CWE-362
2,498 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.
CVEs (2,498)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
drivers/char/pcmcia/synclink_cs.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling ioctl, aka a race condition...Show more |
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Sep 27, 2022 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member o...Show more |
Use after free in Tab Strip in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via cra...Show more |
Use after free in SplitScreen in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a...Show more |
Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
1Blazzdev 1Rate My Post Wp Rating System Jun 17, 2026 Sep 23, 2022 N/A· v4 3.1 LOW· v3 N/A· v2 Authenticated (subscriber+) Race Condition vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress allows attackers to increase/decrease votes. |
In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to gain root privileges. There is a race c...Show more |
The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart. |
In PVRSRVRGXSubmitTransferKM of rgxtransfer.c, there is a possible user after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...Show more |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreJun 17, 2026 Sep 13, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 Windows ALPC Elevation of Privilege Vulnerability |
1Microsoft 5Windows 10 Windows 11Windows Server 2016+2 moreJun 17, 2026 Sep 13, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 Windows Photo Import API Elevation of Privilege Vulnerability |
1Wp Postratings Project 1Wp Postratings Jun 17, 2026 Sep 9, 2022 N/A· v4 3.1 LOW· v3 N/A· v2 Rating increase/decrease via race condition in Lester 'GaMerZ' Chan WP-PostRatings plugin <= 1.89 at WordPress. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Sep 9, 2022 N/A· v4 4.7 MEDIUM· v3 N/A· v2 An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free. |
In apusys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID:...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Sep 2, 2022 N/A· v4 4.7 MEDIUM· v3 N/A· v2 An issue was discovered in include/asm-generic/tlb.h in the Linux kernel before 5.19. Because of a race condition (unmap_mapping_range versus munmap), a device driver can free a page while it still has stale TLB entries....Show more |
2Linux Netapp2Hci Baseboard Management Controller Linux KernelJun 17, 2026 Sep 1, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address informati...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Aug 31, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentiall...Show more |