Home/Company/Linux Kernel CVEs
Linux Kernel CVEs

Linux Kernel Vulnerabilities Discovered by Svace

No.DateCVESource
1382026-09-17CVE-2026-93176: drm/amd/display: Fix dangling pointer in plane reset functionLINK ↗
1372026-09-17CVE-2026-93175: drm/amd/display: Fix dangling pointer in CRTC reset functionLINK ↗
1362026-09-17CVE-2026-93037: RDMA/hfi1: Propagate sdma_txinit_ahg() errorsLINK ↗
1352026-09-17CVE-2026-90245: fbdev: kyro: Validate overlay viewport coordinatesLINK ↗
1342026-08-28CVE-2026-80605: HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()LINK ↗
1332026-08-15CVE-2026-74362: ext2: fix ignored return value of generic_write_sync()LINK ↗
1322026-08-10CVE-2026-68355: wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()LINK ↗
1312026-07-19CVE-2026-63838: ASoC: rsnd: Fix potential out-of-bounds access of component_dais[]LINK ↗
1302026-06-24CVE-2026-53068: drm/komeda: fix integer overflow in AFBC framebuffer size checkLINK ↗
1292026-06-03CVE-2026-46267: nfc: hci: shdlc: Stop timers and work before freeing contextLINK ↗
1282026-05-27CVE-2026-46092: wifi: rtw88: check for PCI upstream bridge existenceLINK ↗
1272026-05-06CVE-2026-43272: ring-buffer: Fix possible dereference of uninitialized pointerLINK ↗
1262026-05-06CVE-2026-43123: fbcon: check return value of con2fb_acquire_newinfo()LINK ↗
1252026-05-01CVE-2026-31779: wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler()LINK ↗
1242026-01-14CVE-2025-71136: media: adv7842: Avoid possible out-of-bounds array accesses in adv7842_cp_log_status()LINK ↗
1232026-01-13CVE-2025-68820: ext4: xattr: fix null pointer deref in ext4_raw_inode()LINK ↗
1222026-01-13CVE-2025-68782: scsi: target: Reset t_task_cdb pointer in error caseLINK ↗
1212025-12-24CVE-2023-54057: iommu/amd: Add a length limitation for the ivrs_acpihid command-line parameterLINK ↗
1202025-12-24CVE-2025-68345: ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_hda_read_acpi()LINK ↗
1192025-12-08CVE-2025-40294: Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern()LINK ↗
1182025-12-04CVE-2025-40252: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end()LINK ↗
1172025-10-30CVE-2025-40098: ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state()LINK ↗
1162025-10-30CVE-2025-40097: ALSA: hda: Fix missing pointer check in hda_component_manager_init functionLINK ↗
1152025-10-28CVE-2025-40068: fs: ntfs3: Fix integer overflow in run_unpack()LINK ↗
1142025-10-22CVE-2023-53705: ipv6: Fix out-of-bounds access in ipv6_find_tlv()LINK ↗
1132025-10-15CVE-2025-39991: wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load()LINK ↗
1122025-10-07CVE-2023-53661: bnxt: avoid overflow in bnxt_get_nvram_directory()LINK ↗
1112025-10-01CVE-2023-53498: drm/amd/display: Fix potential null dereferenceLINK ↗
1102025-09-19CVE-2025-39838: cifs: prevent NULL pointer dereference in UTF16 conversionLINK ↗
1092025-09-18CVE-2023-53384: wifi: mwifiex: avoid possible NULL skb pointer dereferenceLINK ↗
1082025-09-17CVE-2023-53335: RDMA/cxgb4: Fix potential null-ptr-deref in pass_establish()LINK ↗
1072025-09-16CVE-2023-53332: genirq/ipi: Fix NULL pointer deref in irq_data_get_affinity_mask()LINK ↗
1062025-09-16CVE-2023-53307: rbd: avoid use-after-free in do_rbd_add() when rbd_dev_create() failsLINK ↗
