VendorsLinuxlinux_kernel4.4
Vulnerabilities

Linux Kernel 4.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2015-8539
The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted.c, and security/keys/user_defined.c.
Published 2016-02-08 · Modified
7.8EPSS 0.004
CVE-2018-10938
A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a denial-of-service. A certain non-default configuration of LSM (Linux Security Module) and NetLabel should be set up on a system before an attacker could leverage this flaw.
Published 2018-08-27 · Modified
7.1EPSS 0.050
CVE-2017-7273
The cp_report_fixup function in drivers/hid/hid-cypress.c in the Linux kernel 3.2 and 4.x before 4.9.4 allows physically proximate attackers to cause a denial of service (integer underflow) or possibly have unspecified other impact via a crafted HID report.
Published 2017-03-27 · Modified
6.6EPSS 0.005
CVE-2015-7513
arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related to the kvm_vm_ioctl_set_pit and kvm_vm_ioctl_set_pit2 functions.
Published 2016-02-08 · Modified
6.5EPSS 0.006
CVE-2015-8785
The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero length for the first segment of an iov.
Published 2016-02-08 · Modified
6.2EPSS 0.006
CVE-2025-71185
dmaengine: ti: dma-crossbar: fix device leak on am335x route allocation
Published 2026-01-31 · Modified
5.5EPSS 0.002
CVE-2022-50285
mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages
Published 2025-09-15 · Analyzed
5.5EPSS 0.002
CVE-2015-7515
The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device that lacks endpoints.
Published 2016-04-27 · Modified
4.91 PoCEPSS 0.018