A Go CLI tool that checks a running Linux system for known kernel CVE vulnerabilities and reports whether the system is safe, vulnerable, or unknown.
make build # dynamic build (local dev)
make build-static # fully static build (CGO_ENABLED=0)./linux-cve-checker # readable output (default)
./linux-cve-checker -format json # JSON outputExit code is 0 if the verdict is safe, otherwise 1.
- CVE-2026-31431 (
CopyfailChecker)
make test # run all tests
make vet # go vet ./...
make fmt # go fmt ./...