kernel records
22 published records for vendor kernel.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 95.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-552 Files or Directories Accessible to External Parties2
- CWE-189 Numeric Errors1
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-252 Unchecked Return Value1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2015-5224No exploit | The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly okernel · util-linux · CWE-377 | Critical9.8 | — | 4.5% | Aug 23, 2017 |
32Monitor | CVE-2018-17953No exploit | pam_access does not handle netmask matches correctlyopensuse · leap · CWE-284 | High8.1 | — | 1.3% | Nov 27, 2018 |
31Monitor | CVE-2014-9114No exploit | Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.opensuse · opensuse · CWE-77 | High7.8 | — | 0.6% | Mar 31, 2017 |
31Monitor | CVE-2018-7738No exploit | In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint namekernel · util-linux | High7.8 | — | 0.4% | Mar 6, 2018 |
31Monitor | CVE-2016-2779No exploit | runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the tekernel · util-linux · CWE-264 | High7.8 | — | 0.4% | Feb 7, 2017 |
28Monitor | CVE-2007-5191No exploit | mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return valueskernel · util-linux · CWE-252 | High7.2 | — | 0.4% | Oct 4, 2007 |
26Monitor | CVE-2020-21583No exploit | An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parametkernel · util-linux · CWE-78 | Medium6.7 | — | 0.5% | Aug 22, 2023 |
24Monitor | CVE-2020-10751No exploit | A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would onlkernel · selinux · CWE-349 | Medium6.1 | — | 0.3% | May 26, 2020 |
22Monitor | CVE-2021-37600No exploit | An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources inkernel · util-linux · CWE-190 | Medium5.5 | — | 0.7% | Jul 30, 2021 |
22Monitor | CVE-2021-3996No exploit | A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem.kernel · util-linux · CWE-552 | Medium5.5 | — | 0.6% | Aug 23, 2022 |
22Monitor | CVE-2021-3995No exploit | A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem.kernel · util-linux · CWE-552 | Medium5.5 | — | 0.6% | Aug 23, 2022 |
22Monitor | CVE-2001-1494No exploit | script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescrkernel · util-linux · CWE-59 | Medium5.5 | — | 0.4% | Dec 31, 2001 |
22Monitor | CVE-2022-0563No exploit | A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support.kernel · util-linux · CWE-209 | Medium5.5 | — | 0.4% | Feb 21, 2022 |
21Monitor | CVE-2026-3184No exploit | Util-linux: util-linux: access control bypass due to improper hostname canonicalizationkernel · util-linux · CWE-289 | Medium5.3 | — | 0.6% | Apr 3, 2026 |
21Monitor | CVE-2026-13595No exploit | Util-linux: util-linux: heap use-after-free in libblkid nested partition probingredhat · hardened images · CWE-416 | Medium5.3 | — | 0.2% | Jun 29, 2026 |
19Monitor | CVE-2009-3288No exploit | The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect variable when accessing kernel · linux kernel · CWE-119 | Medium4.9 | — | 0.4% | Sep 22, 2009 |
19Monitor | CVE-2007-6712No exploit | Integer overflow in the hrtimer_forward function (hrtimer.c) in Linux kernel 2.6.21-rc4, when running on 64-bit systems, allows local users kernel · linux kernel · CWE-189 | Medium4.9 | — | 0.4% | Apr 12, 2008 |
18Monitor | CVE-2016-5011No exploit | The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a dkernel · util-linux | Medium4.6 | — | 0.5% | Apr 11, 2017 |
18Monitor | CVE-2026-27456No exploit | util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setupkernel · util-linux · CWE-59 | Medium4.7 | — | 0.1% | Apr 3, 2026 |
14Monitor | CVE-2024-28085Proof of concept | wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals tkernel · util-linux · CWE-150 | Low3.3 | — | 2.2% | Mar 27, 2024 |