1052025-09-15CVE-2022-50288: qlcnic: prevent ->dcb use-after-free on qlcnic_dcb_enable() failureLINK ↗
1042025-09-15CVE-2023-53196: usb: dwc3: qcom: Fix potential memory leakLINK ↗
1032025-08-19CVE-2025-38604: wifi: rtl818x: Kill URBs before clearing tx status queueLINK ↗
1022025-08-16CVE-2025-38513: wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev()LINK ↗
1012025-07-10CVE-2025-38312: fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod()LINK ↗
1002025-07-10CVE-2025-38277: mtd: nand: ecc-mxic: Fix use of uninitialized variable retLINK ↗
992025-07-04CVE-2025-38183: net: lan743x: fix potential out-of-bounds write in lan743x_ptp_io_event_clock_get()LINK ↗
982025-07-03CVE-2025-38167: fs/ntfs3: handle hdr_first_de() return valueLINK ↗
972025-07-03CVE-2025-38159: wifi: rtw88: fix the 'para' buffer size to avoid reading out of boundsLINK ↗
962025-07-03CVE-2025-38142: hwmon: (asus-ec-sensors) check sensor index in read_string()LINK ↗
952025-06-18CVE-2022-50185: drm/radeon: fix potential buffer overflow in ni_set_mc_special_registers()LINK ↗
942025-06-18CVE-2022-50180: wifi: iwlegacy: 4965: fix potential off-by-one overflow in il4965_rs_fill_link_cmd()LINK ↗
932025-06-18CVE-2022-50132: usb: cdns3: change place of 'priv_ep' assignment in cdns3_gadget_ep_dequeue(), cdns3_gadget_ep_enable()LINK ↗
922025-06-18CVE-2022-50040: net: dsa: sja1105: fix buffer overflow in sja1105_setup_devlink_regions()LINK ↗
912025-06-18CVE-2025-38077: platform/x86: dell-wmi-sysman: Avoid buffer overflow in current_password_store()LINK ↗
902025-05-20CVE-2025-37979: ASoC: qcom: Fix sc7280 lpass potential buffer overflowLINK ↗
892025-05-20CVE-2025-37927: iommu/amd: Fix potential buffer overflow in parse_ivrs_acpihidLINK ↗
882025-05-09CVE-2025-37844: cifs: avoid NULL pointer dereference in dbg callLINK ↗
872025-05-09CVE-2025-37858: fs/jfs: Prevent integer overflow in AG size calculationLINK ↗
862025-05-09CVE-2025-37851: fbdev: omapfb: Add 'plane' value checkLINK ↗
852025-05-08CVE-2025-37811: usb: chipidea: ci_hdrc_imx: fix usbmisc handlingLINK ↗
842025-05-02CVE-2023-53066: qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_infoLINK ↗
832025-05-01CVE-2025-37769: drm/amd/pm/smu11: Prevent division by zeroLINK ↗
822025-05-01CVE-2025-37768: drm/amd/pm: Prevent division by zeroLINK ↗
812025-05-01CVE-2025-37767: drm/amd/pm: Prevent division by zeroLINK ↗
802025-05-01CVE-2025-37766: drm/amd/pm: Prevent division by zeroLINK ↗
792025-05-01CVE-2025-37771: drm/amd/pm: Prevent division by zeroLINK ↗
782025-05-01CVE-2025-37770: drm/amd/pm: Prevent division by zeroLINK ↗
772025-04-03CVE-2025-21997: xsk: fix an integer overflow in xp_create_and_assign_umem()LINK ↗
762025-04-03CVE-2025-21996: drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse()LINK ↗
752025-04-01CVE-2025-21962: cifs: Fix integer overflow while processing closetimeo mount optionLINK ↗
742025-04-01CVE-2025-21964: cifs: Fix integer overflow while processing acregmax mount optionLINK ↗
732025-04-01CVE-2025-21963: cifs: Fix integer overflow while processing acdirmax mount optionLINK ↗
722025-03-27CVE-2023-53005: trace_events_hist: add check for return value of 'create_hist_field'LINK ↗
712025-03-27CVE-2023-53032: netfilter: ipset: Fix overflow before widen in the bitmap_ip_create() function.LINK ↗
