VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18523CVEs
CVE-2022-47940
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2_write.
Published 2022-12-23 · Modified
8.1EPSS 0.014
CVE-2021-29986
A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
Published 2021-08-17 · Modified
8.1EPSS 0.013
CVE-2023-1194
Use-after-free in parse_lease_state()
Published 2023-11-03 · Analyzed
8.1EPSS 0.011
CVE-2020-4945
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.
Published 2021-06-24 · Modified
8.1EPSS 0.010
CVE-2023-52434
smb: client: fix potential OOBs in smb2_parse_contexts()
Published 2024-02-20 · Modified
8.1EPSS 0.010
CVE-2021-38941
IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable to host information leakage or destruction if unauthorized access to these containers could execute arbitrary commands. IBM X-Force ID: 211048.
Published 2022-06-30 · Modified
8.1EPSS 0.009
CVE-2021-26628
MaxBoard XSS and File Upload Vulnerability
Published 2022-04-26 · Modified
8.1EPSS 0.008
CVE-2026-47619
NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
Published 2026-08-04 · Analyzed
8.1EPSS 0.008
CVE-2023-44154
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
8.1EPSS 0.008
CVE-2021-47131
net/tls: Fix use-after-free after the TLS device goes down and up
Published 2024-03-15 · Modified
8.1EPSS 0.008
CVE-2022-48655
firmware: arm_scmi: Harden accesses to the reset domains
Published 2024-04-28 · Analyzed
8.1EPSS 0.007
CVE-2024-26736
afs: Increase buffer size in afs_update_volume_status()
Published 2024-04-03 · Modified
8.1EPSS 0.007
CVE-2024-44986
ipv6: fix possible UAF in ip6_finish_output2()
Published 2024-09-04 · Modified
8.1EPSS 0.007
CVE-2024-26954
ksmbd: fix slab-out-of-bounds in smb_strndup_from_utf16()
Published 2024-05-01 · Modified
8.1EPSS 0.007
CVE-2024-0100
CVE
Published 2024-05-09 · Analyzed
8.1EPSS 0.007
CVE-2022-49075
btrfs: fix qgroup reserve overflow the qgroup limit
Published 2025-02-26 · Modified
8.1EPSS 0.007
CVE-2026-64398
ksmbd: add a permission check for FSCTL_SET_ZERO_DATA
Published 2026-07-25 · Analyzed
8.1EPSS 0.007
CVE-2024-57973
rdma/cxgb4: Prevent potential integer overflow on 32bit
Published 2025-02-27 · Modified
8.1EPSS 0.007
CVE-2022-48743
net: amd-xgbe: Fix skb data length underflow
Published 2024-06-20 · Modified
8.1EPSS 0.006
CVE-2021-47368
enetc: Fix illegal access when reading affinity_hint
Published 2024-05-21 · Modified
8.1EPSS 0.006
CVE-2025-21762
arp: use RCU protection in arp_xmit()
Published 2025-02-27 · Modified
8.1EPSS 0.006
CVE-2024-50215
nvmet-auth: assign dh_key to NULL after kfree_sensitive
Published 2024-11-09 · Modified
8.1EPSS 0.006
CVE-2024-56627
ksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read
Published 2024-12-27 · Modified
8.1EPSS 0.006
CVE-2025-21765
ipv6: use RCU protection in ip6_default_advmss()
Published 2025-02-27 · Modified
8.1EPSS 0.006
CVE-2023-40363
IBM InfoSphere Information Server privilege escalation
Published 2023-11-18 · Modified
8.1EPSS 0.006
CVE-2023-3865
ksmbd: fix out-of-bound read in smb2_write
Published 2025-08-16 · Modified
8.1EPSS 0.006
CVE-2024-46858
mptcp: pm: Fix uaf in __timer_delete_sync
Published 2024-09-27 · Modified
8.1EPSS 0.006
CVE-2021-47433
btrfs: fix abort logic in btrfs_replace_file_extents
Published 2024-05-22 · Modified
8.1EPSS 0.006
CVE-2026-64235
x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines
Published 2026-07-24 · Analyzed
8.1EPSS 0.006
CVE-2026-7872
Path Traversal Vulnerability in File Component Leading to Arbitrary File Read and Authentication Bypass
Published 2026-07-17 · Analyzed
8.1EPSS 0.006
CVE-2026-31708
smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path
Published 2026-05-01 · Modified
8.1EPSS 0.006
CVE-2023-52885
SUNRPC: Fix UAF in svc_tcp_listen_data_ready()
Published 2024-07-14 · Modified
8.1EPSS 0.006
CVE-2026-46010
rxrpc: Fix error handling in rxgk_extract_token()
Published 2026-05-27 · Analyzed
8.1EPSS 0.006
CVE-2026-31613
smb: client: fix OOB reads parsing symlink error response
Published 2026-04-24 · Modified
8.1EPSS 0.006
CVE-2022-38385
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 233777.
Published 2022-11-11 · Modified
8.1EPSS 0.005
CVE-2025-21766
ipv4: use RCU protection in __ip_rt_update_pmtu()
Published 2025-02-27 · Modified
8.1EPSS 0.005
CVE-2026-52967
smb/client: fix possible infinite loop and oob read in symlink_data()
Published 2026-06-24 · Analyzed
8.1EPSS 0.005
CVE-2022-48629
crypto: qcom-rng - ensure buffer for generate is completely filled
Published 2024-03-05 · Modified
8.1EPSS 0.005
CVE-2023-38738
IBM OpenPages with Watson information disclosure
Published 2024-01-19 · Modified
8.1EPSS 0.005
CVE-2025-22042
ksmbd: add bounds check for create lease context
Published 2025-04-16 · Modified
8.1EPSS 0.005
← Prev78 / 464Next →