VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18523CVEs
CVE-2021-3483
A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. Versions before kernel 5.12-rc6 are affected
Published 2021-05-17 · Modified
7.8EPSS 0.004
CVE-2022-22454
IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
Published 2022-05-10 · Modified
7.8EPSS 0.004
CVE-2017-18595
An issue was discovered in the Linux kernel before 4.14.11. A double free may be caused by the function allocate_trace_buffer in the file kernel/trace/trace.c.
Published 2019-09-04 · Modified
7.8EPSS 0.004
CVE-2023-52624
drm/amd/display: Wake DMCUB before executing GPINT commands
Published 2024-03-26 · Analyzed
7.8EPSS 0.004
CVE-2025-23339
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running cuobjdump.
Published 2025-09-24 · Modified
7.8EPSS 0.004
CVE-2017-9986
The intr function in sound/oss/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue head pointer between two kernel reads of that value, aka a "double fetch" vulnerability.
Published 2017-06-28 · Modified
7.8EPSS 0.004
CVE-2021-28691
Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malformed packet. Such kernel thread termination will lead to a use-after-free in Linux netback when the backend is destroyed, as the kernel thread associated with queue 0 will have already exited and thus the call to kthread_stop will be performed against a stale pointer.
Published 2021-06-29 · Analyzed
7.8EPSS 0.004
CVE-2022-28390
ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.
Published 2022-04-03 · Analyzed
7.8EPSS 0.004
CVE-2020-12362
Integer overflow in the firmware for some Intel(R) Graphics Drivers for Windows * before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable an escalation of privilege via local access.
Published 2021-02-17 · Modified
7.8EPSS 0.004
CVE-2017-17852
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging mishandling of 32-bit ALU ops.
Published 2017-12-23 · Modified
7.8EPSS 0.004
CVE-2017-8064
drivers/media/usb/dvb-usb-v2/dvb_usb_core.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.
Published 2017-04-23 · Modified
7.8EPSS 0.004
CVE-2016-4568
drivers/media/v4l2-core/videobuf2-v4l2.c in the Linux kernel before 4.5.3 allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a crafted number of planes in a VIDIOC_DQBUF ioctl call.
Published 2016-05-23 · Modified
7.8EPSS 0.004
CVE-2022-3541
Linux Kernel BPF spl2sw_driver.c spl2sw_nvmem_get_mac_address use after free
Published 2022-10-17 · Modified
7.8EPSS 0.004
CVE-2022-1882
A use-after-free flaw was found in the Linux kernel’s pipes functionality in how a user performs manipulations with the pipe post_one_notification() after free_pipe_info() that is already called. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Published 2022-05-26 · Modified
7.8EPSS 0.004
CVE-2025-21704
usb: cdc-acm: Check control transfer buffer size before access
Published 2025-02-22 · Modified
7.8EPSS 0.004
CVE-2022-0500
A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system.
Published 2022-03-25 · Modified
7.8EPSS 0.004
CVE-2019-14565
Insufficient initialization in Intel(R) SGX SDK Windows versions 2.4.100.51291 and earlier, and Linux versions 2.6.100.51363 and earlier, may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.
Published 2019-11-14 · Modified
7.8EPSS 0.004
CVE-2019-14566
Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.
Published 2019-11-14 · Modified
7.8EPSS 0.004
CVE-2024-49513
Not a product | Out-of-bounds Write (CWE-787)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2021-3760
A flaw was found in the Linux kernel. A use-after-free vulnerability in the NFC stack can lead to a threat to confidentiality, integrity, and system availability.
Published 2022-02-16 · Modified
7.8EPSS 0.004
CVE-2012-6701
Integer overflow in fs/aio.c in the Linux kernel before 3.4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec.
Published 2016-05-02 · Modified
7.8EPSS 0.004
CVE-2022-33743
network backend may cause Linux netfront to use freed SKBs While adding logic to support XDP (eXpress Data Path), a code label was moved in a way allowing for SKBs having references (pointers) retained for further processing to nevertheless be freed.
Published 2022-07-05 · Modified
7.8EPSS 0.004
CVE-2021-3715
A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2022-03-02 · Modified
7.8EPSS 0.004
CVE-2018-7480
The blkcg_init_queue function in block/blk-cgroup.c in the Linux kernel before 4.11 allows local users to cause a denial of service (double free) or possibly have unspecified other impact by triggering a creation failure.
Published 2018-02-25 · Modified
7.8EPSS 0.004
CVE-2024-50264
vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans
Published 2024-11-19 · Modified
7.8EPSS 0.004
CVE-2018-15471
An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.x and other products. The Linux netback driver allows frontends to control mapping of requests to request queues. When processing a request to set or change this mapping, some input validation (e.g., for an integer overflow) was missing or flawed, leading to OOB access in hash handling. A malicious or buggy frontend may cause the (usually privileged) backend to make out of bounds memory accesses, potentially resulting in one or more of privilege escalation, Denial of Service (DoS), or information leaks.
Published 2018-08-17 · Modified
7.8EPSS 0.004
CVE-2022-3636
Linux Kernel Ethernet mtk_ppe.c __mtk_ppe_check_skb use after free
Published 2022-10-21 · Modified
7.8EPSS 0.004
CVE-2021-47028
mt76: mt7915: fix txrate reporting
Published 2024-02-28 · Modified
7.8EPSS 0.004
CVE-2012-1097
The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a (1) PTRACE_GETREGSET or (2) PTRACE_SETREGSET ptrace call.
Published 2012-05-17 · Modified
7.8EPSS 0.004
CVE-2019-15925
An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c.
Published 2019-09-04 · Modified
7.8EPSS 0.003
CVE-2021-26930
An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service requests to the PV backend, the driver maps grant references provided by the frontend. In this process, errors may be encountered. In one case, an error encountered earlier might be discarded by later processing, resulting in the caller assuming successful mapping, and hence subsequent operations trying to access space that wasn't mapped. In another case, internal state would be insufficiently updated, preventing safe recovery from the error. This affects drivers/block/xen-blkback/blkback.c.
Published 2021-02-17 · Modified
7.8EPSS 0.003
CVE-2022-3565
Linux Kernel Bluetooth l1oip_core.c del_timer use after free
Published 2022-10-17 · Modified
7.8EPSS 0.003
CVE-2021-26934
An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration, but this wasn't stated accordingly in its support status entry.
Published 2021-02-17 · Modified
7.8EPSS 0.003
CVE-2023-3812
Kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags
Published 2023-07-24 · Modified
7.8EPSS 0.003
CVE-2022-3625
Linux Kernel IPsec devlink.c devlink_param_get use after free
Published 2022-10-21 · Modified
7.8EPSS 0.003
CVE-2024-53096
mm: resolve faulty mmap_region() error path behaviour
Published 2024-11-25 · Modified
7.8EPSS 0.003
CVE-2017-7794
On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.
Published 2018-06-11 · Modified
7.8EPSS 0.003
CVE-2020-15852
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
Published 2020-07-20 · Modified
7.8EPSS 0.003
CVE-2022-39189
An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED situations.
Published 2022-09-02 · Modified
7.8EPSS 0.003
CVE-2021-47242
mptcp: fix soft lookup in subflow_error_report()
Published 2024-05-21 · Modified
7.8EPSS 0.003
← Prev97 / 464Next →