Linux Kernel vulnerabilities
16,409 known vulnerabilities affecting linux/linux_kernel.
Total CVEs
16,409
CISA KEV
31
actively exploited
Public exploits
315
Exploited in wild
67
Severity breakdown
CRITICAL230HIGH4553MEDIUM9655LOW420UNKNOWN1551
Vulnerabilities
Page 58 of 821
CVE-2016-6776P3HIGHCVSS 7.8v3.102017-01-12
CVE-2016-6776 [HIGH] CWE-284 CVE-2016-6776: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-6775P3HIGHCVSS 7.8v3.102017-01-12
CVE-2016-6775 [HIGH] CWE-284 CVE-2016-6775: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2017-0307P3HIGHCVSS 7.8v3.182017-03-08
CVE-2017-0307 [HIGH] CWE-190 CVE-2017-0307: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2017-0306P3HIGHCVSS 7.8v3.102017-03-08
CVE-2017-0306 [HIGH] CWE-120 CVE-2017-0306: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2024-35948P3HIGHCVSS 8.4≥ 6.7, < 6.9v6.92024-05-20
CVE-2024-35948 [HIGH] CWE-400 CVE-2024-35948: In the Linux kernel, the following vulnerability has been resolved: bcachefs: Check for journal ent
In the Linux kernel, the following vulnerability has been resolved:
bcachefs: Check for journal entries overruning end of sb clean section
Fix a missing bounds check in superblock validation.
Note that we don't yet have repair code for this case - repair code for
individual items is generally low priority, since the whole superblock
is checksummed,
nvdosv
CVE-2017-0338P3HIGHCVSS 7.8v3.182017-03-08
CVE-2017-0338 [HIGH] CVE-2017-0338: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions:
nvd
CVE-2016-8430P3HIGHCVSS 7.8v3.102017-01-12
CVE-2016-8430 [HIGH] CWE-264 CVE-2016-8430: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2017-0333P3HIGHCVSS 7.8v3.182017-03-08
CVE-2017-0333 [HIGH] CVE-2017-0333: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions:
nvd
CVE-2017-0337P3HIGHCVSS 7.8v3.182017-03-08
CVE-2017-0337 [HIGH] CVE-2017-0337: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions:
nvd
CVE-2017-0335P3HIGHCVSS 7.8v3.182017-03-08
CVE-2017-0335 [HIGH] CVE-2017-0335: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions:
nvd
CVE-2024-38616P3HIGHCVSS 8.2≥ 5.17, < 6.1.93≥ 6.2, < 6.6.33+2 more2024-06-19
CVE-2024-38616 [HIGH] CWE-400 CVE-2024-38616: In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: re-fix fortifie
In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: re-fix fortified-memset warning
The carl9170_tx_release() function sometimes triggers a fortified-memset
warning in my randconfig builds:
In file included from include/linux/string.h:254,
from drivers/net/wireless/ath/carl9170/tx.c:40:
In function 'fortify_memset_chk
nvdosv
CVE-2026-46251P3HIGHCVSS 8.4≥ 6.0.19, < 6.1.165≥ 6.2, < 6.6.128+3 more2026-06-03
CVE-2026-46251 [HIGH] CVE-2026-46251: In the Linux kernel, the following vulnerability has been resolved: btrfs: fix block_group_tree dir
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix block_group_tree dirty_list corruption
When the incompat flag EXTENT_TREE_V2 is set, we unconditionally add the
block group tree to the switch_commits list before calling
switch_commit_roots, as we do for the tree root and the chunk root.
