Linux Kernel vulnerabilities
16,409 known vulnerabilities affecting linux/linux_kernel.
Total CVEs
16,409
CISA KEV
31
actively exploited
Public exploits
315
Exploited in wild
67
Severity breakdown
CRITICAL230HIGH4553MEDIUM9655LOW420UNKNOWN1551
Vulnerabilities
Page 45 of 821
CVE-2021-38207P3HIGHCVSS 7.5fixed in 5.12.132021-08-08
CVE-2021-38207 [HIGH] CWE-120 CVE-2021-38207: drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attacke
drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial of service (buffer overflow and lockup) by sending heavy network traffic for about ten minutes.
nvdosv
CVE-2019-18805P3CRITICALCVSS 9.8≥ 4.4, < 4.4.180≥ 4.9, < 4.9.172+4 more2019-11-07
CVE-2019-18805 [CRITICAL] CWE-190 CVE-2019-18805: An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other impact, aka CID-19fad20d15a6.
nvdosv
CVE-2022-1678P3HIGHCVSS 7.5≥ 4.18, ≤ 4.19≥ 4.18, < unspecified+1 more2022-05-25
CVE-2022-1678 [HIGH] CWE-911 CVE-2022-1678: An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference
An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.
nvdosv
CVE-2022-47940P3HIGHCVSS 8.1≥ 5.15, < 5.15.145≥ 5.16, < 5.18.182022-12-23
CVE-2022-47940 [HIGH] CWE-125 CVE-2022-47940: An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2_write.
nvdosv
CVE-2018-9363P3HIGHCVSS 8.4≥ 3.14, < 3.16.58≥ 3.17, < 3.18.119+5 more2018-11-06
CVE-2018-9363 [HIGH] CWE-190 CVE-2018-9363: In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of
In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-65853588 References: Upstream kernel.
nvdosv
CVE-2018-16884P3HIGHCVSS 8.0≥ 3.7, < 3.16.65≥ 3.17, < 3.18.133+5 more2018-12-18
CVE-2018-16884 [HIGH] CWE-416 CVE-2018-16884: A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network
A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privil
nvdosv
CVE-2017-7184P3HIGHCVSS 7.8v4.8fixed in 3.2.89+8 more2017-03-19
CVE-2017-7184 [HIGH] CVE-2017-7184: The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does
The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competitio
nvdosv
CVE-2016-20022P3HIGHCVSS 8.4≥ 0, < 4.7.4-12024-06-27
CVE-2016-20022 [HIGH] CVE-2016-20022: In the Linux kernel before 4
In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.
osv
CVE-2026-46288P3HIGHCVSS 8.4≥ 6.12, < 6.12.86≥ 6.13, < 6.18.27+1 more2026-06-08
CVE-2026-46288 [HIGH] CWE-416 CVE-2026-46288: In the Linux kernel, the following vulnerability has been resolved: of: unittest: fix use-after-fre
In the Linux kernel, the following vulnerability has been resolved:
of: unittest: fix use-after-free in of_unittest_changeset()
The variable 'parent' is assigned the value of 'nchangeset' earlier in the
function, meaning both point to the same struct device_node. The call to
of_node_put(nchangeset) can decrement the reference count to zero and
free t
nvd
CVE-2026-53369P3HIGHCVSS 8.4≥ 2.6.12.1, < 5.10.258≥ 5.11, < 5.15.209+11 more2026-07-19
CVE-2026-53369 [HIGH] CVE-2026-53369: In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with ov
In the Linux kernel, the following vulnerability has been resolved:
udf: reject descriptors with oversized CRC length
udf_read_tagged() skips CRC verification when descCRCLength +
sizeof(struct tag) exceeds the block size. A crafted UDF image can
set descCRCLength to an oversized value to bypass CRC validation
entirely; the descriptor is then accepted based
nvd
CVE-2026-43274P3HIGHCVSS 8.4≥ 6.14, < 6.18.16≥ 6.19, < 6.19.62026-05-06
CVE-2026-43274 [HIGH] CWE-125 CVE-2026-43274: In the Linux kernel, the following vulnerability has been resolved: mailbox: mchp-ipc-sbi: fix out-
In the Linux kernel, the following vulnerability has been resolved:
mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq()
The cluster_cfg array is dynamically allocated to hold per-CPU
configuration structures, with its size based on the number of online
CPUs. Previously, this array was indexed using hartid, which may be
nvd
CVE-2026-46270P3HIGHCVSS 8.4≥ 4.2, < 5.10.252≥ 5.11, < 5.15.202+5 more2026-06-03
CVE-2026-46270 [HIGH] CWE-416 CVE-2026-46270: In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-
In the Linux kernel, the following vulnerability has been resolved:
power: supply: rt9455: Fix use-after-free in power_supply_changed()
Using the `devm_` variant for requesting IRQ _before_ the `devm_`
variant for allocating/registering the `power_supply` handle, means that
the `power_supply` handle will be deallocated/unregistered _before_ the
inter
nvd
CVE-2026-43365P3HIGHCVSS 8.2≥ 5.14, < 5.15.203≥ 5.16, < 6.1.167+5 more2026-05-08
CVE-2026-43365 [HIGH] CVE-2026-43365: In the Linux kernel, the following vulnerability has been resolved: xfs: fix undersized l_iclog_rou
In the Linux kernel, the following vulnerability has been resolved:
xfs: fix undersized l_iclog_roundoff values
If the superblock doesn't list a log stripe unit, we set the incore log
roundoff value to 512. This leads to corrupt logs and unmountable
filesystems in generic/617 on a disk with 4k physical sectors...
