Linux vendor intelligence

Linux Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Linux products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse Linux KEVs Full KEV feed
Total KEVs
28
Known exploited vulnerabilities affecting Linux products
In CISA KEV
27
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
Linux KEVs with sensor-observed exploitation activity

The catalog gap matters for Linux exposure

One of the 28 exploited Linux CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 4% of this vendor portfolio.

96%
Covered by CISA
4%
Beyond CISA
7
Product families

Attested Linux CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2022-0492

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain...

kernel Confirmed In CISA 02 Jun 2026
CVE-2026-31431

crypto: algif_aead - Revert to operating out-of-place

Linux Confirmed In CISA 01 Jun 2026
CVE-2018-14634

An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise...

kernel Confirmed In CISA 01 Jun 2026
CVE-2021-22555

Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE

Linux Kernel Confirmed In CISA 01 Jun 2026
CVE-2025-38352

posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()

Linux Confirmed In CISA 01 Jun 2026
CVE-2023-0386

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux...

Linux kernel Confirmed In CISA 01 Jun 2026
CVE-2010-3081

The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly...

Linux Kernel High Beyond CISA 24 Sep 2010
CVE-2019-13272

In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a...

kernel Confirmed In CISA 10 Dec 2021
CVE-2016-5195

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling...

Linux Kernel Confirmed In CISA 03 Mar 2022
CVE-2021-22600

Double Free in net/packet/af_packet.c leading to priviledge escalation

Kernel Confirmed In CISA 11 Apr 2022
CVE-2022-0847

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and...

kernel Confirmed In CISA 25 Apr 2022
CVE-2014-3153

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses,...

Linux Kernel Confirmed In CISA 25 May 2022
CVE-2013-2094

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local...

Linux Kernel Confirmed In CISA 15 Sep 2022
CVE-2013-2596

Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android...

Linux Kernel Confirmed In CISA 15 Sep 2022
CVE-2013-6282

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses,...

Linux Kernel Confirmed In CISA 15 Sep 2022
CVE-2023-0266

Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel

Linux Kernel Confirmed In CISA 30 Mar 2023
CVE-2010-3904

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36...

Linux Kernel Confirmed In CISA 12 May 2023
CVE-2014-0196

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO &...

kernel Confirmed In CISA 12 May 2023
CVE-2021-3560

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the...

polkit Confirmed In CISA 12 May 2023
CVE-2024-1086

Use-after-free in Linux kernel's netfilter: nf_tables component

Kernel Confirmed In CISA 30 May 2024
CVE-2022-2586

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table...

linux Confirmed In CISA 26 Jun 2024
CVE-2024-36971

net: fix __dst_negative_advice() race

Linux Confirmed In CISA 07 Aug 2024
CVE-2022-0185

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel...

kernel Confirmed In CISA 21 Aug 2024
CVE-2017-1000253

Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86...

Kernel Confirmed In CISA 09 Sep 2024
CVE-2024-53104

media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format

Linux Confirmed In CISA 05 Feb 2025
CVE-2024-50302

HID: core: zero-initialize the report buffer

Linux Confirmed In CISA 04 Mar 2025
CVE-2024-53197

ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices

Linux Confirmed In CISA 09 Apr 2025
CVE-2024-53150

ALSA: usb-audio: Fix out of bounds reads when finding clock sources

Linux Confirmed In CISA 09 Apr 2025

Showing 28 of 28 Linux known exploited vulnerabilities.

Recurring weakness patterns

Use after free, out-of-bounds write, and integer overflow or wraparound account for ten mapped occurrences across this Linux KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.