Astra Linux Common Edition
2,020 CVEs tracked. 25 of them are in CISA KEV.
This hub aggregates every CVE we track for Astra Linux Common Edition, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Astra Linux Common Edition CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 52 |
| 2024-11 | 51 |
| 2024-12 | 30 |
| 2025-01 | 51 |
| 2025-02 | 35 |
| 2025-03 | 32 |
| 2025-04 | 48 |
| 2025-05 | 46 |
| 2025-06 | 29 |
| 2025-07 | 47 |
| 2025-08 | 30 |
| 2025-09 | 42 |
| 2025-10 | 11 |
| 2025-11 | 61 |
| 2025-12 | 2 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 2 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 2,020 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical218
- High876
- Medium849
- Low77
Latest CVEs
The 15 most recently published vulnerabilities affecting Astra Linux Common Edition.
- CVE-2026-43500rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present7.8
- CVE-2026-43284xfrm: esp: avoid in-place decrypt on shared skb frags8.8
- CVE-2026-31431crypto: algif_aead - Revert to operating out-of-place7.8
- CVE-2023-53836bpf, sockmap: Fix skb refcnt race after locking changes7.8
- CVE-2025-13992Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security sev...4.7
- CVE-2025-13228Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2025-13230Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2025-13229Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2025-13227Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2025-13226Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2025-13224Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2025-13223Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2025-13107Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)4.3
- CVE-2024-13178Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)4.3
- CVE-2025-9479Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)4.3
Product grouping is registry-driven, with AI assist and human review. How it works