cbcvebase.

Linux Kernel vulnerabilities

16,409 known vulnerabilities affecting linux/linux_kernel.

Total CVEs
16,409
CISA KEV
31
actively exploited
Public exploits
315
Exploited in wild
67
Severity breakdown
CRITICAL230HIGH4553MEDIUM9655LOW420UNKNOWN1551

Vulnerabilities

Page 38 of 821
CVE-2026-46307P3HIGHCVSS 8.3≥ 3.0, < 5.10.258≥ 5.11, < 5.15.209+7 more2026-06-08
CVE-2026-46307 [HIGH] CWE-125 CVE-2026-46307: In the Linux kernel, the following vulnerability has been resolved: wifi: ath5k: do not access arra In the Linux kernel, the following vulnerability has been resolved: wifi: ath5k: do not access array OOB Vincent reports: > The ath5k driver seems to do an array-index-out-of-bounds access as > shown by the UBSAN kernel message: > UBSAN: array-index-out-of-bounds in drivers/net/wireless/ath/ath5k/base.c:1741:20 > index 4 is out of range for type 'iee
nvd
CVE-2021-3347P3HIGHCVSS 7.8≤ 5.10.112021-01-29
CVE-2021-3347 [HIGH] CWE-416 CVE-2021-3347: An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-afte An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.
nvdosv
CVE-2022-1011P3HIGHCVSS 7.8fixed in 5.17v5.17+1 more2022-03-18
CVE-2022-1011 [HIGH] CWE-416 CVE-2022-1011: A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers wri A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.
nvdosv
CVE-2026-31788P3HIGHCVSS 8.2≥ 2.6.37.1, < 5.10.253≥ 5.11, < 5.15.203+7 more2026-03-25
CVE-2026-31788 [HIGH] CVE-2026-31788: In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: restrict usage in In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: restrict usage in unprivileged domU The Xen privcmd driver allows to issue arbitrary hypercalls from user space processes. This is normally no problem, as access is usually limited to root and the hypervisor will deny any hypercalls affecting other domains. In case the guest is
nvdosv
CVE-2014-0101P3HIGHCVSS 7.8≥ 2.6.24, < 3.2.56≥ 3.3, < 3.4.84+3 more2014-03-11
CVE-2014-0101 [HIGH] CWE-476 CVE-2014-0101: The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does n The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and
nvdosv
CVE-2023-1829P3HIGHCVSS 7.8fixed in 4.14.308≥ 4.15, < 4.19.276+12 more2023-04-12
CVE-2023-1829 [HIGH] CWE-416 CVE-2023-1829: A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exp A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker
nvdosv
CVE-2022-3910P3HIGHCVSS 7.8≥ 5.18, < 5.19.11v6.0+1 more2022-11-22
CVE-2022-3910 [HIGH] CWE-416 CVE-2022-3910: Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Refe Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Reference Count in io_uring leads to Use-After-Free and Local Privilege Escalation. When io_msg_ring was invoked with a fixed file, it called io_fput_file() which improperly decreased its reference count (leading to Use-After-Free and Local Privilege Escalati
nvdosv
CVE-2020-10757P3HIGHCVSS 7.8≥ 4.5, < 4.9.227≥ 4.10, < 4.14.184+5 more2020-06-09
CVE-2020-10757 [HIGH] CWE-119 CVE-2020-10757: A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pa A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
nvdosv
CVE-2016-7039P3HIGHCVSS 7.5≥ 4.0, < 4.1.37≥ 4.2, < 4.4.32+1 more2016-10-16
CVE-2016-7039 [HIGH] CWE-399 CVE-2016-7039: The IP stack in the Linux kernel through 4.8.2 allows remote attackers to cause a denial of service The IP stack in the Linux kernel through 4.8.2 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for large crafted packets, as demonstrated by packets that contain only VLAN headers, a related issue to CVE-2016-8666.
nvdosv
CVE-2022-50386P3HIGHCVSS 8.0fixed in 4.9.331≥ 4.10, < 4.14.296+6 more2025-09-18
CVE-2022-50386 [HIGH] CWE-416 CVE-2022-50386: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix user-afte In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix user-after-free This uses l2cap_chan_hold_unless_zero() after calling __l2cap_get_chan_blah() to prevent the following trace: Bluetooth: l2cap_core.c:static void l2cap_chan_destroy(struct kref *kref) Bluetooth: chan 0000000023c4974d Bluetooth: parent 00000000ae
nvdosv
CVE-2020-14381P3HIGHCVSS 7.8fixed in 5.6v5.6+1 more2020-12-03
CVE-2020-14381 [HIGH] CWE-416 CVE-2020-14381: A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to co A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory or escalate their privileges when creating a futex on a filesystem that is about to be unmounted. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvdosv
CVE-2022-1679P3HIGHCVSS 7.8≥ 2.6.35, < 4.14.291≥ 4.15, < 4.19.256+6 more2022-05-16
CVE-2022-1679 [HIGH] CWE-416 CVE-2022-1679: A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a u A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system.
nvdosv
CVE-2023-6535P3HIGHCVSS 7.5≥ 0, < 5.10.209-1≥ 0, < 6.1.76-1+1 more2024-02-07
CVE-2023-6535 [HIGH] CVE-2023-6535: A flaw was found in the Linux kernel's NVMe driver A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial of service.
osv
CVE-2023-6536P3HIGHCVSS 7.5≥ 5.0, < 5.4.268≥ 5.5, < 5.10.209+4 more2024-02-07
CVE-2023-6536 [HIGH] CWE-476 CVE-2023-6536: A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated maliciou A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial of service.
nvdosv
CVE-2026-53357P3HIGHCVSS 8.0≥ 5.7, < 5.10.259≥ 5.11, < 5.15.210+9 more2026-07-02
CVE-2026-53357 [HIGH] CVE-2026-53357: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_soc In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() bt_accept_dequeue() unlinks a not-yet-accepted child from the parent accept queue and release_sock()s it before returning, so the returned sk has no caller reference and is unlocked. l2cap_sock_cleanup_listen() walks thes
nvd
CVE-2026-43499P3HIGHCVSS 7.8≥ 2.6.39, < 6.1.175≥ 6.2, < 6.6.140+3 more2026-05-21
CVE-2026-43499 [HIGH] CWE-416 CVE-2026-43499: In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task inste In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_wai
nvd
CVE-2023-6356P3HIGHCVSS 7.5≥ 5.0, < 5.4.268≥ 5.5, < 5.10.209+4 more2024-02-07
CVE-2023-6356 [HIGH] CWE-476 CVE-2023-6356: A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated maliciou A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver and causing kernel panic and a denial of service.
nvdosv
CVE-2019-25044P3HIGHCVSS 7.8v5.22021-05-14
CVE-2019-25044 [HIGH] CWE-416 CVE-2019-25044: The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary c The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related to blk_mq_free_rqs and blk_cleanup_queue.
nvd
CVE-2019-14835P3HIGHCVSS 7.8≥ 2.6.34, < 3.16.74≥ 4.4, < 4.4.193+5 more2019-09-17
CVE-2019-14835 [HIGH] CWE-120 CVE-2019-14835: A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their pr
nvdosv
CVE-2021-38300P3HIGHCVSS 7.8≥ 3.16, < 4.14.251≥ 4.15, < 4.19.211+3 more2021-09-20
CVE-2021-38300 [HIGH] CVE-2021-38300: arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel context. This occurs because conditional branches can exceed the 128 KB limit of the MIPS architecture.
nvdosv
Linux Kernel vulnerabilities | cvebase