cbcvebase.

Linux Kernel vulnerabilities

16,409 known vulnerabilities affecting linux/linux_kernel.

Total CVEs
16,409
CISA KEV
31
actively exploited
Public exploits
315
Exploited in wild
67
Severity breakdown
CRITICAL230HIGH4553MEDIUM9655LOW420UNKNOWN1551

Vulnerabilities

Page 81 of 821
CVE-2021-47103P3HIGHCVSS 7.8≥ 3.6, < 4.9.331≥ 4.10, < 4.14.296+5 more2024-03-04
CVE-2021-47103 [HIGH] CWE-416 CVE-2021-47103: In the Linux kernel, the following vulnerability has been resolved: inet: fully convert sk->sk_rx_d In the Linux kernel, the following vulnerability has been resolved: inet: fully convert sk->sk_rx_dst to RCU rules syzbot reported various issues around early demux, one being included in this changelog [1] sk->sk_rx_dst is using RCU protection without clearly documenting it. And following sequences in tcp_v4_do_rcv()/tcp_v6_do_rcv() are not follow
nvdosv
CVE-2023-3111P3HIGHCVSS 7.8≥ 2.6.31, < 4.14.318≥ 4.15, < 4.19.286+5 more2023-06-05
CVE-2023-3111 [HIGH] CWE-416 CVE-2023-3111: A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag().
nvdosv
CVE-2021-20226P3HIGHCVSS 7.8≥ 5.5, < 5.8.18≥ 5.9.0, < 5.9.3+1 more2021-02-23
CVE-2021-20226 [HIGH] CWE-416 CVE-2021-20226: A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial of service problem on the system The issue results from the lack of validating the existence of an object prior to performing operations on the object by not incrementing the file reference counter while in use. The highest
nvdosv
CVE-2017-15868P3HIGHCVSS 7.8≥ 3.2, < 3.2.97≥ 3.3, < 3.10.108+2 more2017-12-05
CVE-2017-15868 [HIGH] CWE-20 CVE-2017-15868: The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does n The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.
nvdosv
CVE-2015-8539P3HIGHCVSS 7.8fixed in 4.4v4.42016-02-08
CVE-2015-8539 [HIGH] CWE-269 CVE-2015-8539: The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a d The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted.c, and security/keys/user_defined.c.
nvdosv
CVE-2019-19252P3HIGHCVSS 7.8≤ 5.3.132019-11-25
CVE-2019-19252 [HIGH] CWE-125 CVE-2019-19252: vcs_write in drivers/tty/vt/vc_screen.c in the Linux kernel through 5.3.13 does not prevent write ac vcs_write in drivers/tty/vt/vc_screen.c in the Linux kernel through 5.3.13 does not prevent write access to vcsu devices, aka CID-0c9acb1af77a.
nvdosv
CVE-2022-3545P3HIGHCVSS 7.8≥ 4.11, < 4.14.303≥ 4.15, < 4.19.270+3 more2022-10-17
CVE-2022-3545 [HIGH] CWE-119 CVE-2022-3545: A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerab A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function area_cache_get of the file drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211045 was
nvdosv
CVE-2019-15927P3HIGHCVSS 7.8fixed in 3.16.66≥ 3.17, < 3.18.132+5 more2019-09-04
CVE-2019-15927 [HIGH] CWE-125 CVE-2019-15927: An issue was discovered in the Linux kernel before 4.20.2. An out-of-bounds access exists in the fun An issue was discovered in the Linux kernel before 4.20.2. An out-of-bounds access exists in the function build_audio_procunit in the file sound/usb/mixer.c.
nvdosv
CVE-2017-11473P3HIGHCVSS 7.8fixed in 3.2.95≥ 3.3, < 3.16.50+5 more2017-07-20
CVE-2017-11473 [HIGH] CWE-120 CVE-2017-11473: Buffer overflow in the mp_override_legacy_irq() function in arch/x86/kernel/acpi/boot.c in the Linux Buffer overflow in the mp_override_legacy_irq() function in arch/x86/kernel/acpi/boot.c in the Linux kernel through 3.2 allows local users to gain privileges via a crafted ACPI table.
nvdosv
CVE-2025-38146P3HIGHCVSS 7.8≥ 5.5, < 5.10.239≥ 5.11, < 5.15.186+4 more2025-07-03
CVE-2025-38146 [HIGH] CWE-129 CVE-2025-38146: In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Fix the dead In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Fix the dead loop of MPLS parse The unexpected MPLS packet may not end with the bottom label stack. When there are many stacks, The label count value has wrapped around. A dead loop occurs, soft lockup/CPU stuck finally. stack backtrace: UBSAN: array-index-out-of-bo
nvdosv
CVE-2024-53141P3HIGHCVSS 7.8≥ 2.6.39, < 4.19.325≥ 4.20, < 6.6.64+2 more2024-12-06