XFS (sda1): Mounting V5 Filesystem ff3121ca-
nvd
CVE-2006-2451P4MEDIUMCVSS 4.6PoCv2.6.13v2.6.13.1+48 more2006-07-07
CVE-2006-2451 [MEDIUM] CWE-399 CVE-2006-2451: The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2
The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl function and a program that causes a core dump file to be created in a directory for which the user
nvd
CVE-2026-31613P3HIGHCVSS 8.1≥ 6.1, < 6.18.24≥ 6.19, < 6.19.14+1 more2026-04-24
CVE-2026-31613 [HIGH] CWE-125 CVE-2026-31613: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB reads pars
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix OOB reads parsing symlink error response
When a CREATE returns STATUS_STOPPED_ON_SYMLINK, smb2_check_message()
returns success without any length validation, leaving the symlink
parsers as the only defense against an untrusted server.
symlink_data() walks SMB 3.1.1
nvd
CVE-2023-52434P3HIGHCVSS 8.0≥ 5.3, < 5.4.277≥ 5.5, < 5.10.211+4 more2024-02-20
CVE-2023-52434 [HIGH] CWE-119 CVE-2023-52434: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix potential OOBs in smb2_parse_contexts()
Validate offsets and lengths before dereferencing create contexts in
smb2_parse_contexts().
This fixes following oops when accessing invalid create contexts from
server:
BUG: unable to handle page fault for address: ffff88811
nvdosv
CVE-2026-31708P3HIGHCVSS 8.1≥ 5.1, < 6.6.136≥ 6.7, < 6.12.84+2 more2026-05-01
CVE-2026-31708 [HIGH] CWE-125 CVE-2026-31708: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read in sm
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path
smb2_ioctl_query_info() has two response-copy branches: PASSTHRU_FSCTL
and the default QUERY_INFO path. The QUERY_INFO branch clamps
qi.input_buffer_length to the server-reported OutputBufferLength and then
copies qi.
nvd
CVE-2022-24122P3HIGHCVSS 7.8≥ 5.14, < 5.15.19≥ 5.16, < 5.16.52022-01-29
CVE-2022-24122 [HIGH] CWE-416 CVE-2022-24122: kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabl
kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
nvdosv
CVE-2026-31393P3HIGHCVSS 8.1≥ 2.6.24, < 5.10.253≥ 5.11, < 5.15.203+9 more2026-04-03
CVE-2026-31393 [HIGH] CWE-125 CVE-2026-31393: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate L2CA
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access
l2cap_information_rsp() checks that cmd_len covers the fixed
l2cap_info_rsp header (type + result, 4 bytes) but then reads
rsp->data without verifying that the payload is present:
- L2CAP_IT_FEAT_MASK calls get_u
nvdosv
CVE-2026-43362P3HIGHCVSS 8.1≥ 4.11, < 6.6.130≥ 6.7, < 6.12.78+3 more2026-05-08
CVE-2026-43362 [HIGH] CWE-787 CVE-2026-43362: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix in-place encry
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix in-place encryption corruption in SMB2_write()
SMB2_write() places write payload in iov[1..n] as part of rq_iov.
smb3_init_transform_rq() pointer-shares rq_iov, so crypt_message()
encrypts iov[1] in-place, replacing the original plaintext with
ciphertext. On a replay
nvd