Linux Kernel vulnerabilities
99 known vulnerabilities affecting linux/kernel.
Total CVEs
99
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH64MEDIUM30LOW4
Vulnerabilities
Page 4 of 5
CVE-2021-3501P4HIGHCVSS 7.1≥ 5.9, < 5.10.32≥ 5.11, < 5.11.162021-05-06
CVE-2021-3501 [HIGH] CWE-787 CVE-2021-3501: A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KV
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
nvd
CVE-2024-0775P4HIGHCVSS 7.1fixed in 4.14.315≥ 4.15, < 4.19.283+6 more2024-01-22
CVE-2024-0775 [HIGH] CWE-416 CVE-2024-0775: A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel
A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an information leak problem while freeing the old quota file names before a potential failure, leading to a use-after-free.
nvd
CVE-2009-2844P4HIGHCVSS 7.8v2.6.24.7v2.6.25.152009-08-18
CVE-2009-2844 [HIGH] CWE-399 CVE-2009-2844: cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6
cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6 allows remote attackers to cause a denial of service (crash) via a sequence of beacon frames in which one frame omits an SSID Information Element (IE) and the subsequent frame contains an SSID IE, which triggers a NULL pointer dereference in the cmp_ies fu
nvd
CVE-2022-3564P4HIGHCVSS 7.1vn/a2022-10-17
CVE-2022-3564 [HIGH] CWE-119 CVE-2022-3564: A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is
A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-2110
nvd
CVE-2022-1353P4HIGHCVSS 7.1fixed in 4.9.311≥ 4.10, < 4.14.276+5 more2022-04-29
CVE-2022-1353 [HIGH] CWE-200 CVE-2022-1353: A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. Th
A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.
nvd
CVE-2021-34981P4MEDIUMCVSS 6.7v4.15.0-118-generic2024-05-07
CVE-2021-34981 [MEDIUM] CWE-415 CVE-2021-34981: Linux Kernel Bluetooth CMTP Module Double Free Privilege Escalation Vulnerability. This vulnerabilit
Linux Kernel Bluetooth CMTP Module Double Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists
nvd
CVE-2023-6610P4HIGHCVSS 7.1fixed in 6.1.74≥ 6.2, < 6.6.132023-12-08
CVE-2023-6610 [HIGH] CWE-125 CVE-2023-6610: An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the
An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.
nvd
CVE-2022-3635P4HIGHCVSS 7.0vn/a2022-10-21
CVE-2022-3635 [HIGH] CWE-119 CVE-2022-3635: A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this
A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function tst_timer of the file drivers/atm/idt77252.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. VDB-211934 is the identifier assigned to this vulnerability.
nvd
CVE-2023-5197P4MEDIUMCVSS 6.6≥ 5.9, < 6.62023-09-27
CVE-2023-5197 [MEDIUM] CWE-416 CVE-2023-5197: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
Addition and removal of rules from chain bindings within the same transaction causes leads to use-after-free.
We recommend upgrading past commit f15f29fd4779be8a418b66e9d52979bb6d6c2325.
nvd
CVE-2022-3594P4MEDIUMCVSS 5.3vn/a2022-10-18
CVE-2022-3594 [MEDIUM] CWE-404 CVE-2022-3594: A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vul
A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function intr_callback of the file drivers/net/usb/r8152.c of the component BPF. The manipulation leads to logging of excessive data. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The associ
nvd
CVE-2019-19332P4MEDIUMCVSS 6.1v3.13 through 5.42020-01-09
CVE-2019-19332 [MEDIUM] CWE-787 CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the
An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or process able to access the '/dev/kvm' device could use this flaw to crash the system, resulting
nvd
CVE-2022-3567P4MEDIUMCVSS 6.4vn/a2022-10-17
CVE-2022-3567 [MEDIUM] CWE-362 CVE-2022-3567: A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability aff
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function inet6_stream_ops/inet6_dgram_ops of the component IPv6 Handler. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. VDB-211090 is the identifier assigned to this vulnerability.
nvd
CVE-2022-3435P4MEDIUMCVSS 4.3vn/a2022-10-08
CVE-2022-3435 [MEDIUM] CWE-119 CVE-2022-3435: A vulnerability classified as problematic has been found in Linux Kernel. This affects the function
A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-210357
nvd
CVE-2022-3523P4MEDIUMCVSS 5.3vn/a2022-10-16
CVE-2022-3523 [MEDIUM] CWE-119 CVE-2022-3523: A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is an unk
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is an unknown function of the file mm/memory.c of the component Driver Handler. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is
nvd
CVE-2022-42432P4MEDIUMCVSS 4.4v6.0-rc22023-03-29
CVE-2022-42432 [MEDIUM] CWE-457 CVE-2022-42432: This vulnerability allows local attackers to disclose sensitive information on affected installation
This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel 6.0-rc2. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the nft_osf_eval function. The issue results from the
nvd
CVE-2009-2406P4MEDIUMCVSS 6.9v2.6.24.7v2.6.25.152009-07-31
CVE-2009-2406 [MEDIUM] CWE-119 CVE-2009-2406: Stack-based buffer overflow in the parse_tag_11_packet function in fs/ecryptfs/keystore.c in the eCr
Stack-based buffer overflow in the parse_tag_11_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to not ensuring that the key signature length in a Tag
nvd
CVE-2022-36280P4MEDIUMCVSS 5.5≥ v3.2-rc1, < 5.13.0-52*2022-09-09
CVE-2022-36280 [MEDIUM] CWE-120 CVE-2022-36280: An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/v
An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU component in the Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).
nvd
CVE-2018-10872P4MEDIUMCVSS 5.5vn/a2018-07-10
CVE-2018-10872 [MEDIUM] CWE-250 CVE-2018-10872: A flaw was found in the way the Linux kernel handled exceptions delivered after a stack switch opera
A flaw was found in the way the Linux kernel handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, processor does not deliver interrupts and exceptions, they are delivered once the first instruction after the stack switch is executed. An unprivileged system user could use th
nvd
CVE-2022-3563P4MEDIUMCVSS 5.7vn/a2022-10-17
CVE-2022-3563 [MEDIUM] CWE-404 CVE-2022-3563: A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function r
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/mgmt-tester.c of the component BlueZ. The manipulation of the argument cap_len leads to null pointer dereference. It is recommended to apply a patch to fix this issue. VDB-211086 is the identifier assigne
nvd
CVE-2022-3533P4MEDIUMCVSS 5.7vn/a2022-10-17
CVE-2022-3533 [MEDIUM] CWE-404 CVE-2022-3533: A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects the
A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects the function parse_usdt_arg of the file tools/lib/bpf/usdt.c of the component BPF. The manipulation of the argument reg_name leads to memory leak. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-21
nvd