VendorsLinuxlinux_kernel5.3
Vulnerabilities

Linux Kernel 5.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2026-23240
tls: Fix race condition in tls_sw_cancel_work_tx()
Published 2026-03-10 · Analyzed
9.8EPSS 0.005
CVE-2019-15793
Mishandling of file-system uid/gid with namespaces in shiftfs
Published 2020-04-23 · Modified
8.81 PoCEPSS 0.007
CVE-2025-71112
net: hns3: add VLAN id validation before using
Published 2026-01-14 · Modified
8.8EPSS 0.002
CVE-2025-39961
iommu/amd/pgtbl: Fix possible race while increase page table level
Published 2025-10-09 · Modified
8.8EPSS 0.001
CVE-2019-15538
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well in remote DoS if the XFS filesystem is exported for instance via NFS.
Published 2019-08-25 · Modified
7.8EPSS 0.039
CVE-2026-43500
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
Published 2026-05-11 · Modified
7.82 PoCEPSS 0.023
CVE-2019-15791
Reference count underflow in shiftfs
Published 2020-04-23 · Modified
7.81 PoCEPSS 0.013
CVE-2019-15792
Type confusion in shiftfs
Published 2020-04-23 · Modified
7.81 PoCEPSS 0.011
CVE-2019-14835
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.
Published 2019-09-17 · Modified
7.8EPSS 0.006
CVE-2026-52962
ceph: fix a buffer leak in __ceph_setxattr()
Published 2026-06-24 · Analyzed
7.8EPSS 0.002
CVE-2022-50365
skbuff: Account for tail adjustment during pull operations
Published 2025-09-17 · Modified
7.5EPSS 0.006
CVE-2022-49872
net: gso: fix panic on frag_list with mixed head alloc types
Published 2025-05-01 · Modified
7.5EPSS 0.005
CVE-2026-23242
RDMA/siw: Fix potential NULL pointer dereference in header processing
Published 2026-03-18 · Modified
7.5EPSS 0.004
CVE-2019-15794
Reference counting error in overlayfs/shiftfs error path when used in conjuction with aufs
Published 2020-04-23 · Modified
7.21 PoCEPSS 0.012
CVE-2025-71097
ipv4: Fix reference count leak when using error routes with nexthop objects
Published 2026-01-13 · Modified
5.5EPSS 0.001
CVE-2026-23292
scsi: target: Fix recursive locking in __configfs_open_file()
Published 2026-03-25 · Analyzed
5.5EPSS 0.001
CVE-2019-20934
An issue was discovered in the Linux kernel before 5.2.6. On NUMA systems, the Linux fair scheduler has a use-after-free in show_numa_stats() because NUMA fault statistics are inappropriately freed, aka CID-16d51a590a8c.
Published 2020-11-28 · Modified
5.4EPSS 0.003