← Back
CWE-362

2,512 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.

JSON object

Loading...

CVEs (2,512)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
May 13, 2026
Aug 18, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in a USB driver can lead to a Use After Free condition.
1Google
1Android
May 13, 2026
Aug 18, 2017
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in two KGSL driver functions can lead to a Use After Free condition.
1Google
1Android
May 13, 2026
Aug 18, 2017
N/A· v4
7.0 HIGH· v3
5.1 MEDIUM· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a driver potentially leading to a use-after-free condition.
1Google
1Android
May 13, 2026
Aug 18, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in an IOCTL handler potentially leading to an integer overflow and then an out-of-bounds write.
1Google
1Android
May 13, 2026
Aug 18, 2017
N/A· v4
7.0 HIGH· v3
5.1 MEDIUM· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to a use-after-free condition.
1Google
1Android
May 13, 2026
Aug 18, 2017
N/A· v4
7.0 HIGH· v3
5.1 MEDIUM· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a video driver which can lead to a double free.
1Google
1Android
May 13, 2026
Aug 18, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, in some memory allocation and free functions, a race condition can potentially occur leading to a Use After Free condition.
1Google
1Android
May 13, 2026
Aug 18, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, when accessing the sde_rotator debug interface for register reading with multiple processes, one process can free the debug buffer while ano...Show more
In all Qualcomm products with Android releases from CAF using the Linux kernel, when accessing the sde_rotator debug interface for register reading with multiple processes, one process can free the debug buffer while another process still has the debug buffer in use.Show less
1Google
1Android
May 13, 2026
Aug 18, 2017
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, there is a TOCTOU race condition in Secure UI.
1Google
1Android
May 13, 2026
Aug 9, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A elevation of privilege vulnerability in the Android media framework (libgui). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-33004354.
1Linux
1Linux Kernel
May 13, 2026
Aug 5, 2017
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
Race condition in the fsnotify implementation in the Linux kernel through 4.12.4 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that leverages simultaneou...Show more
Race condition in the fsnotify implementation in the Linux kernel through 4.12.4 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that leverages simultaneous execution of the inotify_handle_event and vfs_rename functions.Show less
1Samsung
1Samsung Mobile
May 13, 2026
Aug 2, 2017
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1) allows local users to trigger memory errors by leveraging definition of g2d_lock a...Show more
Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1) allows local users to trigger memory errors by leveraging definition of g2d_lock and g2d_unlock lock macros as no-ops, aka SVE-2015-4598.Show less
1Vmware
1Tools
May 13, 2026
Jul 28, 2017
N/A· v4
6.7 MEDIUM· v3
3.7 LOW· v2
VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation. CVSS:...Show more
VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation. CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HShow less
2Artsproject
Kde
2Arts
Kdelibs
May 13, 2026
Jul 25, 2017
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory.
1Yadm Project
1Yadm
May 13, 2026
Jul 17, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
yadm (yet another dotfile manager) 1.10.0 has a race condition (related to the behavior of git commands in setting permissions for new files and directories), which potentially allows access to SSH and PGP keys.
1Openldap
1Openldap Servers
May 13, 2026
Jul 17, 2017
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation...Show more
/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it.Show less
1Teether
1Authd
May 13, 2026
Jul 17, 2017
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
authd sets weak permissions for /etc/ident.key, which allows local users to obtain the key by leveraging a race condition between the creation of the key, and the chmod to protect it.
1Redhat
1Networkmanager
May 13, 2026
Jul 17, 2017
N/A· v4
6.2 MEDIUM· v3
2.1 LOW· v2
Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows...Show more
Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows local users to obtain sensitive connection information by reading temporary files during ifcfg and keyfile changes.Show less
1Google
1Android
May 13, 2026
Jul 7, 2017
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb shell access to execute arbitrary code or any valid package as system by running "pm install" with t...Show more
Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb shell access to execute arbitrary code or any valid package as system by running "pm install" with the target apk, and simultaneously running a crafted script to process logcat's output looking for a dexopt line, which once found should execute bindBackupAgent with the uid member of the ApplicationInfo parameter set to 1000.Show less
1Xen
1Xen
May 13, 2026
Jul 5, 2017
N/A· v4
9.0 CRITICAL· v3
6.8 MEDIUM· v2
The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.