VendorsLinuxlinux_kernel5.4
Vulnerabilities

Linux Kernel 5.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2019-14821
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged host user or process with access to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in a denial of service or potentially escalating privileges on the system.
Published 2019-09-19 · Modified
8.8EPSS 0.008
CVE-2026-31570
can: gw: fix OOB heap access in cgw_csum_crc8_rel()
Published 2026-04-24 · Analyzed
8.8EPSS 0.004
CVE-2025-1290
A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during an AF_VSOCK connect syscall can occur before a worker thread accesses it resulting in a dangling pointer and potential kernel code execution.
Published 2025-04-17 · Analyzed
8.1EPSS 0.003
CVE-2019-19069
A memory leak in the fastrpc_dma_buf_attach() function in drivers/misc/fastrpc.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering dma_get_sgtable() failures, aka CID-fc739a058d99.
Published 2019-11-18 · Modified
7.8EPSS 0.035
CVE-2026-43049
HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure
Published 2026-05-01 · Analyzed
7.8EPSS 0.002
CVE-2023-53308
net: fec: Better handle pm_runtime_get() failing in .remove()
Published 2025-09-16 · Modified
7.8EPSS 0.002
CVE-2022-49851
riscv: fix reserved memory setup
Published 2025-05-01 · Analyzed
7.1EPSS 0.002
CVE-2026-23318
ALSA: usb-audio: Use correct version for UAC3 header validation
Published 2026-03-25 · Analyzed
7.1EPSS 0.001
CVE-2020-9391
An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause heap corruption with the GNU C Library malloc implementation.
Published 2020-02-25 · Modified
5.5EPSS 0.005
CVE-2021-47538
rxrpc: Fix rxrpc_local leak in rxrpc_lookup_peer()
Published 2024-05-24 · Analyzed
5.5EPSS 0.002
CVE-2024-57903
net: restrict SO_REUSEPORT to inet sockets
Published 2025-01-15 · Modified
5.5EPSS 0.002
CVE-2022-50224
KVM: x86/mmu: Treat NX as a valid SPTE bit for NPT
Published 2025-06-18 · Analyzed
5.5EPSS 0.002
CVE-2025-39737
mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup()
Published 2025-09-11 · Modified
5.5EPSS 0.002
CVE-2025-71182
can: j1939: make j1939_session_activate() fail if device is no longer registered
Published 2026-01-31 · Analyzed
5.5EPSS 0.002
CVE-2021-20317
A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the system while running OSP.
Published 2021-09-27 · Modified
4.9EPSS 0.004
CVE-2026-64373
cpufreq: Fix hotplug-suspend race during reboot
Published 2026-07-25 · Analyzed
4.7EPSS 0.001