VendorsLinuxlinux_kernel3.13
Vulnerabilities

Linux Kernel 3.13

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2026-31659
batman-adv: reject oversized global TT response buffers
Published 2026-04-24 · Analyzed
9.8EPSS 0.008
CVE-2026-43038
ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
Published 2026-05-01 · Modified
9.8EPSS 0.004
CVE-2026-23444
wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure
Published 2026-04-03 · Modified
7.8EPSS 0.001
CVE-2014-8884
Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe.c in the Linux kernel before 3.17.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via a large message length in an ioctl call.
Published 2014-11-30 · Modified
6.1EPSS 0.006
CVE-2022-1016
A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivileged attacker.
Published 2022-08-29 · Modified
5.5EPSS 0.004
CVE-2017-8106
The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a single-context INVEPT instruction with a NULL EPT pointer.
Published 2017-04-24 · Modified
5.5EPSS 0.003
CVE-2022-49409
ext4: fix bug_on in __es_tree_search
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2014-3688
The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory consumption) by triggering a large number of chunks in an association's output queue, as demonstrated by ASCONF probes, related to net/sctp/inqueue.c and net/sctp/sm_statefuns.c.
Published 2014-11-30 · Modified
5.0EPSS 0.059
CVE-2014-7841
The sctp_process_param function in net/sctp/sm_make_chunk.c in the SCTP implementation in the Linux kernel before 3.17.4, when ASCONF is used, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via a malformed INIT chunk.
Published 2014-11-30 · Modified
5.0EPSS 0.052
CVE-2014-8709
The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allows remote attackers to obtain sensitive cleartext information by reading packets.
Published 2014-11-10 · Modified
5.0EPSS 0.045
CVE-2014-9090
The do_double_fault function in arch/x86/kernel/traps.c in the Linux kernel through 3.17.4 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to cause a denial of service (panic) via a modify_ldt system call, as demonstrated by sigreturn_32 in the linux-clock-tests test suite.
Published 2014-11-30 · Modified
4.9EPSS 0.004
CVE-2014-7842
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation error report, a similar issue to CVE-2010-5313.
Published 2014-11-30 · Modified
4.9EPSS 0.004
CVE-2014-8989
The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group category that is more restrictive than the entry for the other category, aka a "negative groups" issue, related to kernel/groups.c, kernel/uid16.c, and kernel/user_namespace.c.
Published 2014-11-30 · Modified
4.6EPSS 0.005
CVE-2014-8133
arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local users to bypass the espfix protection mechanism, and consequently makes it easier for local users to bypass the ASLR protection mechanism, via a crafted application that makes a set_thread_area system call and later reads a 16-bit value.
Published 2014-12-17 · Modified
2.1EPSS 0.006