Distributions
Jump directly to maintainer-maintained trackers. Always reconcile package versions with security announcements—never infer patch levels from kernel marketing names alone.
Ubuntu
Canonical CVE pages & Dirty Frag blog
Debian
security-tracker.debian.org matrices
Red Hat ecosystem
Customer Portal + Bugzilla
Additional derivatives (AlmaLinux, Rocky, Amazon Linux, etc.) inherit guidance from their upstream rebuild policies—monitor those vendors' CVE portals similarly.