Skip to content

Vendors

Linux

24records3productslast change2026-08-28RSSas of the 2026-09-07 snapshot

Rows per week, last 26 weeks

19 rows in the last 26 weeks, 0 in the week to 2026-09-070 this week

When Linux edits: same day → over a year

Linux: 26 counted rows by the interval to the first recorded revision: 4 same day, 4 1 to 7 days, 11 8 to 30 days, 1 31 to 90 days, 6 91 to 365 days; 1 more with no located commit, not dated26 counted rows as publisher

Rows, not records: one record that changed for four products is four rows and one record. 11 of the 24 records raised a stated fix version; that is the count the publisher scorecard rates.

Every change, newest first

lines 21 to 40 of 40 · standing on 21 of 41 rows
Every counted change to a CVE or CISA KEV record naming Linux, newest first. A line standing for the same change across several records or products says how many and opens to every one.
Changed on, The day the commit that carried this change was read. Where the same change spans several days, the first and the last, never a midpoint. Not dated means no commit could be located for the row.ChangeCVEProductWhat the record says now
2025-10-30Ransomware use confirmedCVE-2024-1086Kernelstated at publication Unknown, now states Known
2025-10-06Added to CISA KEVCVE-2021-22555Kernellisted by CISA 2025-10-06federal fix due 2025-10-27
2025-10-02Fix version movedCVE-2025-38709Linuxstated at publication 6.6.103, now states 6.6.109
2025-10-02Fix version movedCVE-2023-53431Linuxstated at publication 4.19.276, now states 4.19.281
2025-10-02Fix version movedCVE-2023-53431Linuxstated at publication 5.10.173, now states 5.10.178
2025-10-02Fix version movedCVE-2023-53431Linuxstated at publication 5.15.99, now states 5.15.108
2025-10-02Fix version movedCVE-2023-53431Linuxstated at publication 5.4.235, now states 5.4.241
2025-10-02Fix version movedCVE-2023-53431Linuxstated at publication 6.1.16, now states 6.1.25
2025-10-02Fix version movedCVE-2023-53431Linuxstated at publication 6.2.3, now states 6.2.12
2025-09-04Added to CISA KEVCVE-2025-38352Kernellisted by CISA 2025-09-04federal fix due 2025-09-25
2025-06-17Added to CISA KEVCVE-2023-0386Kernellisted by CISA 2025-06-17federal fix due 2025-07-08
2025-04-25Fix version movedCVE-2025-22077Linuxstated at publication 6.12.23, now states 6.12.25
2025-04-25Fix version movedCVE-2025-22077Linuxstated at publication 6.14.2, now states 6.14.4
2025-04-25Fix version movedCVE-2025-22077Linuxstated at publication 6.6.87, now states 6.6.88
2025-04-09Added to CISA KEVKernellisted by CISA 2025-04-09federal fix due 2025-04-30
2025-04-09Added to CISA KEVCVE-2024-53150Kernellisted by CISA 2025-04-09federal fix due 2025-04-30
2025-04-09Added to CISA KEVCVE-2024-53197Kernellisted by CISA 2025-04-09federal fix due 2025-04-30
2025-03-04Added to CISA KEVCVE-2024-50302Kernellisted by CISA 2025-03-04federal fix due 2025-03-25
2025-02-05Added to CISA KEVCVE-2024-53104Kernellisted by CISA 2025-02-05federal fix due 2025-02-26
2025-01-24Fix version movedCVE-2025-21654Linuxstated at publication 6.6.72, now states 6.6.74
2025-01-24Fix version movedCVE-2024-26885Linuxstated at publication 5.10.214, now states 5.10.227
2023-06-28Fix version movedCVE-2023-3389Kernelstated at publication 6.0, now states 6.4

A line that names a count is the same change on that many records or products, shown once; it opens to every member. A closed line is not reached by find-in-page; the flat view (Every row, flat →) is. Only counted changes are here: a change a kind's false-positive filter refused, such as a product line being renumbered, is in no figure on this page.

Data sources and quality

One vendor, every counted kind of change: the rows where a CVE record or a CISA KEV entry naming Linux changed after publication. The vendor name is the record's own text, compared without regard to case, so one organisation can appear under more than one spelling and this page holds the spellings that share its web address. Rows and records are different numbers and are never added together.

Not counted: a product line being renumbered, a boundary already named in the record's own description, and the other refusal classes are filtered as false positives and are in no figure here, so this page is what survived those filters rather than everything the catalog changed for this vendor.

Not checked: a record published before 2023 cannot have its state at publication recovered and was never compared, and a CISA KEV listing added before the first mirrored commit was never seen changing, so an absence from this page is not evidence that a record held.

How every one of these figures is measured, in full →

Shipped snapshot computed 2026-09-07 from catalog commit ed5547afbae2. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.