← Back
CWE-362

2,512 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.

JSON object

Loading...

CVEs (2,512)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xen
1Xen
May 13, 2026
Jul 5, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain...Show more
The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA-218 bug 2.Show less
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In all Android releases from CAF using the Linux kernel, a race condition exists in a QTEE driver potentially leading to an arbitrary memory write.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to buffer overflow or write to arbitrary pointer location.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
In all Android releases from CAF using the Linux kernel, a race condition potentially exists in the ioctl handler of a sound driver.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
In all Android releases from CAF using the Linux kernel, time-of-check Time-of-use (TOCTOU) Race Conditions exist in several TZ APIs.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
In all Android releases from CAF using the Linux kernel, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists in Secure Display.
1Cornelisnetworks
2Opa Ff
Opa Fm
May 13, 2026
Jun 7, 2017
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Race conditions in opa-fm before 10.4.0.0.196 and opa-ff before 10.4.0.0.197.
1Google
1Android
May 13, 2026
Jun 6, 2017
N/A· v4
7.0 HIGH· v3
9.3 HIGH· v2
In TrustZone in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.
1Google
1Android
May 13, 2026
Jun 6, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
In the Embedded File System in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.
1Sudo Project
1Sudo
May 13, 2026
Jun 5, 2017
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.
3Canonical
DebianFile
3\
Debian LinuxUbuntu Linux
May 13, 2026
Jun 1, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 13, 2026
May 22, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "IOSurface" com...Show more
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "IOSurface" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.Show less
1Apple
1Mac Os X
May 13, 2026
May 22, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitration" component. A race condition allows attackers to execute arbitrary code in a privileged context...Show more
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitration" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.Show less
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 13, 2026
May 22, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Kernel" compon...Show more
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.Show less
1Google
1Android
May 13, 2026
May 16, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
A time-of-check time-of-use race condition could potentially exist in the secure file system in all Android releases from CAF using the Linux kernel.
1Google
1Android
May 13, 2026
May 16, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
In TrustZone a time-of-check time-of-use race condition could potentially exist in a listener routine in all Android releases from CAF using the Linux kernel.
1Google
1Android
May 13, 2026
May 16, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
In TrustZone a time-of-check time-of-use race condition could potentially exist in a QFPROM routine in all Android releases from CAF using the Linux kernel.
1Google
1Android
May 13, 2026
May 16, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
In TrustZone a time-of-check time-of-use race condition could potentially exist in an authentication routine in all Android releases from CAF using the Linux kernel.
1Google
1Android
May 13, 2026
May 12, 2017
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
In core_info_read and inst_info_read in all Android releases from CAF using the Linux kernel, variable "dbg_buf", "dbg_buf->curr" and "dbg_buf->filled_size" could be modified by different threads at the same time, but th...Show more
In core_info_read and inst_info_read in all Android releases from CAF using the Linux kernel, variable "dbg_buf", "dbg_buf->curr" and "dbg_buf->filled_size" could be modified by different threads at the same time, but they are not protected with mutex or locks. Buffer overflow is possible on race conditions. "buffer->curr" itself could also be overwritten, which means that it may point to anywhere of kernel memory (for write).Show less
1Nvidia
1Gpu Driver
May 13, 2026
May 9, 2017
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) where user can trigger a race condition due to lack of synchronization in two functions leading to a d...Show more
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) where user can trigger a race condition due to lack of synchronization in two functions leading to a denial of service or potential escalation of privileges.Show less