VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18492CVEs
CVE-2025-37918
Bluetooth: btusb: avoid NULL pointer dereference in skb_dequeue()
Published 2025-05-20 · Modified
8.8EPSS 0.002
CVE-2025-39848
ax25: properly unshare skbs in ax25_kiss_rcv()
Published 2025-09-19 · Modified
8.8EPSS 0.002
CVE-2026-11303
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2024-35814
swiotlb: Fix double-allocation of slots due to broken alignment handling
Published 2024-05-17 · Modified
8.8EPSS 0.002
CVE-2024-35804
KVM: x86: Mark target gfn of emulated atomic instruction as dirty
Published 2024-05-17 · Modified
8.8EPSS 0.002
CVE-2021-47668
can: dev: can_restart: fix use after free bug
Published 2025-04-17 · Modified
8.8EPSS 0.002
CVE-2022-50419
Bluetooth: hci_sysfs: Fix attempting to call device_add multiple times
Published 2025-09-18 · Modified
8.8EPSS 0.002
CVE-2023-53226
wifi: mwifiex: Fix OOB and integer underflow when rx packets
Published 2025-09-15 · Modified
8.8EPSS 0.002
CVE-2026-11071
Use after free in Base in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-10021
Insufficient validation of untrusted input in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-05-28 · Analyzed
8.8EPSS 0.002
CVE-2026-11177
Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-64117
wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb
Published 2026-07-19 · Analyzed
8.8EPSS 0.002
CVE-2026-11124
Integer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2022-50493
scsi: qla2xxx: Fix crash when I/O abort times out
Published 2025-10-04 · Modified
8.8EPSS 0.002
CVE-2025-39806
HID: multitouch: fix slab out-of-bounds access in mt_report_fixup()
Published 2025-09-16 · Modified
8.8EPSS 0.002
CVE-2025-39761
wifi: ath12k: Decrement TID on RX peer frag setup error handling
Published 2025-09-11 · Modified
8.8EPSS 0.002
CVE-2025-12432
Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-10 · Analyzed
8.8EPSS 0.002
CVE-2023-53589
wifi: iwlwifi: mvm: don't trust firmware n_channels
Published 2025-10-04 · Modified
8.8EPSS 0.002
CVE-2025-39750
wifi: ath12k: Correct tid cleanup when tid setup fails
Published 2025-09-11 · Modified
8.8EPSS 0.002
CVE-2023-53315
wifi: ath11k: Fix SKB corruption in REO destination ring
Published 2025-09-16 · Modified
8.8EPSS 0.002
CVE-2024-57999
powerpc/pseries/iommu: IOMMU incorrectly marks MMIO range in DDW
Published 2025-02-27 · Modified
8.8EPSS 0.002
CVE-2025-21972
net: mctp: unshare packets when reassembling
Published 2025-04-01 · Modified
8.8EPSS 0.002
CVE-2023-53454
HID: multitouch: Correct devm device reference for hidinput input_dev name
Published 2025-10-01 · Modified
8.8EPSS 0.002
CVE-2025-39864
wifi: cfg80211: fix use-after-free in cmp_bss()
Published 2025-09-19 · Modified
8.8EPSS 0.002
CVE-2026-11305
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-11307
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2024-50041
i40e: Fix macvlan leak by synchronizing access to mac_filter_hash
Published 2024-10-21 · Modified
8.8EPSS 0.002
CVE-2025-39952
wifi: wilc1000: avoid buffer overflow in WID string configuration
Published 2025-10-04 · Modified
8.8EPSS 0.002
CVE-2026-23230
smb: client: split cached_fid bitfields to avoid shared-byte RMW races
Published 2026-02-18 · Modified
8.8EPSS 0.002
CVE-2026-11179
Inappropriate implementation in ORB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2025-38512
wifi: prevent A-MSDU attacks in mesh networks
Published 2025-08-16 · Modified
8.8EPSS 0.002
CVE-2025-21969
Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd
Published 2025-04-01 · Modified
8.8EPSS 0.002
CVE-2021-4440
x86/xen: Drop USERGS_SYSRET64 paravirt call
Published 2024-06-25 · Analyzed
8.8EPSS 0.002
CVE-2023-53305
Bluetooth: L2CAP: Fix use-after-free
Published 2025-09-16 · Modified
8.8EPSS 0.002
CVE-2021-47670
can: peak_usb: fix use after free bugs
Published 2025-04-17 · Modified
8.8EPSS 0.002
CVE-2025-38290
wifi: ath12k: fix node corruption in ar->arvifs list
Published 2025-07-10 · Modified
8.8EPSS 0.002
CVE-2025-38592
Bluetooth: hci_devcd_dump: fix out-of-bounds via dev_coredumpv
Published 2025-08-19 · Modified
8.8EPSS 0.002
CVE-2026-11306
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-11670
Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.002
CVE-2026-64255
wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
Published 2026-07-24 · Analyzed
8.8EPSS 0.002
← Prev65 / 463Next →