cbcvebase.

Linux Kernel vulnerabilities

16,357 known vulnerabilities affecting linux/linux_kernel.

Total CVEs
16,357
CISA KEV
31
actively exploited
Public exploits
315
Exploited in wild
67
Severity breakdown
CRITICAL223HIGH4521MEDIUM9642LOW420UNKNOWN1551

Vulnerabilities

Page 7 of 818
CVE-2017-1000371P3HIGHCVSS 7.8PoC≥ 4.1, < 4.1.43≥ 4.2, < 4.4.78+3 more2017-06-19
CVE-2017-1000371 [HIGH] CVE-2017-1000371: The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then the stack will be grown down to 0x80000000, and as the PIE binary is mapped above 0x80000000 the minimum distance between the end of the PIE binary's read-writ
nvdosv
CVE-2017-1000370P3HIGHCVSS 7.8PoC≥ 4.1, < 4.1.43≥ 4.2, < 4.4.78+3 more2017-06-19
CVE-2017-1000370 [HIGH] CVE-2017-1000370: The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary t The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address 0x80000000 and the PIE binary is mapped above 0x40000000 nullifying the protection of the offset2lib patch. This affects Linux Kernel version 4.11.5 and earl
nvdosv
CVE-2018-5390P3HIGHCVSS 7.5≥ 4.9, < 4.18v4.18+1 more2018-08-06
CVE-2018-5390 [HIGH] CWE-400 CVE-2018-5390: Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() an Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
nvdosv
CVE-2017-1000379P3HIGHCVSS 7.8PoC≥ 2.6.12, < 3.2.90≥ 3.3, < 3.10.107+6 more2017-06-19
CVE-2017-1000379 [HIGH] CVE-2017-1000379: The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the hea The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the stack is mapped allowing attackers to more easily manipulate the stack. Linux Kernel version 4.11.5 is affected.
nvdosv
CVE-2019-1999P3HIGHCVSS 7.8PoC≥ 0, < 5.2.6-12019-02-28
CVE-2019-1999 [HIGH] CVE-2019-1999: In binder_alloc_free_page of binder_alloc In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-120025196.
osv
CVE-2009-3613P3HIGHCVSS 7.8PoC≤ 2.6.27.21v2.2.27+283 more2009-10-19
CVE-2009-3613 [HIGH] CWE-399 CVE-2009-3613: The swiotlb functionality in the r8169 driver in drivers/net/r8169.c in the Linux kernel before 2.6. The swiotlb functionality in the r8169 driver in drivers/net/r8169.c in the Linux kernel before 2.6.27.22 allows remote attackers to cause a denial of service (IOMMU space exhaustion and system crash) by using jumbo frames for a large amount of network traffic, as demonstrated by a flood ping.
nvd
CVE-2017-0569P3HIGHCVSS 7.0PoCv3.10v3.182017-04-07
CVE-2017-0569 [HIGH] CWE-131 CVE-2017-0569: An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34198729. References: B-RB#
nvd
CVE-2017-10661P3HIGHCVSS 7.0PoCfixed in 3.2.92≥ 3.3, < 3.16.47+5 more2017-08-19
CVE-2017-10661 [HIGH] CWE-416 CVE-2017-10661: Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privile Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.
nvdosv
CVE-2006-2444P3HIGHCVSS 7.8PoCv2.6.0v2.6.1+72 more2006-05-25
CVE-2006-2444 [HIGH] CVE-2006-2444: The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) via unspecified remote attack vectors that cause failures in snmp_trap_decode that trigger (1) frees of random memory or (2) frees of previously-freed memory (double-free) by snmp_trap_decode as well as its calling
nvd
CVE-2007-4567P3HIGHCVSS 7.8PoC≤ 2.6.21.7v2.2.27+21 more2007-12-21
CVE-2007-4567 [HIGH] CWE-20 CVE-2007-4567: The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properl The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted IPv6 packet.
nvd
CVE-2017-13216P3HIGHCVSS 7.8PoC≥ 0, < 4.14.17-12018-01-12
CVE-2017-13216 [HIGH] CVE-2017-13216: In ashmem_ioctl of ashmem In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when accessing asma. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-66954097.
osv
CVE-2016-10229P2CRITICALCVSS 9.8≥ 3.2, < 3.2.76≥ 3.3, < 3.4.113+7 more2017-04-04
CVE-2016-10229 [CRITICAL] CWE-358 CVE-2016-10229: udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traff udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
nvdosv
CVE-2026-23231P3HIGHCVSS 7.8PoC≥ 3.16, < 6.1.165≥ 6.2, < 6.6.128+3 more2026-03-04
CVE-2026-23231 [HIGH] CWE-416 CVE-2026-23231: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-a In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table->chains via list_add_tail_rcu() (in nft_chain_add()) before registering hooks. If nf_tables_register_hook() then fails, the error path calls nft_chain_del() (list_del_rc
nvdosv
CVE-2023-5178P2HIGHCVSS 8.8≥ 5.0, < 5.4.260≥ 5.5, < 5.10.199+3 more2023-11-01
CVE-2023-5178 [HIGH] CWE-416 CVE-2023-5178: A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` du A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.
nvdosv
CVE-2019-2025P3HIGHCVSS 7.8PoC≥ 0, < 4.19.9-12019-06-19
CVE-2019-2025 [HIGH] CVE-2019-2025: In binder_thread_read of binder In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-116855682References: Upstream kernel
osv
CVE-2010-0437P3HIGHCVSS 7.8PoC≤ 2.6.26.8v2.6.0+256 more2010-03-24
CVE-2010-0437 [HIGH] CVE-2010-0437: The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2016-7117P2CRITICALCVSS 9.8≥ 2.6.33, < 3.2.80≥ 3.3, < 3.4.113+8 more2016-10-10
CVE-2016-7117 [CRITICAL] CWE-19 CVE-2016-7117: Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel befo Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.
nvdosv
CVE-2019-9162P3HIGHCVSS 7.8PoC≥ 4.19, < 4.19.25≥ 4.20, < 4.20.122019-02-25
CVE-2019-9162 [HIGH] CWE-787 CVE-2019-9162: In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT modu In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local privilege escalation. This affects snmp_version and snmp_helper.
nvdosv
CVE-2019-19241P3HIGHCVSS 7.8PoCfixed in 5.4.22019-12-17
CVE-2019-19241 [HIGH] CVE-2019-19241: In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabilities, aka CID-181e448d8709. This is related to fs/io-wq.c, fs/io_uring.c, and net/socket.c. For example, an attacker can bypass intended restrictions on adding an IPv4 address to the loopback interface. This occurs because IORING_OP_SENDMSG
nvdosv
CVE-2016-1576P3HIGHCVSS 7.8PoC≤ 4.5.22016-05-02
CVE-2016-1576 [HIGH] CVE-2016-1576: The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.
nvdosv