// kernel tracker

Linux 6.18.38

LTS // updated 2026-07-25
running
6.18.38
open CVEs
12
next fix
6.18.39
11 CVEs
fix versions
2
6.18.39, 6.18.40
CVEs — Linux 6.18.38
CVE Fixed In Score Description Links
CVE-2026-53399 6.18.39 9.8 Critical nfsd: release layout stid on setlease failure ↗ CVE ⌥ commit
CVE-2026-63819 6.18.39 7.8 High f2fs: fix to do sanity check on f2fs_get_node_folio_ra() ↗ CVE ⌥ commit
CVE-2026-63816 6.18.39 7.8 High f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode ↗ CVE ⌥ commit
CVE-2026-63815 6.18.39 8.4 High f2fs: bound i_inline_xattr_size for non-inline-xattr inodes ↗ CVE ⌥ commit
CVE-2026-53402 6.18.39 7.1 High fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() ↗ CVE ⌥ commit
CVE-2026-64227 6.18.40 ACPI: driver: Check ACPI_COMPANION() against NULL during probe ↗ CVE ⌥ commit
CVE-2026-64600 6.18.39 xfs: resample the data fork mapping after cycling ILOCK ↗ CVE ⌥ commit
CVE-2026-64207 6.18.39 net/sched: dualpi2: fix GSO backlog accounting ↗ CVE ⌥ commit
CVE-2026-64206 6.18.39 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock ↗ CVE ⌥ commit
CVE-2026-64205 6.18.39 i2c: i801: fix hardware state machine corruption in error path ↗ CVE ⌥ commit
CVE-2026-64189 6.18.39 netfilter: ipset: fix race between dump and ip_set_list resize ↗ CVE ⌥ commit
CVE-2026-64187 6.18.39 xfs: fail recovery on a committed log item with no regions ↗ CVE ⌥ commit

LLVM musl libc libressl Independent