However, the block group tree uses normal
nvd
CVE-2026-53091P3HIGHCVSS 8.4≥ 3.16, < 7.0.102026-06-24
CVE-2026-53091 [HIGH] CWE-131 CVE-2026-53091: In the Linux kernel, the following vulnerability has been resolved: net: pull headers in qdisc_pkt_
In the Linux kernel, the following vulnerability has been resolved:
net: pull headers in qdisc_pkt_len_segs_init()
Most ndo_start_xmit() methods expects headers of gso packets
to be already in skb->head.
net/core/tso.c users are particularly at risk, because tso_build_hdr()
does a memcpy(hdr, skb->data, hdr_len);
qdisc_pkt_len_segs_init() already d
nvd
CVE-2011-1021P4LOWCVSS 3.6PoC≤ 2.6.9v2.6.92012-06-21
CVE-2011-1021 [LOW] CVE-2011-1021: drivers/acpi/debugfs.c in the Linux kernel before 3.0 allows local users to modify arbitrary kernel
drivers/acpi/debugfs.c in the Linux kernel before 3.0 allows local users to modify arbitrary kernel memory locations by leveraging root privileges to write to the /sys/kernel/debug/acpi/custom_method file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4347.
nvdosv
CVE-2024-36886P3HIGHCVSS 7.8≥ 4.1, < 4.19.314≥ 4.20, < 5.4.276+6 more2024-05-30
CVE-2024-36886 [HIGH] CWE-416 CVE-2024-36886: In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in error path Sa
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix UAF in error path
Sam Page (sam4k) working with Trend Micro Zero Day Initiative reported
a UAF in the tipc_buf_append() error path:
BUG: KASAN: slab-use-after-free in kfree_skb_list_reason+0x47e/0x4c0
linux/net/core/skbuff.c:1183
Read of size 8 at addr ffff88804d2a7c80 by t
nvdosv
CVE-2026-46010P3HIGHCVSS 8.1≥ 6.16.9, < 6.17≥ 6.17.1, < 6.18.27+3 more2026-05-27
CVE-2026-46010 [HIGH] CVE-2026-46010: In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix error handling in rx
In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix error handling in rxgk_extract_token()
Fix a missing bit of error handling in rxgk_extract_token(): in the event
that rxgk_decrypt_skb() returns -ENOMEM, it should just return that rather
than continuing on (for anything else, it generates an abort).
nvd
CVE-2020-29661P3HIGHCVSS 7.8≥ 2.6.26, < 4.4.248≥ 4.5, < 4.9.248+4 more2020-12-09
CVE-2020-29661 [HIGH] CWE-416 CVE-2020-29661: A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/
A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.
nvdosv
CVE-2026-46138P3HIGHCVSS 8.1≥ 6.4.16, < 6.5≥ 6.5.3, < 6.6.140+5 more2026-05-28
CVE-2026-46138 [HIGH] CWE-125 CVE-2026-46138: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix OOB r
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt
hci_le_create_big_complete_evt() iterates over BT_BOUND connections for
a BIG handle using a while loop, accessing ev->bis_handle[i++] on each
iteration. However, there is no check that i stays wit
nvd
CVE-2026-31779P3HIGHCVSS 8.1≥ 6.1, < 6.1.168≥ 6.2, < 6.6.134+4 more2026-05-01
CVE-2026-31779 [HIGH] CWE-125 CVE-2026-31779: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix potenti
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler()
The memcpy function assumes the dynamic array notif->matches is at least
as large as the number of bytes to copy. Otherwise, results->matches may
contain unwanted data. To guarantee safety, extend
nvd
CVE-2026-46232P3HIGHCVSS 8.1≥ 6.2, < 6.6.140≥ 6.7, < 6.12.90+5 more2026-05-28
CVE-2026-46232 [HIGH] CVE-2026-46232: In the Linux kernel, the following vulnerability has been resolved: HID: playstation: Clamp num_tou
In the Linux kernel, the following vulnerability has been resolved:
HID: playstation: Clamp num_touch_reports
A device would never lie about the number of touch reports would it?
If it does the loop in dualshock4_parse_report will read off the end of
the touch_reports array, up to about 2 KiB for the maximum number of 256
loop iteraions. The data that is re
nvd