In the Linux kernel, the following vulnerability has been resolved: mptcp: fix TCP options overflow. Syzbot reported t
OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.
In the Linux kernel, the following vulnerability has been resolved: ibmvnic: fix race between xmit and reset There is
In the Linux kernel, the following vulnerability has been resolved: net: use sock_gen_put() when sk_state is TCP_TIME_W
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix timeout on deleted connect
In the Linux kernel, the following vulnerability has been resolved: sunrpc: handle SVC_GARBAGE during svc auth processi
In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: Fix napi rx poll issue When drive
In the Linux kernel, the following vulnerability has been resolved: net, hsr: reject HSR frame if skb can't hold tag R
In the Linux kernel, the following vulnerability has been resolved: net/smc: Reset connection when trying to use SMCRv2
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Ignore multiple conn complete
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Implement ref count for SRB The tim
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow
In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Correctly move list in sc_disable() Commi
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: avoid NULL pointer dereference in
In the Linux kernel, the following vulnerability has been resolved: HID: nintendo: fix rumble worker null pointer deref
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use list_first_entry_or_null for opinfo_get_
Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementat
A vulnerability classified as critical was found in RT-Thread 5.1.0. This vulnerability affects the function csys_sendto
NULL pointer dereference for some Intel(R) MLC software before version v3.11b may allow an authenticated user to potenti
In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Ensure mst_primary pointer is valid in
A null pointer dereference vulnerability in Macrium Reflect prior to 8.1.8017 allows a local attacker to cause a system
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: discard packets if the transport chan
In the Linux kernel, the following vulnerability has been resolved: net: sfc: add missing xdp queue reinitialization A
In the Linux kernel, the following vulnerability has been resolved: xsk: Fix race at socket teardown Fix a race in the
In the Linux kernel, the following vulnerability has been resolved: exec: Force single empty string when argv is empty
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix dereference of stale list iterator after
In the Linux kernel, the following vulnerability has been resolved: nvkm/gsp: correctly advance the read pointer of GSP
In the Linux kernel, the following vulnerability has been resolved: driver core: class: Fix wild pointer dereferences i
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix race at SNDCTL_DSP_SYNC There
Memory corruption in display driver while detaching a device.
In the Linux kernel, the following vulnerability has been resolved: tcp: drop secpath at the same time as we currently
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Harden loops for looking
In the Linux kernel, the following vulnerability has been resolved: drm/fbdev-dma: Add shadow buffering for deferred I/
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix bad hist from corrupting named_trigger
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add sanity checks on rdev validity T
In the Linux kernel, the following vulnerability has been resolved: drm/xe/hmm: Don't dereference struct page pointers
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Validate prev_cpu in scx_bpf_select_cpu_
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Bridge, fix the crash caused by LAG state
In the Linux kernel, the following vulnerability has been resolved: mm/migrate: fix shmem xarray update during migratio
In the Linux kernel, the following vulnerability has been resolved: sctp: add mutual exclusion in proc_sctp_do_udp_port
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Don't expose hw_counters outside of init
In the Linux kernel, the following vulnerability has been resolved: slab: ensure slab->obj_exts is clear in a newly all
In the Linux kernel, the following vulnerability has been resolved: ice: xsk: disable txq irq before flushing hw ice_q
In the Linux kernel, the following vulnerability has been resolved: bpf: consider that tail calls invalidate packet poi
In the Linux kernel, the following vulnerability has been resolved: spi: spi-imx: Add check for spi_imx_setupxfer() Ad
In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix invalid pointer dereference in Etron
In the Linux kernel, the following vulnerability has been resolved: pds_core: make wait_context part of q_info Make th
In the Linux kernel, the following vulnerability has been resolved: xenbus: Use kref to track req lifetime Marek repor
In the Linux kernel, the following vulnerability has been resolved: Revert "usb: typec: ucsi: add a common function ucs
In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix NULL pointer dereference in is_ftrace_t
Frequently Asked Questions
What is CWE-476?
CWE-476 (NULL Pointer Dereference) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-476?
There are 6,577 CVE records associated with CWE-476 in our database. Of these, 121 are critical severity, 1458 are high severity, and 3571 are medium severity.
How can I protect against CWE-476 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-476 using AI-powered security agents.
Detect CWE-476 Vulnerabilities
CyberStrike's AI agents automatically detect null pointer dereference vulnerabilities across your infrastructure.
Get Started