← Back
CWE-362

2,496 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.

JSON object

Loading...

CVEs (2,496)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Whatsapp
1Whatsapp
Jun 17, 2026
Oct 4, 2023
N/A· v4
5.6 MEDIUM· v3
N/A· v2
A race condition in a network transport subsystem led to a heap use-after-free issue in established or unsilenced incoming audio/video calls that could have resulted in app termination or unexpected control flow with ver...Show more
A race condition in a network transport subsystem led to a heap use-after-free issue in established or unsilenced incoming audio/video calls that could have resulted in app termination or unexpected control flow with very low probability.Show less
2Linux
Redhat
10Codeready Linux Builder
Codeready Linux Builder For Arm64Codeready Linux Builder For Power Little Endian+7 more
Jun 17, 2026
Oct 3, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker with a local user privilege may cause a denial of service problem due to a BUG statement referencin...Show more
A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker with a local user privilege may cause a denial of service problem due to a BUG statement referencing pmd_t x.Show less
1Phpkobo
1Ajax Poll Script
Jun 17, 2026
Sep 30, 2023
N/A· v4
3.7 LOW· v3
5.0 MEDIUM· v2
A vulnerability classified as problematic was found in phpkobo Ajax Poll Script 3.18. Affected by this vulnerability is an unknown functionality of the file ajax-poll.php of the component Poll Handler. The manipulation l...Show more
A vulnerability classified as problematic was found in phpkobo Ajax Poll Script 3.18. Affected by this vulnerability is an unknown functionality of the file ajax-poll.php of the component Poll Handler. The manipulation leads to improper enforcement of a single, unique action. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240949 was assigned to this vulnerability.Show less
4Debian
FedoraprojectLinux+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Jun 17, 2026
Sep 28, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue m...Show more
A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue may allow a local user to crash the system.Show less
1Apple
1Macos
Jun 17, 2026
Sep 27, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
A race condition was addressed with improved locking. This issue is fixed in macOS Sonoma 14. An app may be able to modify protected parts of the file system.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Sep 27, 2023
N/A· v4
3.7 LOW· v3
N/A· v2
Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this vulnerability may cause the bone voice ID feature to be unavailable.
2Qemu
Redhat
2Enterprise Linux
Qemu
Jun 17, 2026
Sep 13, 2023
N/A· v4
5.6 MEDIUM· v3
N/A· v2
A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window...Show more
A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.Show less
3Debian
FedoraprojectOpenpmix
3Debian Linux
FedoraOpenpmix
Jun 17, 2026
Sep 9, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
1Apple
1Macos
Jun 17, 2026
Sep 6, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
A race condition was addressed with improved state handling. This issue is fixed in macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.
3Google
LinuxfoundationMediatek
3Android
Iot YoctoYocto
Jun 17, 2026
Sep 4, 2023
N/A· v4
6.4 MEDIUM· v3
N/A· v2
In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID:...Show more
In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341261; Issue ID: ALPS07326570.Show less
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
6.4 MEDIUM· v3
N/A· v2
In pda, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP...Show more
In pda, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07608514; Issue ID: ALPS07608514.Show less
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
6.4 MEDIUM· v3
N/A· v2
In ims service, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Pa...Show more
In ims service, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937105; Issue ID: ALPS07937105.Show less
3Debian
NetappPython
4Active Iq Unified Manager
Converged Systems Advisor AgentDebian Linux+1 more
Jun 17, 2026
Aug 22, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
1Google
1Android
Jun 17, 2026
Aug 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This could lead to local denial of service with no additional execution privileges needed. User interaction...Show more
In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Show less
1Intel
71Compute Element Stk2mv64cc Firmware
Nuc Board Nuc7i3bnb FirmwareNuc Board Nuc7i3bnh Firmware+68 more
Jun 17, 2026
Aug 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
174Nuc 11 Compute Element Cm11ebc4w Firmware
Nuc 11 Compute Element Cm11ebi38w FirmwareNuc 11 Compute Element Cm11ebi58w Firmware+171 more
Jun 17, 2026
Aug 11, 2023
N/A· v4
6.4 MEDIUM· v3
N/A· v2
Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
3Ethernet Network Controller E810 Cam1 Firmware
Ethernet Network Controller E810 Cam2 FirmwareEthernet Network Controller E810 Xxvam2 Firmware
Jun 17, 2026
Aug 11, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Race condition in firmware for some Intel(R) Ethernet Controllers and Adapters E810 Series before version 1.7.2.4 may allow an authenticated user to potentially enable denial of service via local access.
1Microsoft
7Windows 10 1809
Windows 10 21h2Windows 10 22h2+4 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Windows Projected File System Elevation of Privilege Vulnerability
2Google
Linuxfoundation
2Android
Yocto
Jun 17, 2026
Aug 7, 2023
N/A· v4
6.4 MEDIUM· v3
N/A· v2
In imgsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID:...Show more
In imgsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS07420968.Show less
2Debian
Mozilla
2Debian Linux
Firefox
Jun 17, 2026
Aug 1, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR <...Show more
Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.Show less