cbcvebase.

Linux Kernel vulnerabilities

16,357 known vulnerabilities affecting linux/linux_kernel.

Total CVEs
16,357
CISA KEV
31
actively exploited
Public exploits
315
Exploited in wild
67
Severity breakdown
CRITICAL223HIGH4521MEDIUM9642LOW420UNKNOWN1551

Vulnerabilities

Page 8 of 818
CVE-2016-2854P3HIGHCVSS 7.8PoC≥ 3.0.0, ≤ 3.19.8≥ 4.0.0, ≤ 4.20.152016-05-02
CVE-2016-2854 [HIGH] CWE-269 CVE-2016-2854: The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, wh The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.
nvdosv
CVE-2016-1575P3HIGHCVSS 7.8PoC≤ 4.5.22016-05-02
CVE-2016-1575 [HIGH] CWE-269 CVE-2016-1575: The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.
nvdosv
CVE-2016-2853P3HIGHCVSS 7.8PoC≥ 3.0.0, ≤ 3.19.8≥ 4.0.0, ≤ 4.20.152016-05-02
CVE-2016-2853 [HIGH] CWE-269 CVE-2016-2853: The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, whi The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.
nvdosv
CVE-2025-37928P3HIGHCVSS 7.8PoC≥ 4.9, < 6.1.138≥ 6.2, < 6.6.90+3 more2025-05-20
CVE-2025-37928 [HIGH] CVE-2025-37928: In the Linux kernel, the following vulnerability has been resolved: dm-bufio: don't schedule in ato In the Linux kernel, the following vulnerability has been resolved: dm-bufio: don't schedule in atomic context A BUG was reported as below when CONFIG_DEBUG_ATOMIC_SLEEP and try_verify_in_tasklet are enabled. [ 129.444685][ T934] BUG: sleeping function called from invalid context at drivers/md/dm-bufio.c:2421 [ 129.444723][ T934] in_atomic(): 1, irqs_disable
nvdosv
CVE-2009-3726P3HIGHCVSS 7.8PoC≤ 2.6.31v2.2.27+340 more2009-11-09
CVE-2009-3726 [HIGH] CWE-399 CVE-2009-3726: The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6. The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state.
nvd
CVE-2018-13405P3HIGHCVSS 7.8PoC≤ 3.162018-07-06
CVE-2018-13405 [HIGH] CWE-269 CVE-2018-13405: The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to c The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is th
nvdosv
CVE-2026-46333P3HIGHCVSS 7.1PoC≥ 3.16.52, < 3.17≥ 4.4.40, < 4.5+11 more2026-05-15
CVE-2026-46333 [HIGH] CWE-269 CVE-2026-46333: In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dum In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when you don't have an associated mm. And almost all users do in fact use it on
nvd
CVE-2017-11176P3HIGHCVSS 7.8PoCfixed in 3.2.92≥ 3.3, < 3.16.47+6 more2017-07-11
CVE-2017-11176 [HIGH] CWE-416 CVE-2017-11176: The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact.
nvdosv
CVE-1999-0128P4MEDIUMCVSS 5.0PoCv1.3.0v2.01996-12-18
CVE-1999-0128 [MEDIUM] CVE-1999-0128: Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
nvd
CVE-2017-5754P3MEDIUMCVSS 5.6≥ 0, < 4.4.0-109.1322018-01-10
CVE-2017-5754 [MEDIUM] linux regression linux regression USN-3522-1 fixed a vulnerability in the Linux kernel to address Meltdown (CVE-2017-5754). Unfortunately, that update introduced a regression where a few systems failed to boot successfully. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Jann Horn discovered that microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized memory reads via sidechanne
osv
CVE-2019-15791P3HIGHCVSS 7.8PoCv5.0v5.32020-04-24
CVE-2019-15791 [HIGH] CWE-672 CVE-2019-15791: In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel serie In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() installs an fd referencing a file from the lower filesystem without taking an additional reference to that file. After the btrfs ioctl completes this fd is closed, which then puts a reference to that file, leading to
nvd
CVE-2016-3672P3HIGHCVSS 7.8PoC≤ 4.5.22016-04-27
CVE-2016-3672 [HIGH] CWE-254 CVE-2016-3672: The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and bypass the ASLR protection mechanism for a setuid or setgid program, by disabling stack-consumption res
nvdosv
CVE-2019-15792P3HIGHCVSS 7.8PoCv5.0v5.32020-04-24
CVE-2019-15792 [HIGH] CWE-843 CVE-2019-15792: In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel serie In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() calls fdget(oldfd), then without further checks passes the resulting file* into shiftfs_real_fdget(), which casts file->private_data, a void* that points to a filesystem-dependent type, to a "struct shiftfs_file_info
nvd
CVE-2016-3135P3HIGHCVSS 7.8PoC≥ 4.2, < 4.4.21≥ 4.5, < 4.62016-04-27
CVE-2016-3135 [HIGH] CWE-189 CVE-2016-3135: Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
nvdosv
CVE-2024-8805P2HIGHCVSS 8.8≥ 0, < 6.1.115-1≥ 0, < 6.11.4-12024-11-22
CVE-2024-8805 [HIGH] CVE-2024-8805: BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the HID over GATT Profile. The issue results from the la
osv
CVE-2001-0405P3HIGHCVSS 7.5PoCv2.4.0v2.4.1+2 more2001-07-02
CVE-2001-0405 [HIGH] CVE-2001-0405: ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access res ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.
nvd
CVE-2016-9793P3HIGHCVSS 7.8PoC≥ 3.5, < 3.12.69≥ 3.13, < 3.16.40+4 more2016-12-28
CVE-2016-9793 [HIGH] CWE-119 CVE-2016-9793: The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negativ The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability for a crafted setsockopt system call with
nvdosv
CVE-2007-1357P3HIGHCVSS 7.8PoC≤ 2.6.20.42007-04-11
CVE-2007-1357 [HIGH] CVE-2007-1357: The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, al The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, allows remote attackers to cause a denial of service (crash) via an AppleTalk frame that is shorter than the specified length, which triggers a BUG_ON call when an attempt is made to perform a checksum.
nvd
CVE-2024-26594P3HIGHCVSS 7.1fixed in 5.15.149≥ 5.16.0, < 6.1.75+2 more2024-02-23
CVE-2024-26594 [HIGH] CWE-125 CVE-2024-26594: In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in s In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session setup request, ksmbd validate and make the error if it is invalid.
nvdosv
CVE-2023-52755P3HIGHCVSS 8.4≥ 5.15, < 5.15.140≥ 5.16, < 6.1.64+2 more2024-05-21
CVE-2023-52755 [HIGH] CWE-787 CVE-2023-52755: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab out of bounds w In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab out of bounds write in smb_inherit_dacl() slab out-of-bounds write is caused by that offsets is bigger than pntsd allocation size. This patch add the check to validate 3 offsets using allocation size.
nvdosv
Linux Kernel vulnerabilities | cvebase