VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18523CVEs
CVE-2021-47242
mptcp: fix soft lookup in subflow_error_report()
Published 2024-05-21 · Modified
7.8EPSS 0.003
CVE-2017-16526
drivers/uwb/uwbd.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device.
Published 2017-11-04 · Modified
7.8EPSS 0.003
CVE-2016-9794
Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted SNDRV_PCM_TRIGGER_START command.
Published 2016-12-28 · Modified
7.8EPSS 0.003
CVE-2017-7836
The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. This allows for privilege escalation as the replaced libcurl code will run with Firefox's privileges. Note: This attack requires an attacker have local system access and only affects OS X and Linux. Windows systems are not affected. This vulnerability affects Firefox < 57.
Published 2018-06-11 · Modified
7.8EPSS 0.003
CVE-2022-0516
A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw affects Linux kernel versions prior to 5.17-rc4.
Published 2022-03-08 · Modified
7.8EPSS 0.003
CVE-2024-26666
wifi: mac80211: fix RCU use in TDLS fast-xmit
Published 2024-04-02 · Modified
7.8EPSS 0.003
CVE-2023-6817
Use-after-free in Linux kernel's netfilter: nf_tables component
Published 2023-12-18 · Modified
7.8EPSS 0.003
CVE-2022-31661
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'.
Published 2022-08-05 · Modified
7.8EPSS 0.003
CVE-2022-47518
An issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when copying the list of operating channels from Wi-Fi management frames.
Published 2022-12-18 · Modified
7.8EPSS 0.003
CVE-2017-9985
The snd_msndmidi_input_read function in sound/isa/msnd/msnd_midi.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue head pointer between two kernel reads of that value, aka a "double fetch" vulnerability.
Published 2017-06-28 · Modified
7.8EPSS 0.003
CVE-2020-35512
A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors
Published 2021-02-15 · Modified
7.8EPSS 0.003
CVE-2022-25255
In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.
Published 2022-02-16 · Modified
7.8EPSS 0.003
CVE-2026-35558
Improper neutralization of special elements in authentication components in Amazon Athena ODBC driver
Published 2026-04-03 · Analyzed
7.8EPSS 0.003
CVE-2024-27075
media: dvb-frontends: avoid stack overflow warnings with clang
Published 2024-05-01 · Analyzed
7.8EPSS 0.003
CVE-2019-0145
Buffer overflow in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable an escalation of privilege via local access.
Published 2019-11-14 · Modified
7.8EPSS 0.003
CVE-2022-49168
btrfs: do not clean up repair bio if submit fails
Published 2025-02-26 · Analyzed
7.8EPSS 0.003
CVE-2022-31664
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
Published 2022-08-05 · Modified
7.8EPSS 0.003
CVE-2024-50001
net/mlx5: Fix error path in multi-packet WQE transmit
Published 2024-10-21 · Modified
7.8EPSS 0.003
CVE-2024-49894
drm/amd/display: Fix index out of bounds in degamma hardware format translation
Published 2024-10-21 · Modified
7.8EPSS 0.003
CVE-2024-27000
serial: mxs-auart: add spinlock around changing cts state
Published 2024-05-01 · Analyzed
7.8EPSS 0.003
CVE-2022-1998
A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
Published 2022-06-09 · Modified
7.8EPSS 0.003
CVE-2024-39495
greybus: Fix use-after-free bug in gb_interface_release due to race condition.
Published 2024-07-12 · Modified
7.8EPSS 0.003
CVE-2024-41034
nilfs2: fix kernel bug on rename operation of broken directory
Published 2024-07-29 · Modified
7.8EPSS 0.003
CVE-2024-53171
ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit
Published 2024-12-27 · Modified
7.8EPSS 0.003
CVE-2018-9310
An issue was discovered in MagniComp SysInfo before 10-H82 if setuid root (the default). This vulnerability allows any local user on a Linux/UNIX system to run SysInfo and obtain a root shell, which can be used to compromise the local system.
Published 2018-04-30 · Modified
7.8EPSS 0.003
CVE-2021-20268
An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user running the eBPF script calls dev_map_init_map or sock_map_alloc. This flaw allows a local user to crash the system or possibly escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2021-03-09 · Modified
7.8EPSS 0.003
CVE-2025-37839
jbd2: remove wrong sb->s_sequence check
Published 2025-05-09 · Analyzed
7.8EPSS 0.003
CVE-2025-22056
netfilter: nft_tunnel: fix geneve_opt type confusion addition
Published 2025-04-16 · Modified
7.8EPSS 0.003
CVE-2017-7889
The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and bypass slab-allocation access restrictions) via an application that opens the /dev/mem file, related to arch/x86/mm/init.c and drivers/char/mem.c.
Published 2017-04-17 · Modified
7.8EPSS 0.003
CVE-2024-40902
jfs: xattr: fix buffer overflow for invalid xattr
Published 2024-07-12 · Modified
7.8EPSS 0.003
CVE-2024-41042
netfilter: nf_tables: prefer nft_chain_validate
Published 2024-07-29 · Modified
7.8EPSS 0.003
CVE-2020-36313
An issue was discovered in the Linux kernel before 5.7. The KVM subsystem allows out-of-range access to memslots after a deletion, aka CID-0774a964ef56. This affects arch/s390/kvm/kvm-s390.c, include/linux/kvm_host.h, and virt/kvm/kvm_main.c.
Published 2021-04-06 · Modified
7.8EPSS 0.003
CVE-2023-51042
In the Linux kernel before 6.4.12, amdgpu_cs_wait_all_fences in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c has a fence use-after-free.
Published 2024-01-23 · Modified
7.8EPSS 0.003
CVE-2024-49882
ext4: fix double brelse() the buffer of the extents path
Published 2024-10-21 · Modified
7.8EPSS 0.003
CVE-2022-48805
net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup
Published 2024-07-16 · Analyzed
7.8EPSS 0.003
CVE-2012-6703
Integer overflow in the snd_compr_allocate_buffer function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.6-rc6-next-20120917 allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.
Published 2016-06-29 · Modified
7.8EPSS 0.003
CVE-2021-29266
An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v->config_ctx has an invalid value upon re-opening a character device, aka CID-f6bbf0010ba0.
Published 2021-03-26 · Modified
7.8EPSS 0.003
CVE-2021-38166
In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.
Published 2021-08-07 · Analyzed
7.8EPSS 0.003
CVE-2025-37840
mtd: rawnand: brcmnand: fix PM resume warning
Published 2025-05-09 · Analyzed
7.8EPSS 0.003
CVE-2023-6111
Use-after-free in Linux kernel's netfilter: nf_tables component
Published 2023-11-14 · Analyzed
7.8EPSS 0.003
← Prev98 / 464Next →