VendorsLinuxlinux_kernel4.16
Vulnerabilities

Linux Kernel 4.16

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2018-1087
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the processor did not deliver interrupts and exceptions, rather they are delivered once the first instruction after the stack switch is executed. An unprivileged KVM guest user could use this flaw to crash the guest or, potentially, escalate their privileges in the guest.
Published 2018-05-15 · Modified
8.0EPSS 0.008
CVE-2018-8822
Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel through 4.15.11, and in drivers/staging/ncpfs/ncplib_kernel.c in the Linux kernel 4.16-rc through 4.16-rc6, could be exploited by malicious NCPFS servers to crash the kernel or execute code.
Published 2018-03-20 · Modified
7.8EPSS 0.005
CVE-2026-31494
net: macb: use the current queue number for stats
Published 2026-04-22 · Modified
7.8EPSS 0.002
CVE-2026-23340
net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs
Published 2026-03-25 · Modified
7.8EPSS 0.001
CVE-2026-23392
netfilter: nf_tables: release flowtable after rcu grace period on error
Published 2026-03-25 · Modified
7.8EPSS 0.001
CVE-2018-10877
Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating on a crafted ext4 filesystem image.
Published 2018-07-18 · Modified
7.3EPSS 0.022
CVE-2018-1130
Linux kernel before version 4.16-rc7 is vulnerable to a null pointer dereference in dccp_write_xmit() function in net/dccp/output.c in that allows a local user to cause a denial of service by a number of certain crafted system calls.
Published 2018-05-10 · Modified
5.5EPSS 0.005
CVE-2018-1000200
The Linux Kernel versions 4.14, 4.15, and 4.16 has a null pointer dereference which can result in an out of memory (OOM) killing of large mlocked processes. The issue arises from an oom killed process's final thread calling exit_mmap(), which calls munlock_vma_pages_all() for mlocked vmas.This can happen synchronously with the oom reaper's unmap_page_range() since the vma's VM_LOCKED bit is cleared before munlocking (to determine if any other vmas share the memory and are mlocked).
Published 2018-06-05 · Modified
5.5EPSS 0.005
CVE-2018-7754
The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16.4rc4 allows local users to obtain sensitive address information by reading "ffree: " lines in a debugfs file.
Published 2018-08-10 · Modified
5.5EPSS 0.004
CVE-2024-35819
soc: fsl: qbman: Use raw spinlock for cgr_lock
Published 2024-05-17 · Analyzed
5.5EPSS 0.002
CVE-2026-23120
l2tp: avoid one data-race in l2tp_tunnel_del_work()
Published 2026-02-14 · Analyzed
5.5EPSS 0.001
CVE-2026-23368
net: phy: register phy led_triggers during probe to avoid AB-BA deadlock
Published 2026-03-25 · Modified
5.5EPSS 0.001