CVE-2024-53141 [HIGH] CVE-2024-53141: In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing r In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap_ip_uadt When tb[IPSET_ATTR_IP_TO] is not present but tb[IPSET_ATTR_CIDR] exists, the values of ip and ip_to are slightly swapped. Therefore, the range check for ip should be done later, but this part is missing and it seems that the vulnera
nvdosv
CVE-2021-38160P3HIGHCVSS 7.8≥ 2.6.24, < 4.4.276≥ 4.5, < 4.9.276+6 more2021-08-07
CVE-2021-38160 [HIGH] CWE-120 CVE-2021-38160: In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be t In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in
nvdosv
CVE-2023-26606P3HIGHCVSS 7.8≥ 5.15, < 5.15.86≥ 5.16, < 6.0.16+1 more2023-02-26
CVE-2023-26606 [HIGH] CWE-416 CVE-2023-26606: In the Linux kernel 6.0.8, there is a use-after-free in ntfs_trim_fs in fs/ntfs3/bitmap.c. In the Linux kernel 6.0.8, there is a use-after-free in ntfs_trim_fs in fs/ntfs3/bitmap.c.
nvdosv
CVE-2025-38471P3HIGHCVSS 7.8≥ 6.0.6, < 6.1≥ 6.1.1, < 6.1.147+17 more2025-07-28
CVE-2025-38471 [HIGH] CWE-416 CVE-2025-38471: In the Linux kernel, the following vulnerability has been resolved: tls: always refresh the queue w In the Linux kernel, the following vulnerability has been resolved: tls: always refresh the queue when reading sock After recent changes in net-next TCP compacts skbs much more aggressively. This unearthed a bug in TLS where we may try to operate on an old skb when checking if all skbs in the queue have matching decrypt state and geometry. BUG: KASA
nvdosv
CVE-2015-2686P3HIGHCVSS 7.8v3.19v3.19.1+1 more2016-05-02
CVE-2015-2686 [HIGH] CWE-264 CVE-2015-2686: net/socket.c in the Linux kernel 3.19 before 3.19.3 does not validate certain range data for (1) sen net/socket.c in the Linux kernel 3.19 before 3.19.3 does not validate certain range data for (1) sendto and (2) recvfrom system calls, which allows local users to gain privileges by leveraging a subsystem that uses the copy_from_iter function in the iov_iter interface, as demonstrated by the Bluetooth subsystem.
nvd
CVE-2023-52441P3HIGHCVSS 7.8≥ 5.15.0, < 5.15.145≥ 5.16.0, < 6.1.53+1 more2024-02-21
CVE-2023-52441 [HIGH] CWE-119 CVE-2023-52441: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds in ini In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds in init_smb2_rsp_hdr() If client send smb2 negotiate request and then send smb1 negotiate request, init_smb2_rsp_hdr is called for smb1 negotiate request since need_neg is set to false. This patch ignore smb1 packets after ->need_neg is set to false.
nvdosv
CVE-2021-28952P3HIGHCVSS 7.8≤ 5.11.82021-03-20
CVE-2021-28952 [HIGH] CWE-120 CVE-2021-28952: An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire de An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered, aka CID-1c668e1c0a0f. (This has been fixed in 5.12-rc4.)
nvdosv
CVE-2023-26605P3HIGHCVSS 7.8≥ 5.15.75, < 5.15.81≥ 5.19.17, < 6.0.0+1 more2023-02-26
CVE-2023-26605 [HIGH] CWE-416 CVE-2023-26605: In the Linux kernel 6.0.8, there is a use-after-free in inode_cgwb_move_to_attached in fs/fs-writeba In the Linux kernel 6.0.8, there is a use-after-free in inode_cgwb_move_to_attached in fs/fs-writeback.c, related to __list_del_entry_valid.
nvdosv
CVE-2022-0998P3HIGHCVSS 7.8≥ 5.7, < 5.10.88≥ 5.11, < 5.15.11+1 more2022-03-30
CVE-2022-0998 [HIGH] CWE-190 CVE-2022-0998: An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function. This flaw allows a local user to crash or potentially escalate their privileges on the system.
nvdosv
CVE-2019-10142P3HIGHCVSS 7.8≥ 5.0, < 5.0.172019-07-30
CVE-2019-10142 [HIGH] CWE-119 CVE-2019-10142: A flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions A flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excluding 5.0.17. A parameter passed to an ioctl was incorrectly validated and used in size calculations for the page size calculation. An attacker can use this flaw to crash the system, corrupt memory, or create other adverse security affec
nvdosv
Linux Kernel vulnerabilities | cvebase