VendorsLinuxlinux_kernel5.19
Vulnerabilities

Linux Kernel 5.19

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

213CVEs
CVE-2022-50302
lockd: set other missing fields when unlocking files
Published 2025-09-15 · Modified
7.5EPSS 0.004
CVE-2025-38393
NFSv4/pNFS: Fix a race to wake on NFS_LAYOUT_DRAIN
Published 2025-07-25 · Modified
7.5EPSS 0.004
CVE-2022-33742
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).
Published 2022-07-05 · Modified
7.1EPSS 0.003
CVE-2022-33741
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).
Published 2022-07-05 · Modified
7.1EPSS 0.003
CVE-2022-33740
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).
Published 2022-07-05 · Modified
7.1EPSS 0.003
CVE-2022-26365
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).
Published 2022-07-05 · Modified
7.1EPSS 0.003
CVE-2022-49687
virtio_net: fix xdp_rxq_info bug after suspend/resume
Published 2025-02-26 · Analyzed
7.1EPSS 0.003
CVE-2022-49674
dm raid: fix accesses beyond end of raid member array
Published 2025-02-26 · Analyzed
7.1EPSS 0.003
CVE-2022-49340
ip_gre: test csum_start instead of transport header
Published 2025-02-26 · Modified
7.1EPSS 0.003
CVE-2022-49623
powerpc/xive/spapr: correct bitmap allocation size
Published 2025-02-26 · Modified
7.1EPSS 0.003
CVE-2022-49643
ima: Fix a potential integer overflow in ima_appraise_measurement
Published 2025-02-26 · Modified
7.1EPSS 0.003
CVE-2022-49706
zonefs: fix zonefs_iomap_begin() for reads
Published 2025-02-26 · Analyzed
7.1EPSS 0.003
CVE-2026-23327
cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed()
Published 2026-03-25 · Modified
7.1EPSS 0.001
CVE-2021-33655
When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.
Published 2022-07-18 · Modified
6.7EPSS 0.003
CVE-2022-39842
An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is used as the third argument to copy_from_user(), a heap overflow may occur. NOTE: the original discoverer disputes that the overflow can actually happen.
Published 2022-09-05 · Modified
6.1EPSS 0.006
CVE-2022-2318
There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers to crash linux kernel without any privileges.
Published 2022-07-06 · Modified
5.5EPSS 0.004
CVE-2022-2873
An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to crash the system.
Published 2022-08-22 · Modified
5.5EPSS 0.003
CVE-2022-49636
vlan: fix memory leak in vlan_newlink()
Published 2025-02-26 · Modified
5.5EPSS 0.003
CVE-2022-49688
afs: Fix dynamic root getattr
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2022-49568
KVM: Don't null dereference ops->destroy
Published 2025-02-26 · Modified
5.5EPSS 0.003
CVE-2022-49728
ipv6: Fix signed integer overflow in __ip6_append_data
Published 2025-02-26 · Modified
5.5EPSS 0.003
CVE-2022-49345
net: xfrm: unexport __init-annotated xfrm4_protocol_init()
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2022-49625
sfc: fix kernel panic when creating VF
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2022-49713
usb: dwc2: Fix memory leak in dwc2_hcd_init
Published 2025-02-26 · Modified
5.5EPSS 0.003
CVE-2022-49611
x86/speculation: Fill RSB on vmexit for IBRS
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2022-49708
ext4: fix bug_on ext4_mb_use_inode_pa
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2022-49350
net: mdio: unexport __init-annotated mdio_bus_init()
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2022-49358
netfilter: nf_tables: memleak flow rule from commit path
Published 2025-02-26 · Modified
5.5EPSS 0.003
CVE-2022-49673
dm raid: fix KASAN warning in raid5_add_disks
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2022-49341
bpf, arm64: Clear prog->jited_len along prog->jited
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2022-49691
erspan: do not assume transport header is always set
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2022-49675
tick/nohz: unexport __init-annotated tick_nohz_full_setup()
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2022-49710
dm mirror log: round up region bitmap size to BITS_PER_LONG
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2022-49653
i2c: piix4: Fix a memory leak in the EFCH MMIO support
Published 2025-02-26 · Modified
5.5EPSS 0.003
CVE-2022-49658
bpf: Fix insufficient bounds propagation from adjust_scalar_min_max_vals
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2022-49716
irqchip/gic-v3: Fix error handling in gic_populate_ppi_partitions
Published 2025-02-26 · Modified
5.5EPSS 0.003
CVE-2022-49671
RDMA/cm: Fix memory leak in ib_cm_insert_listen
Published 2025-02-26 · Modified
5.5EPSS 0.003
CVE-2022-49644
drm/i915: fix a possible refcount leak in intel_dp_add_mst_connector()
Published 2025-02-26 · Modified
5.5EPSS 0.003
CVE-2022-49731
ata: libata-core: fix NULL pointer deref in ata_host_alloc_pinfo()
Published 2025-02-26 · Modified
5.5EPSS 0.003
CVE-2022-49727
ipv6: Fix signed integer overflow in l2tp_ip6_sendmsg
Published 2025-02-26 · Modified
5.5EPSS 0.003
← Prev2 / 6Next →