Linux CVE assignment process

140 · Greg Kroah-Hartman · Feb. 16, 2026, 2:10 p.m.
Summary
This blog post discusses how the Linux kernel security team currently assigns and identifies CVEs (Common Vulnerabilities and Exposures) and explores the potential process for the Linux kernel to become a CVE Numbering Authority (CNA). It details both the automatic assignment of CVEs and alternative methods for issuing them, providing insights into the security measures surrounding the Linux kernel.