VulnSea

CWE-476

CVEs classified under CWE-476, newest first.

373 CVEsRSS

CVE-2026-80992Medium· 5.5⚖ disputed
2w ago

kernel: net: ravb: avoid dereferencing an invalid PTP clock (CVE-2026-80992)

A flaw was found in the `net: ravb` component of the Linux kernel. This vulnerability allows for a NULL pointer dereference when the Precision Time Protocol (PTP) clock's index is queried before it is properly initialized or if its registr…

▾ SunlitRed Hat · LinuxEPSS 0.18%via CSAF
CVE-2026-80984Medium· 5.5
2w ago

kernel: net/smc: do not dereference an unset send buffer on the SMC-D teardown path (CVE-2026-80984)

A flaw was found in the `net/smc` component of the Linux kernel. When a link group terminates while a socket is waiting in `smc_close_stream_wait()`, a NULL pointer dereference can occur during the SMC-D teardown path. This can lead to a s…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89477High· 7.0
2w ago

kernel: sctp: fix NULL deref on untransmitted RECONF completion (CVE-2026-89477)

A flaw was found in the Stream Control Transmission Protocol (SCTP) implementation within the Linux kernel. This vulnerability occurs when the kernel attempts to complete a stream reconfiguration request that has not been fully transmitted…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.72%via CSAF
CVE-2026-89460Medium· 4.4
2w ago

kernel: s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks (CVE-2026-89460)

A flaw was found in the Linux kernel. A local user can trigger a kernel panic by running the `perf stat` command while CPUs are being hotplugged. This occurs because the system fails to properly allocate CPU event structures for newly onli…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89457Medium· 5.5
2w ago

kernel: s390/dasd: Guard sysfs discipline callbacks against unallocated private data (CVE-2026-89457)

A flaw was found in the s390/dasd component of the Linux kernel. An unprivileged local user can trigger a null pointer dereference by reading specific world-readable sysfs attributes while the device is being brought online. This can lead …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-89442Medium· 5.5⚖ disputed
2w ago

kernel: platform/x86: ISST: Validate socket ID in clos_assoc ioctl (CVE-2026-89442)

A flaw was found in the Linux kernel. The isst_if_clos_assoc ioctl function in the platform/x86: ISST module contains an improper validation of the socket_id. This allows a local attacker to cause an out-of-bounds access or a NULL pointer …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89547High· 7.0
2w ago

kernel: SUNRPC: Check svc pool percpu counter allocation (CVE-2026-89547)

A flaw was found in the Linux kernel's SUNRPC component. A local administrator, under specific conditions of memory pressure or fault injection during RPC server startup, can trigger a failure in per-CPU counter allocation. This failure le…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.57%via CSAF
CVE-2026-89511Medium· 5.5⚖ disputed
2w ago

kernel: qede: Fix NULL pointer dereference in TPA fragment processing (CVE-2026-89511)

A flaw was found in the qede driver in the Linux kernel. Under specific memory pressure conditions, the driver can encounter a NULL pointer dereference when processing network traffic using TPA (TCP Segmentation Offload) continuation fragm…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.72%via CSAF
CVE-2026-89662High· 7.0⚖ disputed
2w ago

kernel: NFSD: Prevent lock owner use-after-free during client teardown (CVE-2026-89662)

A flaw was found in the Linux kernel's Network File System Daemon (NFSD). During client teardown, a race condition can occur where a lock owner is freed while still being referenced, leading to a use-after-free vulnerability. This can resu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.73%via CSAF
CVE-2026-89696Medium· 5.5⚖ disputed
2w ago

kernel: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref (CVE-2026-89696)

A flaw was found in the Linux kernel's Network File System (NFS) daemon (nfsd). A remote client can exploit this by sending a specially crafted NFS COMPOUND request. This request, when processed, can lead to a NULL pointer dereference in t…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-89749Medium· 5.5
2w ago

kernel: tracing: Fix crash passing ERR_PTR to kthread_stop() (CVE-2026-89749)

A flaw was found in the Linux kernel. Specifically, within the tracing subsystem, the `event_test_stuff()` function can pass an invalid error pointer to `kthread_stop()` if `kthread_run()` fails to create a kernel thread. This improper han…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-89506Medium· 4.7
2w ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR The original commit missed that three drivers (mthca, irdma, siw) have UHW data associated with reg_mr that ca…

In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR The original commit missed that three drivers (mthca, irdma, siw) have UHW data associated with reg_mr that ca…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-78130High· 7.5
2w ago

strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

▾ Twilightstrongswan · strongswanEPSS 0.32%via NVD
CVE-2026-89517Medium· 5.5
2w ago

kernel: sched_ext: Fix rq->core_pick corruption under core scheduling (CVE-2026-89517)

A flaw was found in the Linux kernel's `sched_ext` component, which handles core scheduling. When multiple selections on the same core interleave due to a dropped lock, they can corrupt the scheduling state. This corruption can lead to a N…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.20%via CSAF
CVE-2026-89509Medium· 5.5
2w ago

kernel: RDMA/ionic: Embed counter driver data in rdma_counter allocation (CVE-2026-89509)

