VendorsLinuxlinux_kernel6.7
Vulnerabilities

Linux Kernel 6.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

51CVEs
CVE-2023-52881
tcp: do not accept ACK of bytes we never sent
Published 2024-05-29 · Modified
9.8EPSS 0.006
CVE-2023-52775
net/smc: avoid data corruption caused by decline
Published 2024-05-21 · Modified
8.2EPSS 0.007
CVE-2023-52434
smb: client: fix potential OOBs in smb2_parse_contexts()
Published 2024-02-20 · Modified
8.1EPSS 0.010
CVE-2024-0582
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
Published 2024-01-16 · Modified
7.8EPSS 0.128
CVE-2023-52654
io_uring/af_unix: disable sending io_uring over sockets
Published 2024-05-09 · Modified
7.8EPSS 0.009
CVE-2024-35880
io_uring/kbuf: hold io_buffer_list reference over mmap
Published 2024-05-19 · Modified
7.8EPSS 0.007
CVE-2024-21803
Possible UAF in bt_accept_poll in Linux kernel
Published 2024-01-30 · Analyzed
7.8EPSS 0.005
CVE-2023-6817
Use-after-free in Linux kernel's netfilter: nf_tables component
Published 2023-12-18 · Modified
7.8EPSS 0.003
CVE-2024-0646
Kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination
Published 2024-01-17 · Modified
7.8EPSS 0.003
CVE-2024-22705
An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mishandled.
Published 2024-01-23 · Modified
7.8EPSS 0.003
CVE-2023-52807
net: hns3: fix out-of-bounds access may occur when coalesce info is read via debugfs
Published 2024-05-21 · Analyzed
7.8EPSS 0.002
CVE-2023-52796
ipvlan: add ipvlan_route_v6_outbound() helper
Published 2024-05-21 · Analyzed
7.8EPSS 0.002
CVE-2023-52795
vhost-vdpa: fix use after free in vhost_vdpa_probe()
Published 2024-05-21 · Analyzed
7.8EPSS 0.002
CVE-2024-35785
tee: optee: Fix kernel panic caused by incorrect error handling
Published 2024-05-17 · Modified
7.8EPSS 0.002
CVE-2025-22015
mm/migrate: fix shmem xarray update during migration
Published 2025-04-08 · Modified
7.8EPSS 0.002
CVE-2024-41086
bcachefs: Fix sb_field_downgrade validation
Published 2024-07-29 · Modified
7.8EPSS 0.002
CVE-2024-35793
debugfs: fix wait/cancellation handling during remove
Published 2024-05-17 · Modified
7.8EPSS 0.002
CVE-2026-31554
futex: Require sys_futex_requeue() to have identical flags
Published 2026-04-24 · Analyzed
7.8EPSS 0.002
CVE-2025-71086
net: rose: fix invalid array index in rose_kill_by_device()
Published 2026-01-13 · Modified
7.8EPSS 0.001
CVE-2023-6200
Kernel: icmpv6 router advertisement packets, aka linux tcp/ip remote code execution vulnerability
Published 2024-01-28 · Modified
7.5EPSS 0.022
CVE-2026-46110
net: stmmac: Prevent NULL deref when RX memory exhausted
Published 2026-05-28 · Undergoing Analysis
7.5EPSS 0.007
CVE-2024-0565
Kernel: cifs filesystem decryption improper input validation remote code execution vulnerability in function receive_encrypted_standard of client
Published 2024-01-15 · Modified
7.4EPSS 0.020
CVE-2023-6606
Kernel: out-of-bounds read vulnerability in smbcalcsize
Published 2023-12-08 · Modified
7.1EPSS 0.005
CVE-2026-23363
wifi: mt76: mt7925: Fix possible oob access in mt7925_mac_write_txwi_80211()
Published 2026-03-25 · Analyzed
7.1EPSS 0.001
CVE-2023-51780
An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because of a vcc_recvmsg race condition.
Published 2023-12-25 · Modified
7.0EPSS 0.005
CVE-2023-51781
An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free because of an atalk_recvmsg race condition.
Published 2023-12-25 · Modified
7.0EPSS 0.003
CVE-2023-51782
An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because of a rose_accept race condition.
Published 2023-12-25 · Modified
7.0EPSS 0.003
CVE-2023-6531
Kernel: gc's deletion of an skb races with unix_stream_read_generic() leading to uaf
Published 2024-01-21 · Modified
7.0EPSS 0.002
CVE-2024-0607
Kernel: nf_tables: pointer math issue in nft_byteorder_eval()
Published 2024-01-18 · Modified
6.6EPSS 0.002
CVE-2023-6915
Kernel: null pointer dereference vulnerability in ida_free in lib/idr.c
Published 2024-01-15 · Modified
6.2EPSS 0.003
CVE-2023-6622
Kernel: null pointer dereference vulnerability in nft_dynset_init()
Published 2023-12-08 · Analyzed
5.5EPSS 0.003
CVE-2023-6560
Kernel: io_uring out of boundary memory access in __io_uaddr_map()
Published 2023-12-08 · Modified
5.5EPSS 0.003
CVE-2023-52655
usb: aqc111: check packet for fixup for true limit
Published 2024-05-13 · Analyzed
5.5EPSS 0.003
CVE-2025-37889
ASoC: ops: Consistently treat platform_max as control value
Published 2025-05-09 · Analyzed
5.5EPSS 0.003
CVE-2023-52784
bonding: stop the device in bond_setup_by_slave()
Published 2024-05-21 · Analyzed
5.5EPSS 0.002
CVE-2023-52781
usb: config: fix iteration issue in 'usb_get_bos_descriptor()'
Published 2024-05-21 · Analyzed
5.5EPSS 0.002
CVE-2023-52774
s390/dasd: protect device queue against concurrent access
Published 2024-05-21 · Analyzed
5.5EPSS 0.002
CVE-2023-52778
mptcp: deal with large GSO size
Published 2024-05-21 · Analyzed
5.5EPSS 0.002
CVE-2023-52787
blk-mq: make sure active queue usage is held for bio_integrity_prep()
Published 2024-05-21 · Analyzed
5.5EPSS 0.002
CVE-2023-52780
net: mvneta: fix calls to page_pool_get_stats
Published 2024-05-21 · Analyzed
5.5EPSS 0.002
1 / 2Next →