmbd, SUNRPC and ntfs3 — and most are reachable over the network without credentials. It reads as a coordinated audit of that code rather than an ordinary week. Several records name a fix only on 7.2 and mainline, so the branch bump does not clear every one. Full advisory →

Earlier months are kept below, collapsed. The totals and the bar scale on this page still span every week on record, so a bar means the same thing in any month.

August 20265 weeks · 1,554 CVEs · range 6–1,086
Linux kernel CVEs published per week in August 2026, with the reason for each change in volume
WindowCVEs publishedRejectedScored in recordWhat moved the number
30 Aug – 5 Sep 2026188018 of 188Ordinary weekly rate on the 2 September stable cycle: 188 contiguous IDs, CVE-2026-80726 to CVE-2026-80913, none rejected. Counted on 5 September before the window closed, so it may still rise. Full advisory →
23 – 29 Aug 2026228A full stable cycle landed on 28 August and the records for everything in it were published together — nothing at all was published 23 to 25 Aug, then 92 on the 26th and 135 on the 28th. Full advisory →
16 – 22 Aug 2026651 of 6A return to normal rate after the backlog cleared. Six contiguous IDs, CVE-2026-74578 to 74583. Full advisory →
9 – 15 Aug 20261,086Not one week of new bugs. The CNA published a backlog of older assignments in two large ID blocks. NVD counted 1,082 in the same window.
2 – 8 Aug 202646Ordinary week. Every record already fixed in a stable release. Full advisory →

Range across all 7 weeks on record: 6 to 1,086. The bar is a log scale. On a linear one an ordinary week next to a backlog flush is an invisible sliver, which would misrepresent both.

The fix shipped upstream. Has it reached your vendor tree?

Every maintained longterm series took a patch release on 14 September 2026. Each row below is one of the 17 SoCs on the BSP status table, showing the gap between that release and the last commit on the vendor branch it pins. 6 of 17 have not moved since that cycle.

Vendor tree state
No stream or frozen
No upstream longterm behind it, or no commit in over a year.
Lagging or stalled
Alive, but has missed the most recent stable cycles.
Tracking
Moved within a fortnight of the last stable cycle. Still verify the log.
Vendor BSP branches and how far behind the newest upstream release in their series they are
SoCVendor branchSeriesNewest upstreamBranch last movedBehind by
No upstream fix stream1The branch pins a kernel series that was never longterm. There is no upstream stable release to be behind, and no security backports are coming from kernel.org at all.
NVIDIA Jetson Orin (Tegra234)
NVIDIA
Jetson Linux 39.2.1 (JetPack 7.2.1)6.8none — not a longterm series11 August 2026No upstream fix stream
Frozen — over a year1The branch has taken no commit in more than a year. Whatever the last stable cycle fixed, this tree has not carried it.
Amlogic A311D (G12B)
Amlogic
khadas-linux-6.12.y6.126.12.110
14 September 2026
5 August 2025405 days
Lagging — 2 weeks to 4 months4The branch is alive but has not moved since the last full stable cycle. The most recent round of fixes has not landed on it yet.
Rockchip RK3588 / RK3588S
Rockchip
develop-6.16.16.1.188
14 September 2026
29 July 202647 days
Renesas RZ/G2L (R9A07G044)
Renesas
rz-6.12-cip146.126.12.110
14 September 2026
25 May 2026112 days
ST STM32MP1 (STM32MP157)
STMicroelectronics
v6.6-stm32mp6.66.6.157
14 September 2026
1 June 2026105 days
ST STM32MP2 (STM32MP257)
STMicroelectronics
v6.6-stm32mp6.66.6.157
14 September 2026
1 June 2026105 days
Tracking — within a fortnight10The branch moved within a fortnight of the last stable cycle. That is the best signal a commit date can give, and it is still not proof the fixes were merged.
TI AM335x (Sitara)
Texas Instruments
ti-linux-6.18.y6.186.18.52
14 September 2026
16 September 2026-2 days
TI AM62A (AM62A7)
Texas Instruments
ti-linux-6.18.y6.186.18.52
14 September 2026
16 September 2026-2 days
TI AM62x (AM625)
Texas Instruments
ti-linux-6.18.y6.186.18.52
14 September 2026
16 September 2026-2 days
NXP i.MX6ULL
NXP
lf-6.18.y6.186.18.52
14 September 2026
8 September 20266 days
NXP i.MX8M Plus
NXP
lf-6.18.y6.186.18.52
14 September 2026
8 September 20266 days
NXP i.MX93
NXP
lf-6.18.y6.186.18.52
14 September 2026
8 September 20266 days
TI J721E / TDA4VM
Texas Instruments
ti-linux-6.18.y6.186.18.52
14 September 2026
16 September 2026-2 days
Qualcomm QCS6490 (RB3 Gen 2)
Qualcomm
qcom-6.18.y6.186.18.52
14 September 2026
19 September 2026-5 days
Microchip SAMA7G5 (SAMA7G54)
Microchip
linux-6.18-mchp6.186.18.52
14 September 2026
17 September 2026-3 days
AMD Zynq UltraScale+ MPSoC
AMD (Xilinx)
xlnx_rebase_v6.18_LTS6.186.18.52
14 September 2026
4 September 202610 days
No public tree1The vendor publishes no browsable git for this SoC, so there is nothing to date. Recorded as unknown rather than guessed.
Allwinner T507 / T527
Allwinner
Tina 5.0_AIOT5.155.15.221
14 September 2026
no public treeNo public tree

The weekly advisory

Every week we read the CNA announcements, cross-check the count against NVD, and write up what to patch by device class — with the minimum safe release for each branch. That is where the individual CVEs are discussed. This page carries the shape of the problem; the advisory carries the week.

All kernel CVE advisories →

Get the updates

An email when a kernel series reaches end of life, a board row changes, or a layer picks up a release branch. Nothing else.

RSS