Linux CVE assignment process

· Greg Kroah-Hartman · Feb. 16, 2026, 2:10 p.m.
Summary
This blog post discusses how the Linux kernel security team currently assigns and identifies CVEs (Common Vulnerabilities and Exposures) and explores the potential process for the Linux kernel to become a CVE Numbering Authority (CNA). It details both the automatic assignment of CVEs and alternative methods for issuing them, providing insights into the security measures surrounding the Linux kernel.
AUTHOR
Sponsored
Zulip logo Zulip
Organized team chat for people who take work seriously. Topic-based threading keeps conversations focused.
Try Zulip
Become a sponsor →
BLOG POST FEATURED ON

Add this plugin to your blog