702025-03-27CVE-2023-52976: efi: fix potential NULL deref in efi_mem_reserve_persistentLINK ↗
692025-03-27CVE-2023-52988: ALSA: hda/via: Avoid potential array out-of-bound in add_secret_dac_path()LINK ↗
682025-03-06CVE-2024-58052: drm/amdgpu: Fix potential NULL pointer dereference in atomctrl_get_smc_sclk_range_tableLINK ↗
672025-02-27CVE-2025-21775: can: ctucanfd: handle skb allocation failureLINK ↗
662025-02-27CVE-2025-21736: nilfs2: fix possible int overflows in nilfs_fiemap()LINK ↗
652025-02-27CVE-2024-58009: Bluetooth: L2CAP: handle NULL sock pointer in l2cap_sock_allocLINK ↗
642025-02-27CVE-2024-58014: wifi: brcmsmac: add gain range check to wlc_phy_iqcal_gainparams_nphy()LINK ↗
632025-02-26CVE-2022-49731: ata: libata-core: fix NULL pointer deref in ata_host_alloc_pinfo()LINK ↗
622025-02-26CVE-2022-49267: mmc: core: use sysfs_emit() instead of sprintf()LINK ↗
612025-01-31CVE-2025-21680: pktgen: Avoid out-of-bounds access in get_imix_entriesLINK ↗
602024-11-09CVE-2024-50215: nvmet-auth: assign dh_key to NULL after kfree_sensitiveLINK ↗
592024-11-08CVE-2024-50205: ALSA: firewire-lib: Avoid division by zero in apply_constraint_to_size()LINK ↗
582024-11-08CVE-2024-50180: fbdev: sisfb: Fix strbuf array overflowLINK ↗
572024-11-07CVE-2024-50160: ALSA: hda/cs8409: Fix possible NULL dereferenceLINK ↗
562024-11-07CVE-2024-50145: octeon_ep: Add SKB allocation failures handling in __octep_oq_process_rx()LINK ↗
552024-10-21CVE-2022-49019: net: ethernet: nixge: fix NULL dereferenceLINK ↗
542024-10-21CVE-2024-50009: cpufreq: amd-pstate: add check for cpufreq_cpu_get's return valueLINK ↗
532024-10-21CVE-2024-50000: net/mlx5e: Fix NULL deref in mlx5e_tir_builder_alloc()LINK ↗
522024-10-21CVE-2024-47751: PCI: kirin: Fix buffer overflow in kirin_pcie_parse_port()LINK ↗
512024-10-21CVE-2024-47749: RDMA/cxgb4: Added NULL check for lookup_atidLINK ↗
502024-10-21CVE-2024-47743: KEYS: prevent NULL pointer dereference in find_asymmetric_key()LINK ↗
492024-10-09CVE-2024-47663: staging: iio: frequency: ad9834: Validate frequency parameter valueLINK ↗
482024-09-13CVE-2024-46676: nfc: pn533: Add poll mod list filling checkLINK ↗
472024-08-21CVE-2024-43877: media: pci: ivtv: Add check for DMA map resultLINK ↗
462024-08-17CVE-2024-43860: remoteproc: imx_rproc: Skip over memory region when node value is NULLLINK ↗
452024-08-17CVE-2024-43842: wifi: rtw89: Fix array index mistake in rtw89_sta_info_get_iter()LINK ↗
442024-08-17CVE-2024-43839: bna: adjust 'name' buf size of bna_tcb and bna_ccb structuresLINK ↗
432024-08-17CVE-2024-43823: PCI: keystone: Fix NULL pointer dereference in case of DT error in ks_pcie_setup_rc_app_regs()LINK ↗
422024-08-17CVE-2024-43818: ASoC: amd: Adjust error handling in case of absent codec deviceLINK ↗
412024-08-17CVE-2024-42277: iommu: sprd: Avoid NULL deref in sprd_iommu_hw_enLINK ↗
402024-07-30CVE-2024-42138: mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI fileLINK ↗
392024-07-29CVE-2024-42092: gpio: davinci: Validate the obtained number of IRQsLINK ↗
382024-07-16CVE-2022-48863: mISDN: Fix memory leak in dsp_pipeline_build()LINK ↗
372024-07-12CVE-2024-40982: ssb: Fix potential NULL pointer dereference in ssb_device_uevent()LINK ↗
362024-07-12CVE-2024-40940: net/mlx5: Fix tainted pointer delete is case of flow rules creation failLINK ↗
352024-07-12CVE-2024-40939: net: wwan: iosm: Fix tainted pointer delete is case of region creation failLINK ↗
342024-07-12CVE-2024-40919: bnxt_en: Adjust logging of firmware messages in case of released token in __hwrm_send()LINK ↗
332024-07-12CVE-2024-39506: liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packetLINK ↗
322024-06-21CVE-2024-38637: greybus: lights: check return of get_channel_from_modeLINK ↗
312024-06-21CVE-2024-38622: drm/msm/dpu: Add callback function pointer check before its callLINK ↗
302024-06-19CVE-2024-38579: crypto: bcm - Fix pointer arithmeticLINK ↗
292024-06-19CVE-2024-38577: rcu-tasks: Fix show_rcu_tasks_trace_gp_kthread buffer overflowLINK ↗
282024-06-19CVE-2024-38576: rcu: Fix buffer overflow in print_cpu_stall_info()LINK ↗
272024-06-19CVE-2024-38573: cppc_cpufreq: Fix possible null pointer dereferenceLINK ↗
262024-06-19CVE-2024-38571: thermal/drivers/tsens: Fix null pointer dereferenceLINK ↗
252024-06-19CVE-2024-38546: drm: vc4: Fix possible null pointer dereferenceLINK ↗
242024-06-19CVE-2024-38550: ASoC: kirkwood: Fix potential NULL dereferenceLINK ↗
232024-06-18Re: CVE-2023-52685: pstore: ram_core: fix possible overflow in persistent_ram_init_ecc()LINK ↗
222024-05-28Re: CVE-2023-52685: pstore: ram_core: fix possible overflow in persistent_ram_init_ecc()LINK ↗
212024-05-21CVE-2023-52744: RDMA/irdma: Fix potential NULL-ptr-dereferenceLINK ↗
202024-05-21CVE-2022-48708: pinctrl: single: fix potential NULL dereferenceLINK ↗
192024-05-20CVE-2024-35992: phy: marvell: a3700-comphy: Fix out of bounds readLINK ↗
182024-05-19CVE-2024-35925: block: prevent division by zero in blk_rq_stat_sum()LINK ↗
172024-05-19CVE-2024-35922: fbmon: prevent division by zero in fb_videomode_from_videomode()LINK ↗
162024-05-19CVE-2024-35916: dma-buf: Fix NULL pointer dereference in sanitycheck()LINK ↗
152024-05-19CVE-2024-35891: net: phy: micrel: Fix potential null pointer dereferenceLINK ↗
142024-05-19CVE-2024-35878: of: module: prevent NULL pointer dereference in vsnprintf()LINK ↗
132024-05-17CVE-2023-52683: ACPI: LPIT: Avoid u32 multiplication overflowLINK ↗
122024-05-17CVE-2023-52693: ACPI: video: check for error while searching for backlight device parentLINK ↗
112024-05-17CVE-2023-52687: crypto: safexcel - Add error handling for dma_map_sg() callsLINK ↗
102024-05-17CVE-2023-52685: pstore: ram_core: fix possible overflow in persistent_ram_init_ecc()LINK ↗
92024-05-03CVE-2022-48672: of: fdt: fix off-by-one error in unflatten_dt_nodes()LINK ↗
82024-05-01CVE-2024-27051: cpufreq: brcmstb-avs-cpufreq: add check for cpufreq_cpu_get's return valueLINK ↗
72024-05-01CVE-2024-27041: drm/amd/display: fix NULL checks for adev->dm.dc in amdgpu_dm_fini()LINK ↗
62024-05-01CVE-2024-27008: drm: nv04: Fix out of bounds accessLINK ↗
52024-04-28CVE-2022-48657: arm64: topology: fix possible overflow in amu_fie_setup()LINK ↗
42024-04-03CVE-2024-26736: afs: Increase buffer size in afs_update_volume_status()LINK ↗
32024-04-03CVE-2024-26722: ASoC: rt5645: Fix deadlock in rt5645_jack_detect_work()LINK ↗
22024-03-02CVE-2023-52573: net: rds: Fix possible NULL-pointer dereferenceLINK ↗
12024-03-02CVE-2023-52512: pinctrl: nuvoton: wpcm450: fix out of bounds writeLINK ↗

Find Hidden Issues in Critical Software