CWE-362
2,498 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.
CVEs (2,498)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only shared memory mappings. This flaw allows an unprivileged, local user to gain write a...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Aug 31, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh->use to represent how many objects are using the rose_neigh. When a user wants to delete a rose_route via r...Show more |
3Fedoraproject LinuxNetapp7Fedora H300s FirmwareH410c Firmware+4 moreJun 17, 2026 Aug 29, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local...Show more |
2Ovirt Redhat4Vdsm VirtualizationVirtualization For Ibm Power Little Endian+1 moreJun 17, 2026 Aug 26, 2022 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text. |
A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack of proper locking wh...Show more |
A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a temporary directory, substitute their directory at that name, and then have access to ansible-runner's...Show more |
3Debian RedhatSamba7Debian Linux Enterprise LinuxEnterprise Linux Aus+4 moreJun 17, 2026 Aug 23, 2022 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share. |
1Eternal Terminal Project 1Eternal Terminal Jun 17, 2026 Aug 16, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 A race condition exists in Eternal Terminal prior to version 6.2.0 which allows a local attacker to hijack Eternal Terminal's IPC socket, enabling access to Eternal Terminal clients which attempt to connect in the future...Show more |
1Eternal Terminal Project 1Eternal Terminal Jun 17, 2026 Aug 16, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted us...Show more |
1Eternal Terminal Project 1Eternal Terminal Jun 17, 2026 Aug 16, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A privilege escalation to root exists in Eternal Terminal prior to version 6.2.0. This is due to the combination of a race condition, buffer overflow, and logic bug all in PipeSocketHandler::listen(). |
Use after free in Offline in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI i...Show more |
Use after free in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interactions. |
Use after free in Nearby Share in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specif...Show more |
Use after free in Overview Mode in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via speci...Show more |
Use after free in Tab Strip in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific...Show more |
In the Audio HAL, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation...Show more |
In st21nfc_loc_set_polaritymode of fc/st21nfc.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is n...Show more |
In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communication due to a race condition. This could lead to local escalation of privilege with no additional execution privileges...Show more |
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreJun 17, 2026 Aug 9, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability |