Linux Kernel vulnerabilities
16,409 known vulnerabilities affecting linux/linux_kernel.
Total CVEs
16,409
CISA KEV
31
actively exploited
Public exploits
315
Exploited in wild
67
Severity breakdown
CRITICAL230HIGH4553MEDIUM9655LOW420UNKNOWN1551
Vulnerabilities
Page 37 of 821
CVE-2023-52801P3CRITICALCVSS 9.1≥ 6.2, < 6.5.13≥ 6.6, < 6.6.32024-05-21
CVE-2023-52801 [CRITICAL] CWE-284 CVE-2023-52801: In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix missing update of
In the Linux kernel, the following vulnerability has been resolved:
iommufd: Fix missing update of domains_itree after splitting iopt_area
In iopt_area_split(), if the original iopt_area has filled a domain and is
linked to domains_itree, pages_nodes have to be properly
reinserted. Otherwise the domains_itree becomes corrupted and we will UAF.
nvdosv
CVE-2014-4608P3HIGHCVSS 7.3fixed in 3.15.22014-07-03
CVE-2014-4608 [HIGH] CWE-190 CVE-2014-4608: Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c
Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Literal Run. NOTE: the author of the LZO algorithms says "the Linux kernel is *not* affected; media h
nvdosv
CVE-2006-1857P3CRITICALCVSS 9.0v2.6.0v2.6.1+58 more2006-05-22
CVE-2006-1857 [CRITICAL] CWE-119 CVE-2006-1857: Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial o
Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed HB-ACK chunk.
nvd
CVE-2016-4580P3HIGHCVSS 7.5≤ 4.5.42016-05-23
CVE-2016-4580 [HIGH] CWE-200 CVE-2016-4580: The x25_negotiate_facilities function in net/x25/x25_facilities.c in the Linux kernel before 4.5.5 d
The x25_negotiate_facilities function in net/x25/x25_facilities.c in the Linux kernel before 4.5.5 does not properly initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory via an X.25 Call Request.
nvdosv
CVE-2002-2438P3HIGHCVSS 7.5fixed in 2.4.20vbefore Linux kernel 2.4.202021-05-18
CVE-2002-2438 [HIGH] CWE-287 CVE-2002-2438: TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) s
TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling.
nvd
CVE-2021-4093P3HIGHCVSS 8.8≥ 5.11, < 5.14.16vkernel 5.152022-02-18
CVE-2021-4093 [HIGH] CWE-125 CVE-2021-4093: A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted
A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KVM guest using SEV-ES can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT for a string I/O instruction (for example, outs or ins) using the exit reason SVM_EXIT_IOIO. This issue results in a crash of the
nvdosv
CVE-2024-35814P3HIGHCVSS 8.8≥ 6.3, < 6.6.24≥ 6.7, < 6.7.12+1 more2024-05-17
CVE-2024-35814 [HIGH] CWE-415 CVE-2024-35814: In the Linux kernel, the following vulnerability has been resolved: swiotlb: Fix double-allocation
In the Linux kernel, the following vulnerability has been resolved:
swiotlb: Fix double-allocation of slots due to broken alignment handling
Commit bbb73a103fbb ("swiotlb: fix a braino in the alignment check fix"),
which was a fix for commit 0eee5ae10256 ("swiotlb: fix slot alignment
checks"), causes a functional regression with vsock in a virtual mac
nvdosv
CVE-2026-52952P3HIGHCVSS 8.8≥ 7.0, < 7.0.10v7.1-rc1+2 more2026-06-24
CVE-2026-52952 [HIGH] CWE-617 CVE-2026-52952: In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in __iommu_g
In the Linux kernel, the following vulnerability has been resolved:
iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset
In __iommu_group_set_domain_internal(), concurrent domain attachments are
rejected when any device in the group is recovering. This is necessary to
fence concurrent attachments to a multi-device group where devices
nvd
CVE-2026-46174P3HIGHCVSS 8.8≥ 3.16.58, < 3.17≥ 4.4.144, < 4.5+19 more2026-05-28
CVE-2026-46174 [HIGH] CVE-2026-46174: In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Prevent improper i
In the Linux kernel, the following vulnerability has been resolved:
x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache
Make sure resources are not improperly shared in the op cache and
cause instruction corruption this way.
