← Back

Linux Kernel

linux_kernel

Vendor: Linux • 14,504 CVEs

CVEs (14,504)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
DebianLinux+2 more
11Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+8 more
May 6, 2026
May 23, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer inter...Show more
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.Show less
3Canonical
LinuxNovell
10Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+7 more
May 6, 2026
May 23, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via...Show more
The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface.Show less
1Linux
1Linux Kernel
May 6, 2026
May 23, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
drivers/media/v4l2-core/videobuf2-v4l2.c in the Linux kernel before 4.5.3 allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a crafted number of...Show more
drivers/media/v4l2-core/videobuf2-v4l2.c in the Linux kernel before 4.5.3 allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a crafted number of planes in a VIDIOC_DQBUF ioctl call.Show less
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
May 6, 2026
May 23, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecifi...Show more
The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface.Show less
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
May 6, 2026
May 23, 2016
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted application o...Show more
The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted application on (1) a system with more than 32 Gb of memory, related to the program reference count or (2) a 1 Tb system, related to the map reference count.Show less
1Linux
1Linux Kernel
May 6, 2026
May 23, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or cause a denial of service...Show more
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or cause a denial of service (use-after-free) via crafted BPF instructions that reference an incorrect file descriptor.Show less
3Canonical
LinuxNovell
10Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+7 more
May 6, 2026
May 23, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory b...Show more
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.Show less
3Canonical
LinuxNovell
5Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Server+2 more
May 6, 2026
May 23, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a me...Show more
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.Show less
4Canonical
FedoraprojectLinux+1 more
11Fedora
Linux KernelSuse Linux Enterprise Debuginfo+8 more
May 6, 2026
May 23, 2016
N/A· v4
6.2 MEDIUM· v3
2.1 LOW· v2
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory vi...Show more
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.Show less
1Linux
1Linux Kernel
May 6, 2026
May 9, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify authorization for private SET IOCTL cal...Show more
The WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify authorization for private SET IOCTL calls, which allows attackers to gain privileges via a crafted application, related to wlan_hdd_hostapd.c and wlan_hdd_wext.c.Show less
1Linux
1Linux Kernel
May 6, 2026
May 9, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Stack-based buffer overflow in the SET_WPS_IE IOCTL implementation in wlan_hdd_hostapd.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions...Show more
Stack-based buffer overflow in the SET_WPS_IE IOCTL implementation in wlan_hdd_hostapd.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via a crafted application that uses a long WPS IE element.Show less
1Linux
1Linux Kernel
May 6, 2026
May 9, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android...Show more
Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via a crafted application that establishes a packet filter.Show less
2Google
Linux
3Linux Kernel
Nexus 5x FirmwareNexus 6p Firmware
May 6, 2026
May 5, 2016
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices an...Show more
The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, uses an incorrect integer data type, which allows attackers to cause a denial of service (integer overflow, heap-based buffer overflow, and incorrect memory allocation) or possibly have unspecified other impact via a crafted IOCTL_KGSL_PERFCOUNTER_QUERY ioctl call.Show less
2Google
Linux
2Android
Linux Kernel
May 6, 2026
May 5, 2016
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devic...Show more
The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify that a port is a client port, which allows attackers to gain privileges or cause a denial of service (race condition and list corruption) by making many BIND_CONTROL_PORT ioctl calls.Show less
4Canonical
LinuxNovell+1 more
10Linux Kernel
Suse Linux Enterprise DesktopSuse Linux Enterprise Live Patching+7 more
May 6, 2026
May 2, 2016
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserti...Show more
Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB descriptor.Show less
3Canonical
LinuxNovell
9Linux Kernel
Suse Linux Enterprise DesktopSuse Linux Enterprise Live Patching+6 more
May 6, 2026
May 2, 2016
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a maste...Show more
The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface.Show less
3Canonical
LinuxNovell
10Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+7 more
May 6, 2026
May 2, 2016
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a cr...Show more
The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.Show less
3Canonical
LinuxNovell
10Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+7 more
May 6, 2026
May 2, 2016
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device witho...Show more
The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both a control and a data endpoint descriptor.Show less
3Canonical
LinuxNovell
10Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+7 more
May 6, 2026
May 2, 2016
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both an interrupt-i...Show more
drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both an interrupt-in and an interrupt-out endpoint descriptor, related to the cypress_generic_port_probe and cypress_open functions.Show less
3Canonical
LinuxNovell
9Linux Kernel
Suse Linux Enterprise DesktopSuse Linux Enterprise Live Patching+6 more
May 6, 2026
May 2, 2016
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a cr...Show more
The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device without two interrupt-in endpoint descriptors.Show less