Linux Kernel vulnerabilities
16,357 known vulnerabilities affecting linux/linux_kernel.
Total CVEs
16,357
CISA KEV
31
actively exploited
Public exploits
315
Exploited in wild
67
Severity breakdown
CRITICAL223HIGH4521MEDIUM9642LOW420UNKNOWN1551
Vulnerabilities
Page 6 of 818
CVE-2022-0995P3HIGHCVSS 7.8PoC≥ 5.8, < 5.10.106≥ 5.11, < 5.15.29+3 more2022-03-25
CVE-2022-0995 [HIGH] CWE-787 CVE-2022-0995: An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notificat
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
nvdosv
CVE-2023-0210P2HIGHCVSS 7.5≥ 5.15, < 5.15.87≥ 5.16, < 6.0.19+2 more2023-03-27
CVE-2023-0210 [HIGH] CWE-122 CVE-2023-0210: A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediatel
A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based systems.
nvdosv
CVE-2017-6074P3HIGHCVSS 7.8PoCfixed in 3.2.86≥ 3.3, < 3.10.106+6 more2017-02-18
CVE-2017-6074 [HIGH] CWE-415 CVE-2017-6074: The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandle
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
nvdosv
CVE-2017-15649P3HIGHCVSS 7.8PoC≤ 4.13.52017-10-19
CVE-2017-15649 [HIGH] CWE-362 CVE-2017-15649: net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via c
net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet_do_bind) that leads to a use-after-free, a different vulnerability than CVE-2017-6346.
nvdosv
CVE-2016-6187P3HIGHCVSS 7.8PoC≥ 4.5, < 4.6.52016-08-06
CVE-2016-6187 [HIGH] CWE-119 CVE-2016-6187: The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does n
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which allows local users to gain privileges by triggering an AppArmor setprocattr hook.
nvdosv
CVE-2015-0569P3HIGHCVSS 7.8PoC≥ 3.0.0, ≤ 3.19.8≥ 4.0.0, ≤ 4.20.152016-05-09
CVE-2015-0569 [HIGH] CWE-787 CVE-2015-0569: Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.
Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via a crafted application that establishes a pack
nvd
CVE-2022-47939P2CRITICALCVSS 9.8≥ 5.15, < 5.15.61≥ 5.16, < 5.18.18+1 more2022-12-23
CVE-2022-47939 [CRITICAL] CWE-416 CVE-2022-47939: An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2p
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_DISCONNECT.
nvdosv
CVE-2019-15793P3HIGHCVSS 8.8PoCv5.0v5.32020-04-24
CVE-2019-15793 [HIGH] CWE-538 CVE-2019-15793: In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel serie
In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing operations in the lower filesystem were translating them into init_user_ns, whereas they should have been translated into the s_user_ns for the lower filesystem. This result
nvd
CVE-2022-22942P3HIGHCVSS 7.8PoC≥ 0, < 5.10.92-2≥ 0, < 5.15.15-22023-12-13
CVE-2022-22942 [HIGH] CVE-2022-22942: The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes
The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer.
osv
CVE-2014-9322P3HIGHCVSS 7.8PoCfixed in 3.2.65≥ 3.3, < 3.4.106+5 more2014-12-17
CVE-2014-9322 [HIGH] CWE-269 CVE-2014-9322: arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associa
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.
nvdosv
CVE-2017-8824P3HIGHCVSS 7.8PoC≥ 2.6.14, < 3.2.97≥ 3.3, < 3.16.52+5 more2017-12-05
CVE-2017-8824 [HIGH] CWE-416 CVE-2017-8824: The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local use
The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.
nvdosv
CVE-2018-11412P3MEDIUMCVSS 5.9PoC≥ 4.13, ≤ 4.16.112018-05-24
CVE-2018-11412 [MEDIUM] CWE-416 CVE-2018-11412: In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a mem
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a dedicated inode.
nvdosv
CVE-2019-14901P2CRITICALCVSS 9.8≥ 3.15, < 3.16.83≥ 3.17, < 4.4.217+4 more2019-11-29
CVE-2019-14901 [CRITICAL] CWE-122 CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in M
A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with this vulnerability is with the availability of the system. If code exec
nvdosv
CVE-2017-18017P3CRITICALCVSS 9.8≥ 3.2, < 3.2.99≥ 3.3, < 3.10.108+6 more2018-01-03
CVE-2017-18017 [CRITICAL] CWE-416 CVE-2017-18017: The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.
nvdosv
CVE-2017-16939P3HIGHCVSS 7.8PoC≥ 2.6.28, < 3.2.97≥ 3.3, < 3.16.52+5 more2017-11-24
CVE-2017-16939 [HIGH] CWE-416 CVE-2017-16939: The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allow
The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in conjunction with XFRM_MSG_GETPOLICY Netlink messages.
nvdosv
CVE-2016-1583P3HIGHCVSS 7.8PoC≥ 2.6.19, < 3.18.54≥ 3.19, < 4.4.14+1 more2016-06-27
CVE-2016-1583 [HIGH] CWE-119 CVE-2016-1583: The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allo
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.
nvdosv
CVE-2012-0055P3HIGHCVSS 7.8PoCfixed in 3.0.02020-02-19
CVE-2012-0055 [HIGH] CWE-862 CVE-2012-0055: OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing
OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.
nvd
CVE-2018-18955P3HIGHCVSS 7.0PoC≥ 4.15, < 4.19.22018-11-16
CVE-2018-18955 [HIGH] CWE-863 CVE-2018-18955: In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allo
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading
nvdosv
CVE-2017-1000364P3HIGHCVSS 7.4PoC≤ 4.11.52017-06-19
CVE-2017-1000364 [HIGH] CWE-119 CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard
An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010).
nvdosv
CVE-2016-3134P3HIGHCVSS 8.4PoC≤ 4.5.22016-04-27
CVE-2016-3134 [HIGH] CWE-119 CVE-2016-3134: The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, w
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
nvdosv