A flaw was found in the Linux kernel's RDMA/ionic driver. This vulnerability arises from the driver's incorrect handling of `rdma_counter` allocations, specifically by not embedding counter driver data as required. This oversight can lead …

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89592Medium· 5.5
2w ago

kernel: accel/rocket: fix NULL dereference and integer overflow in rocket_job_push() (CVE-2026-89592)

A flaw was found in the `accel/rocket` component of the Linux kernel. This vulnerability arises from two issues: a missing null check after a memory allocation failure and an integer overflow when calculating memory requirements based on u…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89591Medium· 5.5
2w ago

kernel: accel/rocket: initialize job domain before cleanup paths (CVE-2026-89591)

A flaw was found in the Linux kernel's `accel/rocket` module. During error handling in the `rocket_ioctl_submit_job()` function, a cleanup routine may attempt to free a `job->domain` pointer that has not yet been initialized, leading to a …

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89552Medium· 4.1
2w ago

kernel: Linux kernel: Denial of Service via NULL pointer dereference in parameter handling (CVE-2026-89552)

A flaw was found in the Linux kernel. When updating charp parameters, an allocation failure can cause the parameter to be set to NULL before the new value is successfully allocated. This can lead to a kernel NULL pointer dereference, which…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89734Medium· 5.5
2w ago

kernel: usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init() (CVE-2026-89734)

A flaw was found in the Linux kernel's USB Video Class (UVC) gadget driver. This vulnerability occurs in the `uvcg_video_init()` function when the `kthread_run_worker()` function fails. In such a scenario, an error logging mechanism attemp…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89717Medium· 4.7
2w ago

In the Linux kernel, the following vulnerability has been resolved: zram: set default primary compressor in zram_destroy_comps() Patch series "zram: fix zram issues reported by sashiko". Sashiko drove by and reported [1] a couple of z…

In the Linux kernel, the following vulnerability has been resolved: zram: set default primary compressor in zram_destroy_comps() Patch series "zram: fix zram issues reported by sashiko". Sashiko drove by and reported [1] a couple of z…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-89770Medium· 5.5
2w ago

kernel: iomap: don't free integrity payload that doesn't exist (CVE-2026-89770)

A flaw was found in the `iomap` component of the Linux kernel. This vulnerability occurs when Protection Information (PI) verification is disabled on a block device, causing `fs_bio_integrity_alloc` to not allocate a bio integrity payload.…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.20%via CSAF
CVE-2026-89451Medium· 5.5
2w ago

kernel: iommu/sva: Set handle->dev before the SVA handle is visible (CVE-2026-89451)

A flaw was found in the Linux kernel's IOMMU (Input/Output Memory Management Unit) SVA (Shared Virtual Addressing) component. A race condition during the attachment of an SVA handle can lead to a situation where a device pointer is not pro…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89439Medium· 5.5
2w ago

kernel: platform/x86: ISST: Add a NULL check for sst_inst[] (CVE-2026-89439)

A flaw was found in the Linux kernel's Intel Speed Select Technology (ISST) driver. A missing NULL check for `isst_common.sst_inst[]` during failed socket loading could allow a local attacker to trigger a NULL pointer dereference. This vul…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-80993Medium· 5.5
2w ago

kernel: net: phylink: correctly validate returned PCS in phylink_inband_caps (CVE-2026-80993)

A flaw was found in the Linux kernel's `net: phylink` component. The `phylink_inband_caps()` function does not correctly validate the return value from `mac_select_pcs`, which can return an error pointer instead of a valid Physical Coding …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89484Medium· 5.5
2w ago

kernel: lockd: fix NULL dereference on lockowner allocation failure (CVE-2026-89484)

A flaw was found in the Linux kernel's `lockd` component. This vulnerability occurs when the Network Lock Manager (NLM) client attempts to initialize file lock operations without successfully allocating a lockowner. This can lead to a NULL…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-78126Medium· 5.9
2w ago

strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.

strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.

▾ Sunlitstrongswan · strongswanEPSS 0.41%via NVD
CVE-2026-79590Medium· 6.5PoC
2w ago

A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0

A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functio…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-45747High· 7.5PoC
2w ago

Suricata lua/tls: null dereference in TlsGetCertInfo

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lu…

▾ MidnightOISF · suricataEPSS 0.39%via CVEORG
CVE-2026-86547Medium· 6.2PoC
2w ago

mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode

mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode. Attackers can craft malicious .mrb bytecode files with OP_ENTER instructions at the top leve…

▾ Twilightmrubyc · mrubycEPSS 0.18%via NVD
CVE-2026-66303Medium· 6.5
2w ago

Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

▾ Sunlitmicrosoft · skype_for_business_serverEPSS 1.1%via NVD
CWE-476 vulnerabilities (CVEs) — page 3 · VulnSea