cbcvebase.

Linux Kernel vulnerabilities

16,409 known vulnerabilities affecting linux/linux_kernel.

Total CVEs
16,409
CISA KEV
31
actively exploited
Public exploits
315
Exploited in wild
67
Severity breakdown
CRITICAL230HIGH4553MEDIUM9655LOW420UNKNOWN1551

Vulnerabilities

Page 78 of 821
CVE-2019-19447P3HIGHCVSS 7.8≥ 2.6.12, < 3.16.82≥ 3.17, < 4.4.208+5 more2019-12-08
CVE-2019-19447 [HIGH] CWE-416 CVE-2019-19447: In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, an In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c.
nvdosv
CVE-2019-19377P3HIGHCVSS 7.8≥ 2.6.12, < 4.19.156≥ 4.20, < 5.4.33+2 more2019-11-29
CVE-2019-19377 [HIGH] CWE-416 CVE-2019-19377: In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, a In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can lead to a use-after-free in btrfs_queue_work in fs/btrfs/async-thread.c.
nvdosv
CVE-2019-19814P3HIGHCVSS 7.8v5.0.212019-12-17
CVE-2019-19814 [HIGH] CWE-787 CVE-2019-19814: In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segmen In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.
nvd
CVE-2018-20784P3CRITICALCVSS 9.8≥ 4.13, < 4.14.93≥ 4.19, < 4.19.15+2 more2019-02-22
CVE-2018-20784 [CRITICAL] CWE-835 CVE-2018-20784: In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attack In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in update_blocked_averages) or possibly have unspecified other impact by inducing a high load.
nvdosv
CVE-2019-15099P3HIGHCVSS 7.5≥ 4.14, < 4.14.157≥ 4.15, < 4.19.87+2 more2019-08-16
CVE-2019-15099 [HIGH] CWE-476 CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereferen drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
nvdosv
CVE-2021-38201P3HIGHCVSS 7.5≥ 5.11.0, < 5.12.19≥ 5.13.0, < 5.13.42021-08-08
CVE-2021-38201 [HIGH] CWE-119 CVE-2021-38201: net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of serv net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations.
nvd
CVE-2026-53277P3HIGHCVSS 8.8≥ 6.12, < 6.18.36≥ 6.19, < 7.0.13+6 more2026-06-25
CVE-2026-53277 [HIGH] CWE-662 CVE-2026-53277: In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Take the SRCU lock In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation walk_s1() and kvm_walk_nested_s2() expect to be called while holding kvm->srcu to guard against memslot changes. While this is generally the case, __kvm_at_s12() and __kvm_find_s1_desc_level() call
nvd
CVE-2016-5343P3CRITICALCVSS 9.8≥ 3.0, ≤ 3.19.82016-10-10
CVE-2016-5343 [CRITICAL] CWE-120 CVE-2016-5343: drivers/soc/qcom/qdsp6v2/voice_svc.c in the QDSP6v2 Voice Service driver for the Linux kernel 3.x, a drivers/soc/qcom/qdsp6v2/voice_svc.c in the QDSP6v2 Voice Service driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a write request, as demonstrated by a
nvd
CVE-2016-7912P3HIGHCVSS 7.8≥ 3.15, < 3.16.40≥ 3.17, < 4.1.24+2 more2016-11-16
CVE-2016-7912 [HIGH] CWE-416 CVE-2016-7912: Use-after-free vulnerability in the ffs_user_copy_worker function in drivers/usb/gadget/function/f_f Use-after-free vulnerability in the ffs_user_copy_worker function in drivers/usb/gadget/function/f_fs.c in the Linux kernel before 4.5.3 allows local users to gain privileges by accessing an I/O data structure after a certain callback call.
nvdosv
CVE-2013-1959P4LOWCVSS 3.7PoC≤ 3.8.8v3.0+190 more2013-05-03
CVE-2013-1959 [LOW] CWE-264 CVE-2013-1959: kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requir kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_map and gid_map files, which allows local users to gain privileges by opening a file within an unprivileged process and then modifying the file within a privileged process.
nvdosv
CVE-2024-35869P3HIGHCVSS 8.4≥ 6.2.8, < 6.3≥ 6.4, < 6.6.29+2 more2024-05-19
CVE-2024-35869 [HIGH] CWE-416 CVE-2024-35869: In the Linux kernel, the following vulnerability has been resolved: smb: client: guarantee refcount In the Linux kernel, the following vulnerability has been resolved: smb: client: guarantee refcounted children from parent session Avoid potential use-after-free bugs when walking DFS referrals, mounting and performing DFS failover by ensuring that all children from parent @tcon->ses are also refcounted. They're all needed across the entire DFS mount
nvdosv
CVE-2024-38384P3HIGHCVSS 8.4≥ 6.2, < 6.6.33≥ 6.7, < 6.9.42024-06-24
CVE-2024-38384 [HIGH] CWE-400 CVE-2024-38384: In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix list corruption In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix list corruption from reorder of WRITE ->lqueued __blkcg_rstat_flush() can be run anytime, especially when blk_cgroup_bio_start is being executed. If WRITE of `->lqueued` is re-ordered with READ of 'bisc->lnode.next' in the loop of __blkcg_rstat_flush(), `next_bisc` c
nvdosv
CVE-2023-52629P3HIGHCVSS 8.4≥ 2.6.20, < 6.5.42024-03-29
CVE-2023-52629 [HIGH] CWE-416 CVE-2023-52629: In the Linux kernel, the following vulnerability has been resolved: sh: push-switch: Reorder cleanu In the Linux kernel, the following vulnerability has been resolved: sh: push-switch: Reorder cleanup operations to avoid use-after-free bug The original code puts flush_work() before timer_shutdown_sync() in switch_drv_remove(). Although we use flush_work() to stop the worker, it could be rescheduled in switch_timer(). As a result, a use-after-free b
nvdosv
CVE-2026-63797P3HIGHCVSS 8.4≥ 5.18, < 6.1.178≥ 6.2, < 6.6.144+3 more2026-07-19
CVE-2026-63797 [HIGH] CWE-416 CVE-2026-63797: In the Linux kernel, the following vulnerability has been resolved: rpmsg: char: Fix use-after-free In the Linux kernel, the following vulnerability has been resolved: rpmsg: char: Fix use-after-free on probe error path rpmsg_chrdev_probe() stores the newly allocated eptdev in the default endpoint's priv pointer before calling rpmsg_chrdev_eptdev_add(). If rpmsg_chrdev_eptdev_add() then fails, its error path frees eptdev while the default endpoint
nvd
CVE-2016-8424P3HIGHCVSS 7.8v3.102017-01-12
CVE-2016-8424 [HIGH] CWE-264 CVE-2016-8424: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8428P3HIGHCVSS 7.8v3.102017-01-12
CVE-2016-8428 [HIGH] CWE-264 CVE-2016-8428: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8426P3HIGHCVSS 7.8v3.102017-01-12
CVE-2016-8426 [HIGH] CWE-264 CVE-2016-8426: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8427P3HIGHCVSS 7.8v3.102017-01-12
CVE-2016-8427 [HIGH] CWE-264 CVE-2016-8427: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8425P3HIGHCVSS 7.8v3.102017-01-12
CVE-2016-8425 [HIGH] CWE-264 CVE-2016-8425: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8429P3HIGHCVSS 7.8v3.102017-01-12
CVE-2016-8429 [HIGH] CWE-264 CVE-2016-8429: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
Linux Kernel vulnerabilities | cvebase