VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18494CVEs
CVE-2026-43274
mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq()
Published 2026-05-06 · Analyzed
8.4EPSS 0.002
CVE-2026-64045
ovpn: tcp - use cached peer pointer in ovpn_tcp_close()
Published 2026-07-19 · Analyzed
8.4EPSS 0.002
CVE-2026-46270
power: supply: rt9455: Fix use-after-free in power_supply_changed()
Published 2026-06-03 · Analyzed
8.4EPSS 0.002
CVE-2026-46288
of: unittest: fix use-after-free in of_unittest_changeset()
Published 2026-06-08 · Analyzed
8.4EPSS 0.002
CVE-2025-38395
regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods
Published 2025-07-25 · Modified
8.4EPSS 0.002
CVE-2025-38375
virtio-net: ensure the received length does not exceed allocated size
Published 2025-07-25 · Modified
8.4EPSS 0.002
CVE-2022-49886
x86/tdx: Panic on bad configs that #VE on "private" memory access
Published 2025-05-01 · Modified
8.4EPSS 0.002
CVE-2023-0208
NVIDIA DCGM for Linux contains a vulnerability in HostEngine (server component) where a user may cause a heap-based buffer overflow through the bound socket. A successful exploit of this vulnerability may lead to denial of service and data tampering.
Published 2023-04-01 · Modified
8.4EPSS 0.002
CVE-2025-6504
Possibilities of IP Spoofing via X-Forwarded-For (XFF) Header
Published 2025-07-29 · Analyzed
8.4EPSS 0.002
CVE-2022-43910
IBM Security Guardium privilege escalation
Published 2023-07-19 · Modified
8.4EPSS 0.002
CVE-2022-50442
fs/ntfs3: Validate buffer length while parsing index
Published 2025-10-01 · Modified
8.4EPSS 0.002
CVE-2026-64151
iommupt: Check for missing PAGE_SIZE in the pgsize_bitmap
Published 2026-07-19 · Analyzed
8.4EPSS 0.002
CVE-2023-53194
fs/ntfs3: Add length check in indx_get_root
Published 2025-09-15 · Modified
8.4EPSS 0.002
CVE-2025-39718
vsock/virtio: Validate length in packet header before skb_put()
Published 2025-09-05 · Modified
8.4EPSS 0.002
CVE-2025-39869
dmaengine: ti: edma: Fix memory allocation size for queue_priority_map
Published 2025-09-23 · Modified
8.4EPSS 0.002
CVE-2023-53598
bus: mhi: host: Range check CHDBOFF and ERDBOFF
Published 2025-10-04 · Modified
8.4EPSS 0.002
CVE-2025-39790
bus: mhi: host: Detect events pointing to unexpected TREs
Published 2025-09-11 · Modified
8.4EPSS 0.002
CVE-2023-53493
accel/qaic: tighten bounds checking in decode_message()
Published 2025-10-01 · Modified
8.4EPSS 0.002
CVE-2025-39809
HID: intel-thc-hid: intel-quicki2c: Fix ACPI dsd ICRS/ISUB length
Published 2025-09-16 · Modified
8.4EPSS 0.002
CVE-2026-8036
Local privilege escalation in NI-PAL
Published 2026-06-02 · Analyzed
8.4EPSS 0.002
CVE-2025-39882
drm/mediatek: fix potential OF node use-after-free
Published 2025-09-23 · Modified
8.4EPSS 0.002
CVE-2026-64118
qed: fix double free in qed_cxt_tables_alloc()
Published 2026-07-19 · Analyzed
8.4EPSS 0.002
CVE-2026-63797
rpmsg: char: Fix use-after-free on probe error path
Published 2026-07-19 · Analyzed
8.4EPSS 0.001
CVE-2026-23172
net: wwan: t7xx: fix potential skb->frags overflow in RX path
Published 2026-02-14 · Modified
8.4EPSS 0.001
CVE-2024-51459
IBM InfoSphere Server Information command execution
Published 2025-03-19 · Analyzed
8.4EPSS 0.001
CVE-2026-53091
net: pull headers in qdisc_pkt_len_segs_init()
Published 2026-06-24 · Modified
8.4EPSS 0.001
CVE-2026-17877
Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)
Published 2026-07-30 · Analyzed
8.4EPSS 0.001
CVE-2026-64247
KVM: x86: hyper-v: Bound the bank index when querying sparse banks
Published 2026-07-24 · Analyzed
8.4EPSS 0.001
CVE-2021-22555
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
Published 2021-07-07 · Analyzed
8.3KEV1 PoCEPSS 0.787
CVE-2018-14633
A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker can cause a stack buffer overflow and smash up to 17 bytes of the stack. The attack requires the iSCSI target to be enabled on the victim host. Depending on how the target's code was built (i.e. depending on a compiler, compile flags and hardware architecture) an attack may lead to a system crash and thus to a denial-of-service or possibly to a non-authorized access to data exported by an iSCSI target. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is highly unlikely. Kernel versions 4.18.x, 4.14.x and 3.10.x are believed to be vulnerable.
Published 2018-09-25 · Modified
8.3EPSS 0.087
CVE-2020-14305
An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2020-12-02 · Modified
8.3EPSS 0.052
CVE-2019-9500
Broadcom brcmfmac driver is vulnerable to a heap buffer overflow
Published 2020-01-16 · Modified
8.3EPSS 0.039
CVE-2025-23359
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published 2025-02-12 · Analyzed
8.3EPSS 0.037
CVE-2010-3705
The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory corruption and panic) via a crafted value in the last element of this array.
Published 2010-11-26 · Modified
8.3EPSS 0.020
CVE-2011-2497
Integer underflow in the l2cap_config_req function in net/bluetooth/l2cap_core.c in the Linux kernel before 3.0 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a small command-size value within the command header of a Logical Link Control and Adaptation Protocol (L2CAP) configuration request, leading to a buffer overflow.
Published 2011-08-29 · Modified
8.3EPSS 0.020
CVE-2024-26952
ksmbd: fix potencial out-of-bounds when buffer offset is invalid
Published 2024-05-01 · Modified
8.3EPSS 0.007
CVE-2025-22038
ksmbd: validate zero num_subauth before sub_auth is accessed
Published 2025-04-16 · Modified
8.3EPSS 0.006
CVE-2026-77104
CommServe Path Traversal
Published 2026-09-08 · Analyzed
8.3EPSS 0.006
CVE-2024-26692
smb: Fix regression in writes when non-standard maximum write size negotiated
Published 2024-04-03 · Modified
8.3EPSS 0.005
CVE-2026-31712
ksmbd: require minimum ACE size in smb_check_perm_dacl()
Published 2026-05-01 · Modified
8.3EPSS 0.005
← Prev72 / 463Next →