8Monitor | CVE-2015-5218No exploit | Buffer overflow in text-utils/colcrt.c in colcrt in util-linux before 2.27 allows local users to cause a denial of service (crash) via a crakernel · util-linux · CWE-119 | Low2.1 | — | 0.6% | Nov 9, 2015 |
8Monitor | CVE-2013-0157No exploit | (a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restrictekernel · util-linux · CWE-200 | Low2.1 | — | 0.4% | Jan 21, 2014 |
- CVE-2015-522440Plan
The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly o
CriticalCVSS 9.8No exploitEPSS 5%kernel · util-linuxAug 23, 2017
- CVE-2018-1795332Monitor
pam_access does not handle netmask matches correctly
HighCVSS 8.1No exploitEPSS 1%opensuse · leapNov 27, 2018
- CVE-2014-911431Monitor
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
HighCVSS 7.8No exploitEPSS 1%opensuse · opensuseMar 31, 2017
- CVE-2018-773831Monitor
In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name
HighCVSS 7.8No exploitEPSS 0%kernel · util-linuxMar 6, 2018
- CVE-2016-277931Monitor
runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the te
HighCVSS 7.8No exploitEPSS 0%kernel · util-linuxFeb 7, 2017
- CVE-2007-519128Monitor
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values
HighCVSS 7.2No exploitEPSS 0%kernel · util-linuxOct 4, 2007
- CVE-2020-2158326Monitor
An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path paramet
MediumCVSS 6.7No exploitEPSS 1%kernel · util-linuxAug 22, 2023
- CVE-2020-1075124Monitor
A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would onl
MediumCVSS 6.1No exploitEPSS 0%kernel · selinuxMay 26, 2020
- CVE-2021-3760022Monitor
An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in
MediumCVSS 5.5No exploitEPSS 1%kernel · util-linuxJul 30, 2021
- CVE-2021-399622Monitor
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem.
MediumCVSS 5.5No exploitEPSS 1%kernel · util-linuxAug 23, 2022
- CVE-2021-399522Monitor
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem.
MediumCVSS 5.5No exploitEPSS 1%kernel · util-linuxAug 23, 2022
- CVE-2001-149422Monitor
script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescr
MediumCVSS 5.5No exploitEPSS 0%kernel · util-linuxDec 31, 2001
- CVE-2022-056322Monitor
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support.
MediumCVSS 5.5No exploitEPSS 0%kernel · util-linuxFeb 21, 2022
- CVE-2026-318421Monitor
Util-linux: util-linux: access control bypass due to improper hostname canonicalization
MediumCVSS 5.3No exploitEPSS 1%kernel · util-linuxApr 3, 2026
- CVE-2026-1359521Monitor
Util-linux: util-linux: heap use-after-free in libblkid nested partition probing
MediumCVSS 5.3No exploitEPSS 0%redhat · hardened imagesJun 29, 2026
- CVE-2009-328819Monitor
The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect variable when accessing
MediumCVSS 4.9No exploitEPSS 0%kernel · linux kernelSep 22, 2009
- CVE-2007-671219Monitor
Integer overflow in the hrtimer_forward function (hrtimer.c) in Linux kernel 2.6.21-rc4, when running on 64-bit systems, allows local users
MediumCVSS 4.9No exploitEPSS 0%kernel · linux kernelApr 12, 2008
- CVE-2016-501118Monitor
The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a d
MediumCVSS 4.6No exploitEPSS 0%kernel · util-linuxApr 11, 2017
- CVE-2026-2745618Monitor
util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup
MediumCVSS 4.7No exploitEPSS 0%kernel · util-linuxApr 3, 2026
- CVE-2024-2808514Monitor
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals t
LowCVSS 3.3Proof of conceptEPSS 2%kernel · util-linuxMar 27, 2024
- CVE-2015-52188Monitor
Buffer overflow in text-utils/colcrt.c in colcrt in util-linux before 2.27 allows local users to cause a denial of service (crash) via a cra
LowCVSS 2.1No exploitEPSS 1%kernel · util-linuxNov 9, 2015
- CVE-2013-01578Monitor
(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricte
LowCVSS 2.1No exploitEPSS 0%kernel · util-linuxJan 21, 2014