cbcvebase.

Linux Kernel vulnerabilities

16,357 known vulnerabilities affecting linux/linux_kernel.

Total CVEs
16,357
CISA KEV
31
actively exploited
Public exploits
315
Exploited in wild
67
Severity breakdown
CRITICAL223HIGH4521MEDIUM9642LOW420UNKNOWN1551

Vulnerabilities

Page 1 of 818
CVE-2022-0847P1HIGHCVSS 7.8KEVPoCRansomware≥ 5.8, < 5.10.102≥ 5.15, < 5.15.25+2 more2022-03-10
CVE-2022-0847 [HIGH] CWE-665 CVE-2022-0847: A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper i A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate thei
nvdosv
CVE-2026-31431P1HIGHCVSS 7.8KEVPoC≥ 4.14, < 5.10.254≥ 5.11, < 5.15.204+11 more2026-04-22
CVE-2026-31431 [HIGH] CWE-669 CVE-2026-31431: In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the compl
nvd
CVE-2016-5195P1HIGHCVSS 7.0KEVPoC≥ 2.6.22, < 3.2.83≥ 3.3, < 3.4.113+8 more2016-11-10
CVE-2016-5195 [HIGH] CWE-362 CVE-2016-5195: Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to ga Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
nvdosv
CVE-2021-22555P1HIGHCVSS 7.8KEVPoC≥ 2.6.19, < 4.4.267≥ 4.5, < 4.9.267+6 more2021-07-07
CVE-2021-22555 [HIGH] CWE-787 CVE-2021-22555: A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_table A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
nvdosv
CVE-2014-3153P1HIGHCVSS 7.8KEVPoCRansomwarefixed in 3.2.60≥ 3.3, < 3.4.92+3 more2014-06-07
CVE-2014-3153 [HIGH] CVE-2014-3153: The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
nvdosv
CVE-2013-2094P1HIGHCVSS 8.4KEVPoCfixed in 3.0.75≥ 3.1, < 3.2.45+2 more2013-05-14
CVE-2013-2094 [HIGH] CWE-189 CVE-2013-2094: The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an inco The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.
nvdosv
CVE-2019-13272P1HIGHCVSS 7.8KEVPoC≥ 3.16.52, < 3.16.71≥ 4.1.39, < 4.2+6 more2019-07-17
CVE-2019-13272 [HIGH] CVE-2019-13272: In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the cr In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing co
nvdosv
CVE-2021-3493P1HIGHCVSS 7.8KEVPoC≥ 0, < 5.4.0-72.802021-04-15
[HIGH] linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke-5.3, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-kvm, linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke-5.3, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-kvm, linux-oem-5.10, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4, linux-raspi2-
osv
CVE-2024-1086P1HIGHCVSS 7.8KEVPoCRansomware≥ 3.15, < 5.15.149≥ 6.1, < 6.1.76+3 more2024-01-31
CVE-2024-1086 [HIGH] CWE-416 CVE-2024-1086: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error whi
nvdosv
CVE-2019-2215P1HIGHCVSS 7.8KEVPoC≥ 0, < 4.15.4-12019-10-11
CVE-2019-2215 [HIGH] CVE-2019-2215: A use-after-free in binder A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
osv
CVE-2013-6282P1HIGHCVSS 8.8KEVPoCfixed in 3.2.54≥ 3.3, < 3.4.12+1 more2013-11-20
CVE-2013-6282 [HIGH] CWE-20 CVE-2013-6282: The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 A The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.
nvdosv
CVE-2022-0185P1HIGHCVSS 8.4KEVPoC≥ 5.1, < 5.4.173≥ 5.5, < 5.10.93+3 more2022-02-11
CVE-2022-0185 [HIGH] CWE-190 CVE-2022-0185: A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesy A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does no
nvdosv
CVE-2017-1000253P1HIGHCVSS 7.8KEVPoCRansomware≥ 2.6.25, < 3.2.70≥ 3.3, < 3.4.109+7 more2017-10-05
CVE-2017-1000253 [HIGH] CWE-119 CVE-2017-1000253: Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/ Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a se
nvdosv
CVE-2018-14634P1HIGHCVSS 7.8KEVPoC≥ 2.6.0, ≤ 2.6.39.4≥ 3.10, ≤ 3.10.102+1 more2018-09-25
CVE-2018-14634 [HIGH] CWE-190 CVE-2018-14634: An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileg An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
nvdosv
CVE-2010-3904P1HIGHCVSS 7.8KEVPoCfixed in 2.6.362010-12-06
CVE-2010-3904 [HIGH] CWE-1284 CVE-2010-3904: The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol im The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
nvd
CVE-2022-0492P1HIGHCVSS 7.8KEVPoC≥ 2.6.24, < 4.9.301≥ 4.10, < 4.14.266+7 more2022-03-03
CVE-2022-0492 [HIGH] CWE-287 CVE-2022-0492: A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgro A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
nvdosv
CVE-2023-0386P1HIGHCVSS 7.8KEVPoC≥ 5.11, < 5.15.91≥ 5.16, < 6.1.9+2 more2023-03-22
CVE-2023-0386 [HIGH] CWE-282 CVE-2023-0386: A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.
nvdosv
CVE-2021-22600P1HIGHCVSS 7.0KEVPoC≥ 4.14.175, < 4.14.259≥ 4.19.114, < 4.19.222+3 more2022-01-26
CVE-2021-22600 [HIGH] CWE-415 CVE-2021-22600: A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user th A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755
nvdosv
CVE-2014-0196P1MEDIUMCVSS 5.5KEVPoCfixed in 3.2.59≥ 3.3, < 3.4.91+4 more2014-05-07
CVE-2014-0196 [MEDIUM] CWE-362 CVE-2014-0196: The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
nvdosv
CVE-2022-2586P1HIGHCVSS 7.8KEVPoC≤ 5.19.17v6.02024-01-08
CVE-2022-2586 [HIGH] CWE-416 CVE-2022-2586: It was discovered that a nft object or expression could reference a nft set on a different nft table It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
nvdosv
1 / 818Next →