CVE Tools

Alt Linux

5,265 CVEs tracked. 48 of them are in CISA KEV.

This hub aggregates every CVE we track for Alt Linux, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Alt Linux CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Alt Linux CVEs per month
MonthCVEs
2024-10129
2024-1148
2024-1214
2025-0175
2025-0258
2025-0363
2025-04108
2025-0552
2025-0666
2025-07181
2025-08106
2025-09178
2025-1066
2025-1153
2025-1289
2026-01150
2026-0253
2026-0374
2026-0473
2026-0557
2026-060
2026-070
2026-080
2026-090

Severity

How the 5,265 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical3777%
  • High2,23242%
  • Medium2,40846%
  • Low2485%

Latest CVEs

The 15 most recently published vulnerabilities affecting Alt Linux.

  1. CVE-2026-40033FreeRDP - Heap-buffer-overflow in gdi_CacheToSurface via rectangle validation bypass8.8
  2. CVE-2026-9256NGINX ngx_http_rewrite_module vulnerability8.1
  3. CVE-2026-7504Org.keycloak/keycloak-services: open redirect when using wildcard valid redirect uris in keycloak8.1
  4. CVE-2026-7307Keycloak: keycloak: denial of service via specially crafted saml input7.5
  5. CVE-2026-6638PostgreSQL REFRESH PUBLICATION allows SQL injection via table name3.7
  6. CVE-2026-6637PostgreSQL refint allows stack buffer overflow and SQL injection8.8
  7. CVE-2026-6478PostgreSQL discloses MD5-hashed passwords via covert timing channel6.5
  8. CVE-2026-6479PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion7.5
  9. CVE-2026-6477PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory8.8
  10. CVE-2026-6475PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice8.8
  11. CVE-2026-6474PostgreSQL timeofday() can disclose portions of server memory4.3
  12. CVE-2026-6473PostgreSQL server undersizes allocations, via integer wraparound8.8
  13. CVE-2026-6472PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege5.4
  14. CVE-2026-42926NGINX ngx_http_proxy_v2_module vulnerability5.8
  15. CVE-2026-40460NGINX ngx_quic_module vulnerability6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store