CWE-667
719 CVEs • Abstraction: Class
Improper Locking
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.
CVEs (719)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject LinuxNetapp7A250 Firmware Aff 500f FirmwareCloud Backup+4 moreJun 17, 2026 Mar 20, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (deadlock) because exit may be waiting to park a SQPOLL thread, but concurrently that SQPOLL t...Show more |
2Linux Netapp9Aff Baseboard Management Controller Baseboard Management Controller 500f FirmwareBaseboard Management Controller A250 Firmware+6 moreJun 17, 2026 Feb 5, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were im...Show more |
An issue was discovered in the va-ts crate before 0.0.4 for Rust. Because Demuxer<T> omits a required T: Send bound, a data race and memory corruption can occur. |
2Debian Gssproxy Project2Debian Linux GssproxyJun 17, 2026 Dec 31, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in quest...Show more |
In xfrm6_tunnel_free_spi of net/ipv6/xfrm6_tunnel.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction...Show more |
In priorLinearAllocation of C2AllocatorIon.cpp, there is a possible use-after-free due to improper locking. This could lead to local information disclosure in the media codec with no additional execution privileges neede...Show more |
6Broadcom DebianFedoraproject+3 more128300 Firmware 8700 FirmwareA400 Firmware+9 moreJun 17, 2026 Dec 9, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b. |
5Broadcom DebianFedoraproject+2 more118300 Firmware 8700 FirmwareA400 Firmware+8 moreJun 17, 2026 Dec 9, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9...Show more |
1Qualcomm 46Agatti Firmware Apq8009 FirmwareApq8017 Firmware+43 moreJun 17, 2026 Nov 2, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 u'While processing invalid connection request PDU which is nonstandard (interval or timeout is 0) from central device may lead peripheral system enter into dead lock state.(This CVE is equivalent to InvalidConnectionRequ...Show more |
1Apple 5Ipados Iphone OsMac Os X+2 moreJun 17, 2026 Oct 27, 2020 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A memory corruption vulnerability was addressed with improved locking. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6.1, tvOS 13.2, iOS 13.2 and iPadOS 13...Show more |
A lock screen issue allowed access to messages on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 14.0 and iPadOS 14.0. A person with physical access to an iOS device...Show more |
1Apple 3Ipados Iphone OsWatchosJun 17, 2026 Oct 16, 2020 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 This issue was addressed with improved checks. This issue is fixed in iOS 14.0 and iPadOS 14.0, watchOS 7.0. The screen lock may not engage after the specified time period. |
2Debian Google2Android Debian LinuxJun 17, 2026 Oct 14, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In binder_release_work of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interact...Show more |
In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User...Show more |
Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrar...Show more |
A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80. |
In SurfaceFlinger, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is n...Show more |
In the Media extractor, there is a possible use after free due to improper locking. This could lead to remote code execution in the media extractor with no additional execution privileges needed. User interaction is need...Show more |
In blk_mq_queue_tag_busy_iter of blk-mq-tag.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Aug 24, 2020 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer...Show more |