Linux
19,044 known vulnerabilities
Top Products
This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kerne
A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks in the Linux kernel X86
A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based sys
A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the lea
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cf
A flaw was found in the Linux kernel. A use-after-free may be triggered in asus_kbd_backlight_set when plugging/disconne
A flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses li
In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as th
A flaw was found in the Linux Kernel. The tun/tap sockets have their socket UID hardcoded to 0 due to a type confusion i
A flaw was found in the Linux Kernel. The tls_is_tx_ready() incorrectly checks for list emptiness, potentially accessing
A memory leak flaw was found in the Linux kernel's Stream Control Transmission Protocol. This issue may occur when a use
A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a
A flaw was found in the Linux kernel's implementation of RDMA over infiniband. An attacker with a privileged local accou
Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and P
In the Linux kernel through 6.2.8, net/bluetooth/hci_sync.c allows out-of-bounds access because amp_init1[] and amp_init
A NULL pointer dereference was found in io_file_bitmap_get in io_uring/filetable.c in the io_uring sub-component in the
An issue was discovered in the Linux kernel before 5.8. lib/nlattr.c allows attackers to cause a denial of service (unbo
A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be some uninitialized
A use-after-free flaw was found in the Linux kernel’s Ext4 File System in how a user triggers several file operations si
A use-after-free flaw was found in the Linux kernel’s core dump subsystem. This flaw allows a local user to crash the sy
A use-after-free flaw was found in qdisc_graft in net/sched/sch_api.c in the Linux Kernel due to a race problem. This fl
An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow.
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
A use-after-free flaw was found in Linux kernel before 5.19.2. This issue occurs in cmd_hdl_filter in drivers/staging/rt
Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imp
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their us
TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 tha
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remot
IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using sp
IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, u
In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid kfree because it does not validate MFT flags before r
In the Linux kernel before 6.1.3, fs/ntfs3/inode.c does not validate the attribute name offset. An unhandled page fault
In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names. An out-of-bounds write m
ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libg
A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module. The while loop in tipc_link
IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Fo
do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race cond
NVIDIA CUDA Toolkit SDK contains a vulnerability in cuobjdump, where a local user running the tool against a malicious
A use-after-free flaw was found in the Linux kernel’s nouveau driver in how a user triggers a memory overflow that cause
A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resour
A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl functi
A flaw use after free in the Linux kernel integrated infrared receiver/transceiver driver was found in the way user deta
NVIDIA CUDA Toolkit SDK contains a bug in cuobjdump, where a local user running the tool against an ill-formed binary m
In the Linux kernel before 5.15.13, drivers/net/ethernet/mellanox/mlx5/core/steering/dr_domain.c misinterprets the mlx5_
In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NUL
In the Linux kernel before 5.19, drivers/gpu/drm/arm/malidp_planes.c misinterprets the get_sg_table return value (expect
In the Linux kernel before 5.16, tools/perf/util/expr.c lacks a check for the hashmap__new return value.
In the Linux kernel before 5.16.3, drivers/bluetooth/hci_qca.c misinterprets the devm_gpiod_get_index_optional return va
In the Linux kernel before 5.16.3, drivers/scsi/ufs/ufs-mediatek.c misinterprets the regulator_get return value (expects
Frequently Asked Questions
How many CVEs affect Linux?
Linux has 19,044 CVE records in our database, including 767 critical and 8163 high severity vulnerabilities. 47 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Linux vulnerabilities?
Linux has 767 critical severity (CVSS 9.0+) and 8163 high severity (CVSS 7.0-8.9) vulnerabilities. 47 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Linux vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Linux products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Linux Vulnerabilities
CyberStrike scans your infrastructure for Linux vulnerabilities and provides real-time remediation guidance.
Get Started