nvd
CVE-2026-46317P3HIGHCVSS 8.8≥ 6.11, < 6.18.35≥ 6.19, < 7.0.12+6 more2026-06-09
CVE-2026-46317 [HIGH] CVE-2026-46317: In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmu
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Reassign nested_mmus array behind mmu_lock
kvm->arch.nested_mmus[] is walked under kvm->mmu_lock, including from the
MMU notifier path (kvm_unmap_gfn_range() -> kvm_nested_s2_unmap()), which
can run at any time. kvm_vcpu_init_nested() reallocates the array and frees
the old buffe
nvd
CVE-2026-53188P3HIGHCVSS 8.8≥ 6.15, < 6.18.36≥ 6.19, < 7.0.13+7 more2026-06-25
CVE-2026-53188 [HIGH] CVE-2026-53188: In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Validate the passed
In the Linux kernel, the following vulnerability has been resolved:
RDMA/core: Validate the passed in fops for ib_get_ucaps()
Sashiko pointed out it is not safe to rely only on the devt because
char/block alias so if the user finds a block device with the same dev_t
it can masquerade as a ucap cdev fd.
Test the f_ops to only accept authentic cdevs.
nvd
CVE-2026-53266P3HIGHCVSS 8.8≥ 5.4.73, < 5.5≥ 5.8.17, < 5.9+13 more2026-06-25
CVE-2026-53266 [HIGH] CVE-2026-53266: In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_sna
In the Linux kernel, the following vulnerability has been resolved:
netfilter: bridge: make ebt_snat ARP rewrite writable
The ebtables SNAT target keeps the Ethernet source address rewrite
behind skb_ensure_writable(skb, 0). This is intentional: at the bridge
ebtables hooks the Ethernet header is addressed through
skb_mac_header()/eth_hdr(), while skb->data
nvd
CVE-2017-18174P3CRITICALCVSS 9.8fixed in 4.72018-02-11
CVE-2017-18174 [CRITICAL] CWE-415 CVE-2017-18174: In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls
In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a double free.
nvdosv
CVE-2021-27365P3HIGHCVSS 7.8fixed in 4.4.260≥ 4.5, < 4.9.260+5 more2021-03-07
CVE-2021-27365 [HIGH] CWE-787 CVE-2021-27365: An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not hav
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.
nvdosv
CVE-2016-10764P3CRITICALCVSS 9.8≥ 4.8, < 4.9.62019-07-27
CVE-2016-10764 [CRITICAL] CWE-119 CVE-2016-10764: In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.
In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.c cqspi_setup_flash() function. There are CQSPI_MAX_CHIPSELECT elements in the ->f_pdata array so the ">" should be ">=" instead.
nvdosv
CVE-2021-47023P3HIGHCVSS 8.2≥ 5.10, < 5.10.37≥ 5.11, < 5.11.21+1 more2024-02-28
CVE-2021-47023 [HIGH] CWE-400 CVE-2021-47023: In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix por
In the Linux kernel, the following vulnerability has been resolved:
net: marvell: prestera: fix port event handling on init
For some reason there might be a crash during ports creation if port
events are handling at the same time because fw may send initial
port event with down state.
The crash points to cancel_delayed_work() which is called when po
nvdosv
CVE-2018-6412P3HIGHCVSS 7.5≤ 4.152018-01-31
CVE-2018-6412 [HIGH] CWE-200 CVE-2018-6412: In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4
In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands.
nvdosv
CVE-2026-52920P3HIGHCVSS 8.3≥ 2.6.17, < 5.10.258≥ 5.11, < 5.15.209+6 more2026-06-24
CVE-2026-52920 [HIGH] CVE-2026-52920: In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix stric
In the Linux kernel, the following vulnerability has been resolved:
netfilter: xt_policy: fix strict mode inbound policy matching
match_policy_in() walks sec_path entries from the last transform to the
first one, but strict policy matching needs to consume info->pol[] in
the same forward order as the rule layout.
Derive the strict-match policy position from
nvd
CVE-2021-3492P3HIGHCVSS 7.8≥ 0, < 5.4.0-72.802021-05-17
CVE-2021-3492 [HIGH] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
Vincent Dehors discovered that the shiftfs file system in the Ubuntu Linux
kernel did not properly handle faults in copy_from_user() when passing
through ioctls to an underlying file system. A local attacker could use
this to cause a denial of service (memory exhaustion) or execute arbitrary
code.(CVE-2021-3492)
osv
CVE-2019-18814P3CRITICALCVSS 9.8≤ 5.3.92019-11-07
CVE-2019-18814 [CRITICAL] CWE-416 CVE-2019-18814: An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_p
An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_audit_rule_init() in security/apparmor/audit.c.
nvdosv