VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18523CVEs
CVE-2016-3135
Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
Published 2016-04-27 · Modified
7.81 PoCEPSS 0.010
CVE-2025-39964
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
Published 2025-10-13 · Analyzed
7.8KEVEPSS 0.010
CVE-2017-5036
A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to have an unspecified impact via a crafted PDF file.
Published 2017-04-24 · Modified
7.8EPSS 0.010
CVE-2020-10757
A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
Published 2020-06-09 · Modified
7.8EPSS 0.010
CVE-2020-36401
mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).
Published 2021-07-01 · Modified
7.8EPSS 0.010
CVE-2023-20562
Published 2023-08-08 · Modified
7.8EPSS 0.010
CVE-2017-15649
net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet_do_bind) that leads to a use-after-free, a different vulnerability than CVE-2017-6346.
Published 2017-10-19 · Modified
7.81 PoCEPSS 0.010
CVE-2022-32981
An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER (aka PEEKUSR and POKEUSR) when accessing floating point registers.
Published 2022-06-10 · Analyzed
7.8EPSS 0.010
CVE-2020-36402
Solidity 0.7.5 has a stack-use-after-return issue in smtutil::CHCSmtLib2Interface::querySolver. NOTE: c39a5e2b7a3fabbf687f53a2823fc087be6c1a7e is cited in the OSV "fixed" field but does not have a code change.
Published 2021-07-01 · Modified
7.8EPSS 0.010
CVE-2016-2854
The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.
Published 2016-05-02 · Modified
7.81 PoCEPSS 0.010
CVE-2017-1000365
The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.
Published 2017-06-19 · Modified
7.8EPSS 0.009
CVE-2024-41817
Arbitrary Code Execution in `AppImage` version `ImageMagick`
Published 2024-07-29 · Analyzed
7.8EPSS 0.009
CVE-2021-29154
BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c.
Published 2021-04-08 · Modified
7.8EPSS 0.009
CVE-2025-33206
NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service.
Published 2026-01-14 · Analyzed
7.8EPSS 0.009
CVE-2022-29581
Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.
Published 2022-05-17 · Modified
7.8EPSS 0.009
CVE-2016-1575
The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.
Published 2016-05-02 · Modified
7.81 PoCEPSS 0.009
CVE-2022-2639
An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZE as expected, potentially leading to an out-of-bounds write access. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Published 2022-09-01 · Modified
7.8EPSS 0.009
CVE-2023-4004
Kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove()
Published 2023-07-31 · Modified
7.8EPSS 0.009
CVE-2023-3390
Use-after-free in Linux kernel's netfilter subsystem
Published 2023-06-28 · Modified
7.8EPSS 0.009
CVE-2019-14816
There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
Published 2019-09-20 · Modified
7.8EPSS 0.009
CVE-2019-12575
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The root_runner.64 binary is setuid root. This binary executes /opt/pia/ruby/64/ruby, which in turn attempts to load several libraries under /tmp/ruby-deploy.old/lib. A local unprivileged user can create a malicious library under this path to execute arbitrary code as the root user.
Published 2019-07-11 · Modified
7.8EPSS 0.009
CVE-2016-2853
The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.
Published 2016-05-02 · Modified
7.81 PoCEPSS 0.009
CVE-2015-0568
Use-after-free vulnerability in the msm_set_crop function in drivers/media/video/msm/msm_camera.c in the MSM-Camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (memory corruption) via an application that makes a crafted ioctl call.
Published 2016-08-07 · Modified
7.8EPSS 0.009
CVE-2022-36123
The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges.
Published 2022-07-29 · Modified
7.8EPSS 0.009
CVE-2020-4688
IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700.
Published 2021-01-20 · Modified
7.8EPSS 0.009
CVE-2023-52654
io_uring/af_unix: disable sending io_uring over sockets
Published 2024-05-09 · Modified
7.8EPSS 0.009
CVE-2025-21756
vsock: Keep the binding until socket destruction
Published 2025-02-27 · Modified
7.8EPSS 0.009
CVE-2021-36081
Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.
Published 2021-07-01 · Modified
7.8EPSS 0.009
CVE-2019-14814
There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
Published 2019-09-20 · Modified
7.8EPSS 0.009
CVE-2020-7860
UnEGG v0.5 and eariler versions have a Integer overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by UnEGG. Attackers could exploit this and arbitrary code execution. This issue affects: Estsoft UnEGG 0.5 versions prior to 1.0 on linux.
Published 2021-06-11 · Modified
7.8EPSS 0.009
CVE-2018-10879
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a use-after-free in ext4_xattr_set_entry function and a denial of service or unspecified other impact may occur by renaming a file in a crafted ext4 filesystem image.
Published 2018-07-26 · Modified
7.8EPSS 0.009
CVE-2024-44946
kcm: Serialise kcm_sendmsg() for the same socket.
Published 2024-08-31 · Modified
7.8EPSS 0.009
CVE-2022-42720
Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.
Published 2022-10-13 · Modified
7.8EPSS 0.009
CVE-2023-5717
Out-of-bounds write in Linux kernel's Linux Kernel Performance Events (perf) component
Published 2023-10-25 · Modified
7.8EPSS 0.008
CVE-2024-26924
netfilter: nft_set_pipapo: do not free live element
Published 2024-04-24 · Modified
7.8EPSS 0.008
CVE-2024-0193
Kernel: netfilter: use-after-free in nft_trans_gc_catchall_sync leads to privilege escalation
Published 2024-01-02 · Analyzed
7.8EPSS 0.008
CVE-2017-18509
An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels before 4.9.187.
Published 2019-08-13 · Modified
7.8EPSS 0.008
CVE-2020-14381
A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory or escalate their privileges when creating a futex on a filesystem that is about to be unmounted. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2020-12-03 · Modified
7.8EPSS 0.008
CVE-2021-33034
In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.
Published 2021-05-14 · Analyzed
7.8EPSS 0.008
CVE-2026-23231
netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
Published 2026-03-04 · Modified
7.81 PoCEPSS 0.008
← Prev88 / 464Next →