VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18523CVEs
CVE-2022-1679
A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Published 2022-05-16 · Modified
7.8EPSS 0.008
CVE-2019-12578
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher.64 binary is setuid root. This binary executes /opt/pia/openvpn-64/openvpn, passing the parameters provided from the command line. Care was taken to programmatically disable potentially dangerous openvpn parameters; however, the --route-pre-down parameter can be used. This parameter accepts an arbitrary path to a script/program to be executed when OpenVPN exits. The --script-security parameter also needs to be passed to allow for this action to be taken, and --script-security is not currently in the disabled parameter list. A local unprivileged user can pass a malicious script/binary to the --route-pre-down option, which will be executed as root when openvpn is stopped.
Published 2019-07-11 · Modified
7.8EPSS 0.008
CVE-2019-12579
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA Linux/macOS binary openvpn_launcher.64 binary is setuid root. This binary accepts several parameters to update the system configuration. These parameters are passed to operating system commands using a "here" document. The parameters are not sanitized, which allow for arbitrary commands to be injected using shell metacharacters. A local unprivileged user can pass special crafted parameters that will be interpolated by the operating system calls.
Published 2019-07-11 · Modified
7.8EPSS 0.008
CVE-2019-7221
The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.
Published 2019-03-17 · Modified
7.8EPSS 0.008
CVE-2017-7374
Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing cryptographic transform objects to be freed prematurely.
Published 2017-03-31 · Modified
7.8EPSS 0.008
CVE-2022-30594
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.
Published 2022-05-12 · Modified
7.8EPSS 0.008
CVE-2024-38587
speakup: Fix sizeof() vs ARRAY_SIZE() bug
Published 2024-06-19 · Modified
7.8EPSS 0.008
CVE-2020-27815
A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2021-05-26 · Modified
7.8EPSS 0.008
CVE-2022-45934
An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.
Published 2022-11-27 · Modified
7.8EPSS 0.008
CVE-2023-3640
Kernel: x86/mm: a per-cpu entry area leak was identified through the init_cea_offsets function when prefetchnta and prefetcht2 instructions being used for the per-cpu entry area mapping to the user space
Published 2023-07-24 · Modified
7.8EPSS 0.008
CVE-2018-9568
In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-113509306. References: Upstream kernel.
Published 2018-12-06 · Modified
7.8EPSS 0.008
CVE-2024-44940
fou: remove warn in gue_gro_receive on unsupported protocol
Published 2024-08-26 · Modified
7.8EPSS 0.008
CVE-2018-10878
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image.
Published 2018-07-26 · Modified
7.8EPSS 0.008
CVE-2016-2068
The MSM QDSP6 audio driver (aka sound driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (integer overflow, and buffer overflow or buffer over-read) via a crafted application that performs a (1) AUDIO_EFFECTS_WRITE or (2) AUDIO_EFFECTS_READ operation, aka Qualcomm internal bug CR1006609.
Published 2016-07-11 · Modified
7.8EPSS 0.007
CVE-2024-47696
RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency
Published 2024-10-21 · Modified
7.8EPSS 0.007
CVE-2017-9077
The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.
Published 2017-05-19 · Modified
7.8EPSS 0.007
CVE-2020-7851
Innorix File Transfer Solution File Download and Execution Vulnerability
Published 2021-04-19 · Modified
7.8EPSS 0.007
CVE-2019-17387
An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS.
Published 2019-12-05 · Modified
7.8EPSS 0.007
CVE-2021-47477
comedi: dt9812: fix DMA buffers on stack
Published 2024-05-22 · Analyzed
7.8EPSS 0.007
CVE-2024-26880
dm: call the resume method on internal suspend
Published 2024-04-17 · Modified
7.8EPSS 0.007
CVE-2023-6931
Out-of-bounds write in Linux kernel's Performance Events system component
Published 2023-12-19 · Modified
7.8EPSS 0.007
CVE-2021-47259
NFS: Fix use-after-free in nfs4_init_client()
Published 2024-05-21 · Modified
7.8EPSS 0.007
CVE-2020-12657
An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body.
Published 2020-05-05 · Modified
7.8EPSS 0.007
CVE-2026-53362
ipv6: account for fraggap on the paged allocation path
Published 2026-07-04 · Analyzed
7.8KEVEPSS 0.007
CVE-2019-11487
The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It can occur with FUSE requests.
Published 2019-04-23 · Modified
7.8EPSS 0.007
CVE-2018-20856
An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-after-free because a certain error case is mishandled.
Published 2019-07-26 · Modified
7.8EPSS 0.007
CVE-2025-37928
dm-bufio: don't schedule in atomic context
Published 2025-05-20 · Analyzed
7.81 PoCEPSS 0.007
CVE-2017-1677
IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath. IBM X-Force ID: 133999.
Published 2018-03-22 · Modified
7.8EPSS 0.007
CVE-2024-26882
net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv()
Published 2024-04-17 · Modified
7.8EPSS 0.007
CVE-2021-3612
An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2021-07-09 · Modified
7.8EPSS 0.007
CVE-2024-35880
io_uring/kbuf: hold io_buffer_list reference over mmap
Published 2024-05-19 · Modified
7.8EPSS 0.007
CVE-2023-52628
netfilter: nftables: exthdr: fix 4-byte stack OOB write
Published 2024-03-28 · Modified
7.8EPSS 0.007
CVE-2023-3389
Use after free in io_uring in the Linux Kernel
Published 2023-06-28 · Modified
7.8EPSS 0.007
CVE-2022-48658
mm: slub: fix flush_cpu_slab()/__free_slab() invocations in task context.
Published 2024-04-28 · Modified
7.8EPSS 0.007
CVE-2017-7518
A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/process inside a guest could use this flaw to potentially escalate their privileges inside the guest. Linux guests are not affected by this.
Published 2018-07-30 · Modified
7.8EPSS 0.007
CVE-2021-47189
btrfs: fix memory ordering between normal and ordered work functions
Published 2024-04-10 · Modified
7.8EPSS 0.007
CVE-2020-25221
get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page. The result is a refcount underflow. This can be triggered by any 64-bit process that can use ptrace() or process_vm_readv(), aka CID-9fa2dd946743.
Published 2020-09-10 · Modified
7.8EPSS 0.007
CVE-2024-47726
f2fs: fix to wait dio completion
Published 2024-10-21 · Modified
7.8EPSS 0.007
CVE-2023-0461
Use-after-free vulnerability in the Linux Kernel
Published 2023-02-28 · Modified
7.8EPSS 0.007
CVE-2019-8912
In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr.
Published 2019-02-18 · Modified
7.8EPSS 0.007
← Prev89 / 464Next →