cbcvebase.

Linux Kernel vulnerabilities

16,409 known vulnerabilities affecting linux/linux_kernel.

Total CVEs
16,409
CISA KEV
31
actively exploited
Public exploits
315
Exploited in wild
67
Severity breakdown
CRITICAL230HIGH4553MEDIUM9655LOW420UNKNOWN1551

Vulnerabilities

Page 43 of 821
CVE-2026-43031P3HIGHCVSS 7.5≥ 6.15, < 6.18.22≥ 6.19, < 6.19.12+1 more2026-05-01
CVE-2026-43031 [HIGH] CVE-2026-43031: In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Fix BQL a In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets When a TX packet spans multiple buffer descriptors (scatter-gather), axienet_free_tx_chain sums the per-BD actual length from descriptor status into a caller-provided accumulator. That sum is reset on each NAPI poll. If the BDs
nvd
CVE-2026-52956P3HIGHCVSS 7.5≥ 4.9.6, < 4.10≥ 4.10, < 7.0.10+3 more2026-06-24
CVE-2026-52956 [HIGH] CWE-125 CVE-2026-52956: In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-b In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() In __ceph_x_decrypt(), a part of the buffer p is interpreted as a ceph_x_encrypt_header, and the magic field of this struct is accessed. This happens without any guarantee that the buffer is large enough to hold this s
nvd
CVE-2026-43029P3HIGHCVSS 7.5≥ 6.18.1, < 6.18.22≥ 6.19, < 6.19.12+5 more2026-05-01
CVE-2026-43029 [HIGH] CWE-667 CVE-2026-43029: In the Linux kernel, the following vulnerability has been resolved: mptcp: fix soft lockup in mptcp In the Linux kernel, the following vulnerability has been resolved: mptcp: fix soft lockup in mptcp_recvmsg() syzbot reported a soft lockup in mptcp_recvmsg() [0]. When receiving data with MSG_PEEK | MSG_WAITALL flags, the skb is not removed from the sk_receive_queue. This causes sk_wait_data() to always find available data and never perform actual
nvd
CVE-2025-22088P3CRITICALCVSS 9.8≥ 6.0, < 6.1.134≥ 6.2, < 6.6.87+3 more2025-04-16
CVE-2025-22088 [CRITICAL] CWE-416 CVE-2025-22088: In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Prevent use-after-f In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Prevent use-after-free in erdma_accept_newconn() After the erdma_cep_put(new_cep) being called, new_cep will be freed, and the following dereference will cause a UAF problem. Fix this issue.
nvdosv
CVE-2019-17075P3HIGHCVSS 7.5≥ 2.6.35, < 4.4.198≥ 4.5.0, < 4.9.198+3 more2019-10-01
CVE-2019-17075 [HIGH] CVE-2019-17075: An issue was discovered in write_tpt_entry in drivers/infiniband/hw/cxgb4/mem.c in the Linux kernel An issue was discovered in write_tpt_entry in drivers/infiniband/hw/cxgb4/mem.c in the Linux kernel through 5.3.2. The cxgb4 driver is directly calling dma_map_single (a DMA function) from a stack variable. This could allow an attacker to trigger a Denial of Service, exploitable if this driver is used on an architecture for which this stack/DMA interaction has
nvdosv
CVE-2018-20961P3CRITICALCVSS 9.8≥ 4.4, < 4.4.190≥ 4.5, < 4.9.96+2 more2019-08-07
CVE-2018-20961 [CRITICAL] CWE-415 CVE-2018-20961: In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of dri In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may allow attackers to cause a denial of service or possibly have unspecified other impact.
nvdosv
CVE-2019-11810P3HIGHCVSS 7.5fixed in 3.16.69≥ 3.17, < 3.18.139+5 more2019-05-07
CVE-2019-11810 [HIGH] CWE-416 CVE-2019-11810: An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds() in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service, related to a use-after-free.
nvdosv
CVE-2009-4020P3HIGHCVSS 7.8v2.6.322009-12-04
CVE-2009-4020 [HIGH] CWE-119 CVE-2009-4020: Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.
nvd
CVE-2016-2184P4MEDIUMCVSS 4.6PoC≤ 4.5.02016-04-27
CVE-2016-2184 [MEDIUM] CVE-2016-2184: The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linu The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) via a crafted endpoints value in a USB device descriptor.
nvdosv
CVE-2025-68803P3UNKNOWN≥ 0, < 5.10.249-1≥ 0, < 6.1.162-1+2 more2026-01-13
CVE-2025-68803 CVE-2025-68803: In the Linux kernel, the following vulnerability has been resolved: NFSD: NFSv4 file creation neglects setting ACL An NFSv4 client that sets an ACL wi In the Linux kernel, the following vulnerability has been resolved: NFSD: NFSv4 file creation neglects setting ACL An NFSv4 client that sets an ACL with a named principal during file creation retrieves the ACL afterwards, and finds that it is only a default ACL (based on the mode bits) and not the ACL that was reques
osv
