CWE-362
2,511 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.
CVEs (2,511)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Canonical 2Screen Resolution Extra Ubuntu LinuxJun 17, 2026 Mar 28, 2018 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows local users to bypass intended access restrictions by leveraging a race condition via a setuid or p...Show more |
1Kaseya 1Virtual System Administrator Nov 21, 2024 Mar 26, 2018 N/A· v4 7.4 HIGH· v3 6.9 MEDIUM· v2 It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator agent 9.3.0.11 and earlier tries to execute its binaries from working an...Show more |
2Debian Linux2Debian Linux Linux KernelNov 21, 2024 Mar 26, 2018 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified ot...Show more |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition in diag_ioctl_lsm_deinit() leads to a Use After Free condition. |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, race condition in diag_dbgfs_read_dcistats(), while accessing diag_dbgfs_dci_data_index, causes potential he...Show more |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to a race condition in a firmware loading routine, a buffer overflow could potentially occur if multiple...Show more |
A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that allows temporary access to an uploaded executable file that will be disallowed. The application allows an authenticated u...Show more |
3Debian RedhatSamba3Debian Linux Enterprise LinuxSambaNov 21, 2024 Mar 12, 2018 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition. |
In the Linux kernel before 4.15, fs/ocfs2/aops.c omits use of a semaphore and consequently has a race condition for access to the extent tree during read operations in DIRECT mode, which allows local users to cause a den...Show more |
2Debian Libvips2Debian Linux LibvipsJun 17, 2026 Mar 9, 2018 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, which allows remote attackers to cause a denial of service or possibly have unspecifi...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Mar 9, 2018 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/mcheck/mce.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (panic) by leveraging root access to write to...Show more |
2Google Nvidia2Android Shield Tv FirmwareNov 21, 2024 Mar 6, 2018 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 NVIDIA TrustZone Software contains a TOCTOU issue in the DRM application which may lead to the denial of service or possible escalation of privileges. This issue is rated as moderate. |
2Postgresql Suse2Postgresql Suse Linux Enterprise ServerNov 21, 2024 Mar 1, 2018 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root. |
The dm_get_from_kobject function in drivers/md/dm.c in the Linux kernel before 4.14.3 allow local users to cause a denial of service (BUG) by leveraging a race condition with __dm_destroy during creation and removal of D...Show more |
2Microsoft Tivo5Safedisc Windows 7Windows 8+2 moreJun 17, 2026 Feb 26, 2018 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. Two carefully timed calls to IOCTL 0xCA002813 c...Show more |
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a GPU Driver which can potentially lead to a Use After Free condition. |
Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or have unspecified other impact by creating files in advance or winning a race condition, as demonstrate...Show more |
Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and thread crash) via a state manipulation attack...Show more |
4Canonical DebianRedhat+1 more11Debian Linux Enterprise LinuxEnterprise Linux Aus+8 moreNov 21, 2024 Feb 16, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes tha...Show more |
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment. |