Linux Kernel vulnerabilities
16,409 known vulnerabilities affecting linux/linux_kernel.
Total CVEs
16,409
CISA KEV
31
actively exploited
Public exploits
315
Exploited in wild
67
Severity breakdown
CRITICAL230HIGH4553MEDIUM9655LOW420UNKNOWN1551
Vulnerabilities
Page 40 of 821
CVE-2023-1281P3HIGHCVSS 7.8≥ 4.14, < 5.10.169≥ 5.11, < 5.15.95+12 more2023-03-22
CVE-2023-1281 [HIGH] CWE-416 CVE-2023-1281: Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege
Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause a use-after-free when 'tcf_exts_exec()' is called with the destroyed tcf_ext. A local attacker user can use this vulnerability to elevate its privileges to
nvdosv
CVE-2021-4028P3HIGHCVSS 7.8≥ 5.10, < 5.10.71≥ 5.11, < 5.14.10+1 more2022-08-24
CVE-2021-4028 [HIGH] CWE-416 CVE-2021-4028: A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an
A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code, a local attacker could leverage this use-after-free to crash the system or possibly escalate privile
nvdosv
CVE-2020-14351P3HIGHCVSS 7.8fixed in 5.8.17vkernel 5.8.172020-12-03
CVE-2020-14351 [HIGH] CWE-416 CVE-2020-14351: A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem a
A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvdosv
CVE-2024-47742P3HIGHCVSS 7.8≥ 3.7, < 4.19.323≥ 4.20, < 5.4.285+6 more2024-10-21
CVE-2024-47742 [HIGH] CWE-22 CVE-2024-47742: In the Linux kernel, the following vulnerability has been resolved: firmware_loader: Block path tra
In the Linux kernel, the following vulnerability has been resolved:
firmware_loader: Block path traversal
Most firmware names are hardcoded strings, or are constructed from fairly
constrained format strings where the dynamic parts are just some hex
numbers or such.
However, there are a couple codepaths in the kernel where firmware file
names contain
nvdosv
CVE-2024-36978P3HIGHCVSS 7.8≥ 5.4, < 5.4.279≥ 5.5, < 5.10.221+5 more2024-06-19
CVE-2024-36978 [HIGH] CWE-787 CVE-2024-36978: In the Linux kernel, the following vulnerability has been resolved: net: sched: sch_multiq: fix pos
In the Linux kernel, the following vulnerability has been resolved:
net: sched: sch_multiq: fix possible OOB write in multiq_tune()
q->bands will be assigned to qopt->bands to execute subsequent code logic
after kmalloc. So the old q->bands should not be used in kmalloc.
Otherwise, an out-of-bounds write will occur.
nvdosv
CVE-2024-1085P3HIGHCVSS 7.8≥ 5.13, < 5.15.148≥ 5.16, < 6.1.75+2 more2024-01-31
CVE-2024-1085 [HIGH] CWE-416 CVE-2024-1085: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
The nft_setelem_catchall_deactivate() function checks whether the catch-all set element is active in the current generation instead of the next generation before freeing it, but only flags it inactive in the next g
nvdosv
CVE-2023-1670P3HIGHCVSS 7.8≥ 2.6.18, < 4.14.312≥ 4.15, < 4.19.280+6 more2023-03-30
CVE-2023-1670 [HIGH] CWE-416 CVE-2023-1670: A flaw use after free in the Linux kernel Xircom 16-bit PCMCIA (PC-card) Ethernet driver was found.A
A flaw use after free in the Linux kernel Xircom 16-bit PCMCIA (PC-card) Ethernet driver was found.A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
nvdosv
CVE-2022-48948P3HIGHCVSS 7.8≥ 2.6.35, < 4.9.337≥ 4.10, < 4.14.303+6 more2024-10-21
CVE-2022-48948 [HIGH] CWE-120 CVE-2022-48948: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: Prevent buffe
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: uvc: Prevent buffer overflow in setup handler
Setup function uvc_function_setup permits control transfer
requests with up to 64 bytes of payload (UVC_MAX_REQUEST_SIZE),
data stage handler for OUT transfer uses memcpy to copy req->actual
bytes to uvc_event->data.data arra
nvdosv
CVE-2024-26753P3HIGHCVSS 7.8≥ 5.10.209, < 5.10.212≥ 5.18, < 6.1.80+3 more2024-04-03
CVE-2024-26753 [HIGH] CWE-787 CVE-2024-26753: In the Linux kernel, the following vulnerability has been resolved: crypto: virtio/akcipher - Fix s
In the Linux kernel, the following vulnerability has been resolved:
crypto: virtio/akcipher - Fix stack overflow on memcpy
sizeof(struct virtio_crypto_akcipher_session_para) is less than
sizeof(struct virtio_crypto_op_ctrl_req::u), copying more bytes from
stack variable leads stack overflow. Clang reports this issue by
commands:
make -j CC=clang-14 m
nvdosv
CVE-2021-47404P3HIGHCVSS 7.8fixed in 4.4.286≥ 4.5, < 4.9.285+6 more2024-05-21
CVE-2021-47404 [HIGH] CWE-787 CVE-2021-47404: In the Linux kernel, the following vulnerability has been resolved: HID: betop: fix slab-out-of-bou
In the Linux kernel, the following vulnerability has been resolved:
HID: betop: fix slab-out-of-bounds Write in betop_probe
Syzbot reported slab-out-of-bounds Write bug in hid-betopff driver.
The problem is the driver assumes the device must have an input report but
some malicious devices violate this assumption.
So this patch checks hid_device's in
nvdosv
CVE-2024-42148P3HIGHCVSS 7.8≥ 3.3, < 4.19.318≥ 4.20, < 5.4.280+5 more2024-07-30
CVE-2024-42148 [HIGH] CWE-129 CVE-2024-42148: In the Linux kernel, the following vulnerability has been resolved: bnx2x: Fix multiple UBSAN array
In the Linux kernel, the following vulnerability has been resolved:
bnx2x: Fix multiple UBSAN array-index-out-of-bounds
Fix UBSAN warnings that occur when using a system with 32 physical
cpu cores or more, or when the user defines a number of Ethernet
queues greater than or equal to FP_SB_MAX_E1x using the num_queues
module parameter.
Currently ther
nvdosv
CVE-2024-53142P3HIGHCVSS 7.8≥ 2.6.12, < 4.19.325≥ 4.20, < 6.6.64+2 more2024-12-06
CVE-2024-53142 [HIGH] CWE-787 CVE-2024-53142: In the Linux kernel, the following vulnerability has been resolved: initramfs: avoid filename buffe
In the Linux kernel, the following vulnerability has been resolved:
initramfs: avoid filename buffer overrun
The initramfs filename field is defined in
Documentation/driver-api/early-userspace/buffer-format.rst as:
37 cpio_file := ALGN(4) + cpio_header + filename + "\0" + ALGN(4) + data
...
55 ============= ================== =======================
nvdosv
CVE-2026-52943P3HIGHCVSS 7.8≥ 4.7, < 5.10.259≥ 5.11, < 5.15.210+10 more2026-06-24
CVE-2026-52943 [HIGH] CWE-416 CVE-2026-52943: In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zeroco
In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: fix missing zerocopy reference in pskb_carve helpers
pskb_carve_inside_header() and pskb_carve_inside_nonlinear() both copy
the old skb_shared_info header into a new buffer via memcpy(), which
includes the destructor_arg pointer (uarg) for MSG_ZEROCOPY skbs.
Neither func
nvd
CVE-2024-53194P3HIGHCVSS 7.8fixed in 4.19.325≥ 4.20, < 5.4.287+6 more2024-12-27
CVE-2024-53194 [HIGH] CWE-416 CVE-2024-53194: In the Linux kernel, the following vulnerability has been resolved: PCI: Fix use-after-free of slot
In the Linux kernel, the following vulnerability has been resolved:
PCI: Fix use-after-free of slot->bus on hot remove
Dennis reports a boot crash on recent Lenovo laptops with a USB4 dock.
