cbcvebase.

Linux Kernel vulnerabilities

16,409 known vulnerabilities affecting linux/linux_kernel.

Total CVEs
16,409
CISA KEV
31
actively exploited
Public exploits
315
Exploited in wild
67
Severity breakdown
CRITICAL230HIGH4553MEDIUM9655LOW420UNKNOWN1551

Vulnerabilities

Page 46 of 821
CVE-2017-18509P3HIGHCVSS 7.8fixed in 3.16.72≥ 3.17, < 4.4.187+2 more2019-08-13
CVE-2017-18509 [HIGH] CWE-20 CVE-2017-18509: An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific s An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC c
nvdosv
CVE-2022-42720P3HIGHCVSS 7.8≥ 5.1, < 5.4.218≥ 5.5, < 5.10.148+3 more2022-10-14
CVE-2022-42720 [HIGH] CWE-416 CVE-2022-42720: Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 thr Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.
nvdosv
CVE-2024-26952P3HIGHCVSS 7.8≥ 5.15, < 5.15.181≥ 5.16, < 6.1.119+3 more2024-05-01
CVE-2024-26952 [HIGH] CWE-120 CVE-2024-26952: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial out-of-bou In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial out-of-bounds when buffer offset is invalid I found potencial out-of-bounds when buffer offset fields of a few requests is invalid. This patch set the minimum value of buffer offset field to ->Buffer offset to validate buffer length.
nvdosv
CVE-2019-7221P3HIGHCVSS 7.8≤ 4.20.52019-03-21
CVE-2019-7221 [HIGH] CWE-416 CVE-2019-7221: The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.
nvdosv
CVE-2022-1199P3HIGHCVSS 7.5≤ 5.17.14v5.18+1 more2022-08-29
CVE-2022-1199 [HIGH] CWE-416 CVE-2022-1199: A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simu A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability.
nvdosv
CVE-2022-30594P3HIGHCVSS 7.8fixed in 4.19.238≥ 4.20, < 5.4.189+4 more2022-05-12
CVE-2022-30594 [HIGH] CWE-862 CVE-2022-30594: The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows att The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.
nvdosv
CVE-2024-27398P3HIGHCVSS 7.8≥ 4.14.263, < 4.15≥ 4.19.207, < 4.19.314+8 more2024-05-14
CVE-2024-27398 [HIGH] CWE-416 CVE-2024-27398: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free b In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco connection is established and then, the sco socket is releasing, timeout_work will be scheduled to judge whether the sco disconnection is timeout. The sock will be deallocated later, but it is dereferenced aga
nvdosv
CVE-2014-0100P3CRITICALCVSS 9.3≥ 3.9, < 3.10.37≥ 3.11, < 3.12.18+1 more2014-03-11
CVE-2014-0100 [CRITICAL] CWE-362 CVE-2014-0100: Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel thro Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a denial of service (use-after-free error) or possibly have unspecified other impact via a large series of fragmented ICMP Echo Request packets to a system with a heavy CPU load.
nvdosv
CVE-2014-3673P3HIGHCVSS 7.5≥ 2.6.12, < 3.2.64≥ 3.3, < 3.4.107+5 more2014-11-10
CVE-2014-3673 [HIGH] CWE-20 CVE-2014-3673: The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.
nvdosv
CVE-2020-16119P3MEDIUMCVSS 5.5≥ 0, < 5.4.0-51.562020-10-14
CVE-2020-16119 [MEDIUM] linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities Hadar Manor discovered that the DCCP protocol implementation in the Linux kernel improperly
osv
CVE-2024-36904P3HIGHCVSS 7.8≥ 4.16, < 4.19.314≥ 4.20, < 5.4.276+6 more2024-05-30
CVE-2024-36904 [HIGH] CWE-416 CVE-2024-36904: In the Linux kernel, the following vulnerability has been resolved: tcp: Use refcount_inc_not_zero( In the Linux kernel, the following vulnerability has been resolved: tcp: Use refcount_inc_not_zero() in tcp_twsk_unique(). Anderson Nascimento reported a use-after-free splat in tcp_twsk_unique() with nice analysis. Since commit ec94c2696f0b ("tcp/dccp: avoid one atomic operation for timewait hashdance"), inet_twsk_hashdance() sets TIME-WAIT socket'
nvdosv
CVE-2021-3444P3HIGHCVSS 7.8fixed in 5.4.101≥ 5.5.0, < 5.10.19+1 more2021-03-23
CVE-2021-3444 [HIGH] CWE-681 CVE-2021-3444: The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation w The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leading to information disclosure (kernel memory), and possibly out-of-bounds writes that could pote
nvdosv
CVE-2025-21692P3HIGHCVSS 7.8≥ 5.6, < 5.10.234≥ 5.11, < 5.15.178+4 more2025-02-10
CVE-2025-21692 [HIGH] CWE-129 CVE-2025-21692: In the Linux kernel, the following vulnerability has been resolved: net: sched: fix ets qdisc OOB I In the Linux kernel, the following vulnerability has been resolved: net: sched: fix ets qdisc OOB Indexing Haowei Yan found that ets_class_from_arg() can index an Out-Of-Bound class in ets_class_from_arg() when passed clid of 0. The overflow may cause local privilege escalation. [ 18.852298] ------------[ cut here ]------------ [ 18.853271] UBSAN: a
nvdosv
CVE-2019-15239P3HIGHCVSS 7.8v4.16.122019-08-20
CVE-2019-15239 [HIGH] CWE-416 CVE-2019-15239: In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4. In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability that was potentially more severe than the issue that was intended to be fixed by backporting. Specifically, by adding to a write queue between disconnecti
nvdosv
CVE-2023-31436P3HIGHCVSS 7.8≥ 3.7, < 4.14.314≥ 4.15, < 4.19.282+5 more2023-04-28
CVE-2023-31436 [HIGH] CWE-787 CVE-2023-31436: qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds wr qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.
nvdosv
CVE-2022-20421P3HIGHCVSS 7.8≥ 0, < 5.10.149-1≥ 0, < 5.19.11-12022-10-11
CVE-2022-20421 [HIGH] CVE-2022-20421: In binder_inc_ref_for_node of binder In binder_inc_ref_for_node of binder.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239630375References: Upstream kernel
osv
CVE-2017-17806P3HIGHCVSS 7.8fixed in 3.2.97≥ 3.3, < 3.16.52+5 more2017-12-20
CVE-2017-17806 [HIGH] CWE-787 CVE-2017-17806: The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a kernel stack buffer overflow by executi
nvdosv
CVE-2023-35788P3HIGHCVSS 7.8≥ 4.19, < 4.19.285≥ 4.20, < 5.4.246+4 more2023-06-16
CVE-2023-35788 [HIGH] CWE-787 CVE-2023-35788: An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6. An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.
nvdosv
CVE-2020-0423P3HIGHCVSS 7.8≥ 0, < 5.4.0-58.642020-12-13
[HIGH] linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 regression linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 regression USN-4658-1 fixed vulnerabilities in the Linux kernel. Unfortunately, that update introduced a regression in the softwa
osv
CVE-2023-2124P3HIGHCVSS 7.8fixed in 6.4vLinux kernel 6.4-rc12023-05-15
CVE-2023-2124 [HIGH] CWE-787 CVE-2023-2124: An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user re An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system.
nvdosv
Linux Kernel vulnerabilities | cvebase