CVE-2025-40342P3UNKNOWN≥ 0, < 5.10.247-1≥ 0, < 6.1.159-1+2 more2025-12-09
CVE-2025-40342 CVE-2025-40342: In the Linux kernel, the following vulnerability has been resolved: nvme-fc: use lock accessing port_state and rport state nvme_fc_unregister_remote r In the Linux kernel, the following vulnerability has been resolved: nvme-fc: use lock accessing port_state and rport state nvme_fc_unregister_remote removes the remote port on a lport object at any point in time when there is no active association. This races with with the reconnect logic, because nvme_fc_create_asso
osv
CVE-2015-7515P4MEDIUMCVSS 4.6PoCfixed in 4.4v4.42016-04-27
CVE-2015-7515 [MEDIUM] CWE-476 CVE-2015-7515: The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows phy The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device that lacks endpoints.
nvdosv
CVE-2016-3136P4MEDIUMCVSS 4.6PoC≤ 4.5.02016-05-02
CVE-2016-3136 [MEDIUM] CVE-2016-3136: The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device without two interrupt-in endpoint descriptors.
nvdosv
CVE-2025-40140P3UNKNOWN≥ 2.6.12, < 5.4.301≥ 5.5.0, < 5.10.246+5 more2025-11-12
CVE-2025-40140 net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast In the Linux kernel, the following vulnerability has been resolved: net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast syzbot reported WARNING in rtl8150_start_xmit/usb_submit_urb. This is the sequence of events that leads to the warning: rtl8150_start_xmit() { netif_stop_queue(); usb_submit_urb(dev->tx_urb); } rtl8150_
osv
CVE-2025-39982P3UNKNOWN≥ 0, < 6.1.158-1≥ 0, < 6.12.57-1+1 more2025-10-15
CVE-2025-39982 CVE-2025-39982: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync This fixes the following In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync This fixes the following UFA in hci_acl_create_conn_sync where a connection still pending is command submission (conn->state == BT_OPEN) maybe freed, also since this also can happen with the l
osv
CVE-2025-68256P3UNKNOWN≥ 4.12.0, < 6.1.160≥ 6.2.0, < 6.6.120+3 more2025-12-16
CVE-2025-68256 staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser The Information Element (IE) parser rtw_get_ie() trusted the length byte of each IE without validating that the IE body (len bytes after the 2-byte header) fits inside the remaining frame buffer. A malformed frame ca
osv
CVE-2025-40000P3UNKNOWN≥ 0, < 6.12.57-1≥ 0, < 6.16.12-12025-10-15
CVE-2025-40000 CVE-2025-40000: In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix use-after-free in rtw89_core_tx_kick_off_and_wait() There is a bu In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix use-after-free in rtw89_core_tx_kick_off_and_wait() There is a bug observed when rtw89_core_tx_kick_off_and_wait() tries to access already freed skb_data: BUG: KFENCE: use-after-free write in rtw89_core_tx_kick_off_and_wait drivers/n
osv
CVE-2025-39983P3UNKNOWN≥ 0, < 6.16.10-12025-10-15
CVE-2025-39983 CVE-2025-39983: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix UAF in hci_conn_tx_dequeue This fixes the following UAF In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix UAF in hci_conn_tx_dequeue This fixes the following UAF caused by not properly locking hdev when processing HCI_EV_NUM_COMP_PKTS: BUG: KASAN: slab-use-after-free in hci_conn_tx_dequeue+0x1be/0x220 net/bluetooth/hci_conn.c:303
osv
CVE-2025-40068P3UNKNOWN≥ 5.15.0, < 5.15.195≥ 5.16.0, < 6.1.156+3 more2025-10-28
CVE-2025-40068 fs: ntfs3: Fix integer overflow in run_unpack() fs: ntfs3: Fix integer overflow in run_unpack() In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: Fix integer overflow in run_unpack() The MFT record relative to the file being opened contains its runlist, an array containing information about the file's location on the physical disk. Analysis of all Call Stack paths showed that the values of the runlist array, from which LCNs are calculated, are not v
osv
CVE-2025-39985P3UNKNOWN≥ 0, < 5.10.247-1≥ 0, < 6.1.158-1+2 more2025-10-15
CVE-2025-39985 CVE-2025-39985: In the Linux kernel, the following vulnerability has been resolved: can: mcba_usb: populate ndo_change_mtu() to prevent buffer overflow Sending an PF_ In the Linux kernel, the following vulnerability has been resolved: can: mcba_usb: populate ndo_change_mtu() to prevent buffer overflow Sending an PF_PACKET allows to bypass the CAN framework logic and to directly reach the xmit() function of a CAN driver. The only check which is performed by the PF_PACKET framework
osv
Linux Kernel vulnerabilities | cvebase