Skip to main content

Recently Exploited Linux Kernel CVEs

All Linux Kernel CVEs

31 records
CVETitleVendorCVSSEPSSKEVPublished
CVE-2025-39682
tls: fix handling of zero-length records on the rx_list
Linux9.82.9%KEV2025-09-05
CVE-2025-39964
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
Linux7.81.3%KEV2025-10-13
CVE-2026-53266
netfilter: bridge: make ebt_snat ARP rewrite writable
Linux8.80.8%KEV2026-06-25
CVE-2026-53362
ipv6: account for fraggap on the paged allocation path
Linux7.80.7%KEV2026-07-04
CVE-2022-0995
Linux Kernel Out-of-Bounds Write Vulnerability
-7.88.8%KEV2022-03-25
CVE-2022-0492
Linux Kernel Improper Authentication Vulnerability
-7.85.5%KEV2022-03-03
CVE-2026-31431
crypto: algif_aead - Revert to operating out-of-place
Linux7.83.4%KEV2026-04-22
CVE-2018-14634
Linux Kernel Integer Overflow Vulnerability
The Linux Foundation7.814.7%KEV2018-09-25
CVE-2021-22555
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
-8.378.7%KEV2021-07-07
CVE-2025-38352
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
Linux7.81.3%KEV2025-07-22
CVE-2023-0386
Linux Kernel Improper Ownership Management Vulnerability
-7.87.9%KEV2023-03-22
CVE-2024-53197
ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
Linux7.84.1%KEV2024-12-27
CVE-2024-53150
ALSA: usb-audio: Fix out of bounds reads when finding clock sources
Linux7.11.4%KEV2024-12-24
CVE-2024-50302
HID: core: zero-initialize the report buffer
Linux5.50.8%KEV2024-11-19
CVE-2024-53104
media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
Linux7.83.4%KEV2024-12-02
CVE-2017-1000253
Linux Kernel PIE Stack Buffer Corruption Vulnerability
-7.810.7%KEV2017-10-04
CVE-2022-0185
Linux Kernel Heap-Based Buffer Overflow Vulnerability
-8.425.2%KEV2022-02-11
CVE-2022-2586
Linux Kernel Use-After-Free Vulnerability
The Linux Kernel Organization5.310.2%KEV2024-01-08
CVE-2024-1086
Use-after-free in Linux kernel's netfilter: nf_tables component
Linux7.828.1%KEV2024-01-31
CVE-2014-0196
Linux Kernel Race Condition Vulnerability
-5.522.5%KEV2014-05-07
CVE-2010-3904
Linux Kernel Improper Input Validation Vulnerability
-7.815.7%KEV2010-12-06
CVE-2023-0266
Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel
Linux7.93.7%KEV2023-01-30
CVE-2021-3493
Linux Kernel Privilege Escalation Vulnerability
Ubuntu8.849.2%KEV2021-04-17
CVE-2013-2094
Linux Kernel Privilege Escalation Vulnerability
-8.447.7%KEV2013-05-14
CVE-2013-6282
Linux Kernel Improper Input Validation Vulnerability
-8.839.7%KEV2013-11-19
CVE-2013-2596
Linux Kernel Integer Overflow Vulnerability
-7.83.2%KEV2013-04-13
CVE-2014-3153
Linux Kernel Privilege Escalation Vulnerability
-7.837.2%KEV2014-06-07
CVE-2022-0847
Linux Kernel Privilege Escalation Vulnerability
-7.892.8%KEV2022-03-07
CVE-2021-22600
Double Free in net/packet/af_packet.c leading to priviledge escalation
Linux Kernel6.66.6%KEV2022-01-26
CVE-2016-5195
Linux Kernel Race Condition Vulnerability
-7.083.5%KEV2016-11-10
CVE-2019-13272
Linux Kernel Improper Privilege Management Vulnerability
-7.852.2%KEV2019-07-17

Frequently Asked Questions

How many Linux Kernel vulnerabilities are actively exploited?→

31 Linux Kernel CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-09-18.

Which Linux Kernel vulnerabilities are used in ransomware attacks?→

CISA marks 2 Linux Kernel KEV entries as known to be used in ransomware campaigns, including CVE-2017-1000253, CVE-2024-1086.

Which Linux Kernel products have the most exploited vulnerabilities?→
  • +Kernel: 31 CVEs (31 in KEV)
Where does Linux Kernel publish security advisories?→

Linux Kernel publishes security advisories at https://docs.kernel.org/process/cve.html. Check the vendor advisory for fixed versions and workarounds before applying updates.

Sources

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Linux Kernel, MITRE, CISA, or FIRST.