Linux vendor intelligence
Linux Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Linux products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 28
- Known exploited vulnerabilities affecting Linux products
- In CISA KEV
- 27
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Linux KEVs with sensor-observed exploitation activity
The catalog gap matters for Linux exposure
One of the 28 exploited Linux CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 4% of this vendor portfolio.
- 96%
- Covered by CISA
- 4%
- Beyond CISA
- 7
- Product families
Attested Linux CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2022-0492
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain... |
kernel | Confirmed | In CISA | 02 Jun 2026 |
|
CVE-2026-31431
crypto: algif_aead - Revert to operating out-of-place |
Linux | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2018-14634
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise... |
kernel | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2021-22555
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE |
Linux Kernel | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-38352
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() |
Linux | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2023-0386
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux... |
Linux kernel | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2010-3081
The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly... |
Linux Kernel | High | Beyond CISA | 24 Sep 2010 |
|
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a... |
kernel | Confirmed | In CISA | 10 Dec 2021 |
|
CVE-2016-5195
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling... |
Linux Kernel | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2021-22600
Double Free in net/packet/af_packet.c leading to priviledge escalation |
Kernel | Confirmed | In CISA | 11 Apr 2022 |
|
CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and... |
kernel | Confirmed | In CISA | 25 Apr 2022 |
|
CVE-2014-3153
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses,... |
Linux Kernel | Confirmed | In CISA | 25 May 2022 |
|
CVE-2013-2094
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local... |
Linux Kernel | Confirmed | In CISA | 15 Sep 2022 |
|
CVE-2013-2596
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android... |
Linux Kernel | Confirmed | In CISA | 15 Sep 2022 |
|
CVE-2013-6282
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses,... |
Linux Kernel | Confirmed | In CISA | 15 Sep 2022 |
|
CVE-2023-0266
Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel |
Linux Kernel | Confirmed | In CISA | 30 Mar 2023 |
|
CVE-2010-3904
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36... |
Linux Kernel | Confirmed | In CISA | 12 May 2023 |
|
CVE-2014-0196
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO &... |
kernel | Confirmed | In CISA | 12 May 2023 |
|
CVE-2021-3560
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the... |
polkit | Confirmed | In CISA | 12 May 2023 |
|
CVE-2024-1086
Use-after-free in Linux kernel's netfilter: nf_tables component |
Kernel | Confirmed | In CISA | 30 May 2024 |
|
CVE-2022-2586
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table... |
linux | Confirmed | In CISA | 26 Jun 2024 |
|
CVE-2024-36971
net: fix __dst_negative_advice() race |
Linux | Confirmed | In CISA | 07 Aug 2024 |
|
CVE-2022-0185
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel... |
kernel | Confirmed | In CISA | 21 Aug 2024 |
|
CVE-2017-1000253
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86... |
Kernel | Confirmed | In CISA | 09 Sep 2024 |
|
CVE-2024-53104
media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format |
Linux | Confirmed | In CISA | 05 Feb 2025 |
|
CVE-2024-50302
HID: core: zero-initialize the report buffer |
Linux | Confirmed | In CISA | 04 Mar 2025 |
|
CVE-2024-53197
ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices |
Linux | Confirmed | In CISA | 09 Apr 2025 |
|
CVE-2024-53150
ALSA: usb-audio: Fix out of bounds reads when finding clock sources |
Linux | Confirmed | In CISA | 09 Apr 2025 |
No Linux CVEs match this search or filter.
Showing 28 of 28 Linux known exploited vulnerabilities.
Recurring weakness patterns
Use after free, out-of-bounds write, and integer overflow or wraparound account for ten mapped occurrences across this Linux KEV portfolio.
CWE-416
Use After Free
CWE-787
Out-of-bounds Write
CWE-190
Integer Overflow or Wraparound
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-20
Improper Input Validation
CWE-1284
Improper Validation of Specified Quantity in Input
CWE-189
Numeric Errors
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.