Since commit 0fc70886569c ("thunderbolt: Reset USB4 v2 host router") and
commit 59a54c5f3dbd ("thunderbolt: Reset topology created by the boot
firmware"), USB4 v
nvdosv
CVE-2024-26936P3HIGHCVSS 7.8≥ 5.15, < 5.15.159≥ 5.16, < 6.1.88+3 more2024-05-01
CVE-2024-26936 [HIGH] CWE-120 CVE-2024-26936: In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate request buffer
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate request buffer size in smb2_allocate_rsp_buf()
The response buffer should be allocated in smb2_allocate_rsp_buf
before validating request. But the fields in payload as well as smb2 header
is used in smb2_allocate_rsp_buf(). This patch add simple buffer size
validation
nvdosv
CVE-2025-39952P3HIGHCVSS 7.8≥ 4.2, < 6.6.108≥ 6.7, < 6.12.49+5 more2025-10-04
CVE-2025-39952 [HIGH] CWE-787 CVE-2025-39952: In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: avoid buffer ov
In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: avoid buffer overflow in WID string configuration
Fix the following copy overflow warning identified by Smatch checker.
drivers/net/wireless/microchip/wilc1000/wlan_cfg.c:184 wilc_wlan_parse_response_frame()
error: '__memcpy()' 'cfg->s[i]->str' copy overflow (512 vs
nvdosv
CVE-2025-37891P3HIGHCVSS 7.8≥ 6.5, < 6.6.90≥ 6.7, < 6.12.28+5 more2025-05-19
CVE-2025-37891 [HIGH] CWE-120 CVE-2025-37891: In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: Fix buffer overflow
In the Linux kernel, the following vulnerability has been resolved:
ALSA: ump: Fix buffer overflow at UMP SysEx message conversion
The conversion function from MIDI 1.0 to UMP packet contains an
internal buffer to keep the incoming MIDI bytes, and its size is 4, as
it was supposed to be the max size for a MIDI1 UMP packet data.
However, the implementa
nvdosv
CVE-2026-31786P3HIGHCVSS 7.8≥ 4.13, < 5.10.254≥ 5.11, < 5.15.204+6 more2026-04-30
CVE-2026-31786 [HIGH] CWE-787 CVE-2026-31786: In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/
In the Linux kernel, the following vulnerability has been resolved:
Buffer overflow in drivers/xen/sys-hypervisor.c
The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is
neither NUL terminated nor a string.
The first causes a buffer overflow as sprintf in buildid_show will
read and copy till it finds a NUL.
00000000 f4 91 51 f4 dd 38
nvd
CVE-2025-71162P3HIGHCVSS 7.8≥ 4.7, < 5.10.249≥ 5.11, < 5.15.199+9 more2026-01-25
CVE-2025-71162 [HIGH] CWE-416 CVE-2025-71162: In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: tegra-adma: Fix use-after-free
A use-after-free bug exists in the Tegra ADMA driver when audio streams
are terminated, particularly during XRUN conditions. The issue occurs
when the DMA buffer is freed by tegra_adma_terminate_all() before the
vchan completion tasklet finis
nvdosv
CVE-2026-45984P3HIGHCVSS 7.8≥ 5.2, < 5.10.252≥ 5.11, < 5.15.202+5 more2026-05-27
CVE-2026-45984 [HIGH] CWE-416 CVE-2026-45984: In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix use-after-free in iom
In the Linux kernel, the following vulnerability has been resolved:
gfs2: Fix use-after-free in iomap inline data write path
The inline data buffer head (dibh) is being released prematurely in
gfs2_iomap_begin() via release_metapath() while iomap->inline_data
still points to dibh->b_data. This causes a use-after-free when
iomap_write_end_inline() lat
nvd