VendorsLinuxlinux_kernel5.14
Vulnerabilities

Linux Kernel 5.14

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

61CVEs
CVE-2021-4154
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.
Published 2022-02-04 · Modified
8.8EPSS 0.012
CVE-2021-3656
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable both VMLOAD/VMSAVE intercepts and VLS (Virtual VMLOAD/VMSAVE) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape.
Published 2022-03-04 · Modified
8.8EPSS 0.007
CVE-2021-3653
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "int_ctl" field, this issue could allow a malicious L1 to enable AVIC support (Advanced Virtual Interrupt Controller) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape. This flaw affects Linux kernel versions prior to 5.14-rc7.
Published 2021-09-29 · Modified
8.8EPSS 0.004
CVE-2021-47338
fbmem: Do not delete the mode that is still in use
Published 2024-05-21 · Modified
7.8EPSS 0.003
CVE-2021-47341
KVM: mmio: Fix use-after-free Read in kvm_vm_ioctl_unregister_coalesced_mmio
Published 2024-05-21 · Modified
7.8EPSS 0.003
CVE-2021-47310
net: ti: fix UAF in tlan_remove_one
Published 2024-05-21 · Analyzed
7.8EPSS 0.003
CVE-2021-47311
net: qcom/emac: fix UAF in emac_remove
Published 2024-05-21 · Analyzed
7.8EPSS 0.003
CVE-2021-47309
net: validate lwtstate->data before returning from skb_tunnel_info()
Published 2024-05-21 · Modified
7.8EPSS 0.002
CVE-2021-47291
ipv6: fix another slab-out-of-bounds in fib6_nh_flush_exceptions
Published 2024-05-21 · Modified
7.8EPSS 0.002
CVE-2021-47301
igb: Fix use-after-free error during reset
Published 2024-05-21 · Analyzed
7.8EPSS 0.002
CVE-2021-47303
bpf: Track subprog poke descriptors correctly and fix use-after-free
Published 2024-05-21 · Modified
7.8EPSS 0.002
CVE-2021-47300
bpf: Fix tail_call_reachable rejection for interpreter when jit failed
Published 2024-05-21 · Modified
7.8EPSS 0.002
CVE-2021-47296
KVM: PPC: Fix kvm_arch_vcpu_ioctl vcpu_load leak
Published 2024-05-21 · Modified
7.8EPSS 0.002
CVE-2021-47293
net/sched: act_skbmod: Skip non-Ethernet packets
Published 2024-05-21 · Analyzed
7.8EPSS 0.002
CVE-2021-47286
bus: mhi: core: Validate channel ID when processing command completions
Published 2024-05-21 · Analyzed
7.8EPSS 0.002
CVE-2021-47306
net: fddi: fix UAF in fza_probe
Published 2024-05-21 · Analyzed
7.8EPSS 0.002
CVE-2021-47302
igc: Fix use-after-free error during reset
Published 2024-05-21 · Analyzed
7.8EPSS 0.002
CVE-2024-56709
io_uring: check if iowq is killed before queuing
Published 2024-12-29 · Modified
7.8EPSS 0.002
CVE-2025-21924
net: hns3: make sure ptp clock is unregister and freed if hclge_ptp_get_cycle returns an error
Published 2025-04-01 · Modified
7.8EPSS 0.002
CVE-2026-31489
spi: meson-spicc: Fix double-put in remove path
Published 2026-04-22 · Modified
7.8EPSS 0.002
CVE-2022-50243
sctp: handle the error returned from sctp_auth_asoc_init_active_key
Published 2025-09-15 · Modified
7.8EPSS 0.002
CVE-2025-38499
clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns
Published 2025-08-11 · Modified
7.8EPSS 0.002
CVE-2021-47295
net: sched: fix memory leak in tcindex_partial_destroy_work
Published 2024-05-21 · Modified
7.5EPSS 0.015
CVE-2022-49048
ipv6: fix panic when forwarding a pkt with no in6 dev
Published 2025-02-26 · Modified
7.5EPSS 0.007
CVE-2021-4454
can: j1939: fix errant WARN_ON_ONCE in j1939_session_deactivate
Published 2025-03-27 · Modified
7.5EPSS 0.006
CVE-2021-47290
scsi: target: Fix NULL dereference on XCOPY completion
Published 2024-05-21 · Modified
7.5EPSS 0.005
CVE-2021-3743
An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.
Published 2022-03-04 · Modified
7.1EPSS 0.007
CVE-2021-47288
media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf()
Published 2024-05-21 · Analyzed
7.1EPSS 0.002
CVE-2023-53024
bpf: Fix pointer-leak due to insufficient speculative store bypass mitigation
Published 2025-03-27 · Analyzed
7.1EPSS 0.002
CVE-2025-71133
RDMA/irdma: avoid invalid read in irdma_net_event
Published 2026-01-14 · Analyzed
7.1EPSS 0.002
CVE-2021-0920
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel
Published 2021-12-15 · Analyzed
6.9KEVEPSS 0.008
CVE-2021-3679
A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve the resources causing denial of service.
Published 2021-08-05 · Modified
5.5EPSS 0.008
CVE-2021-3732
A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not be accessible.
Published 2022-03-07 · Modified
5.5EPSS 0.003
CVE-2021-47294
netrom: Decrease sock refcount when sock timers expire
Published 2024-05-21 · Analyzed
5.5EPSS 0.003
CVE-2022-49229
ptp: unregister virtual clocks when unregistering physical clock.
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2022-49333
net/mlx5: E-Switch, pair only capable devices
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2024-56707
octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_dmac_flt.c
Published 2024-12-28 · Modified
5.5EPSS 0.002
CVE-2021-47337
scsi: core: Fix bad pointer dereference when ehandler kthread is invalid
Published 2024-05-21 · Analyzed
5.5EPSS 0.002
CVE-2021-47305
dma-buf/sync_file: Don't leak fences on merge failure
Published 2024-05-21 · Analyzed
5.5EPSS 0.002
CVE-2021-47289
ACPI: fix NULL pointer dereference
Published 2024-05-21 · Analyzed
5.5EPSS 0.002
1 / 2Next →