Skip to content
COOEY

FAIL › dossier

linux

VENDOR

· dossier confidence 20%

Linux, an open-source operating system, has faced multiple security vulnerabilities, many of which have been addressed through timely patches. The system's strong community-driven approach to vulnerability management has generally led to a robust security posture.

PROFILE
CategorysoftwareWhat they doLinux is an open-source operating system developed by Linus Torvalds and the Linux kernel community. It is designed to be free, modular, and POSIX-compliant. Websitehttps://www.kernel.org/ ↗
SECURITY POSTURE

Linux has a strong track record of addressing security vulnerabilities through timely patching and community-driven vulnerability management.

Notable failures
  • CVE-2017-1000253
  • CVE-2024-1086
  • CVE-2018-14634
  • CVE-2022-0492
  • CVE-2025-04097
  • CVE-2025-38352
  • CVE-2025-0617
  • CVE-2025-0205
  • CVE-2024-53150
  • CVE-2024-50302
  • CVE-2025-0904
  • CVE-2025-0626
  • CVE-2025-0303
  • CVE-2025-0266
  • CVE-2022-1022
  • CVE-2022-36536
  • CVE-2026-13020
  • CVE-2026-13448
  • CVE-2026-10972
  • CVE-2026-9874
  • CVE-2026-8856
  • CVE-2026-8855
  • CVE-2026-8673
Patterns: repeated unpatched edge-device RCEs; buffer overflow vulnerabilities; use-after-free vulnerabilities; race conditions; insufficient input validation
FAILURE HISTORY · 49
DATEEVENTSEVSUMMARY
2022-10-20 CVE-2021-3493 high Linux Kernel unpatched for privilege escalation
2024-09-09 CVE-2017-1000253 critical A local attacker can escalate privileges via a PIE stack buffer corruption vulnerability in the Linux kernel's load_elf_ binary() function.
2024-08-21 CVE-2022-0185 high Linux kernel heap-based buffer overflow in legacy_parse_param allows privilege escalation via unsupported filesystems.
2024-05-30 CVE-2024-1086 critical A use-after-free vulnerability in the Linux kernel's netfilter component allows local privilege escalation and has been actively exploited in the wild.
2022-04-25 CVE-2022-0847 high An unprivileged local user could escalate privileges on Linux systems via the 'Dirty Pipe' improper initialization vulnerability.
2026-08-26 CVE-2022-0995 high A local privilege escalation vulnerability in the Linux kernel was actively exploited in the wild, allowing attackers to gain root access or cause denial of service.
2021-12-10 CVE-2019-13272 high A local privilege escalation flaw in the Linux kernel allowed unprivileged users to gain root access via improper ptrace handling.
2026-08-27 CVE-2026-53362 high A Linux kernel vulnerability allows privilege escalation via the IPv6 networking subsystem, impacting multiple distributions including Suse and Red Hat.
2022-03-03 CVE-2016-5195 high A local privilege escalation vulnerability in the Linux kernel was actively exploited in the wild, allowing attackers to escalate privileges on unpatched systems.
2026-01-26 CVE-2018-14634 high Linux Kernel CVE-2018-14634 exploited for privilege escalation
2025-10-06 CVE-2021-22555 high Linux Kernel Heap Out-of-Bounds Write Vulnerability actively exploited
2025-09-04 CVE-2025-38352 high Linux Kernel TOCTOU race condition actively exploited
2025-06-17 CVE-2023-0386 high Linux Kernel escalation flaw exploited
2025-04-09 CVE-2024-53197 high A recently exploited Linux kernel vulnerability allows attackers with physical access to manipulate memory or execute code via a malicious USB device.
2023-05-12 CVE-2010-3904 high Linux Kernel RDS protocol vulnerability allows local privilege escalation.
2023-05-12 CVE-2014-0196 high Linux Kernel Race Condition Vulnerability allows local users to gain privileges.
2023-03-30 CVE-2023-0266 high Linux Kernel Use-After-Free Vulnerability exploited in wild
2022-09-15 CVE-2013-2094 high Linux Kernel CVE-2013-2094 allowed unauthorized escalation
2022-09-15 CVE-2013-6282 high Linux Kernel CVE-2013-6282 exposed to active exploitation on ARM v6k/v7, enabling unauthorized memory access and privilege escalation.
2022-09-15 CVE-2013-2596 high Linux Kernel CVE-2013-2596 allowed unauthorized escalation
2026-06-02 CVE-2022-0492 high Linux kernel privilege escalation via cgroups v1 release_agent was actively exploited in the wild.
2022-05-25 CVE-2014-3153 high A local privilege escalation flaw in the Linux kernel's futex_requeue function allowed attackers to escalate privileges without remote access.
2022-04-11 CVE-2021-22600 high A local user could exploit a Linux kernel packet socket flaw for denial-of-service or privilege escalation.
2025-04-09 CVE-2024-53150 high A recently exploited Linux kernel vulnerability allows local attackers to read sensitive information via the USB-audio driver.
2025-03-04 CVE-2024-50302 high A Linux kernel vulnerability allows attackers to leak kernel memory via crafted HID reports, and is currently being exploited in the wild.
2025-02-05 CVE-2024-53104 high A recently exploited Linux kernel vulnerability allows for privilege escalation via an out-of-bounds write in the UVC driver.
2026-05-01 CVE-2026-31431 high Linux kernel vulnerability CVE-2026-31431 enables privilege escalation via incorrect resource transfer between spheres.
2024-06-26 CVE-2022-2586 high Linux kernel use-after-free vulnerability in nft_object allows local privilege escalation.
2026-07-06 CVE-2026-9182 medium ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload.
2026-06-30 CVE-2026-13775 critical Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
2026-06-30 CVE-2026-13782 critical Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
2026-06-30 CVE-2026-13781 critical Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
2026-06-30 CVE-2026-13780 critical Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
2026-06-30 CVE-2026-13776 critical Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
2022-09-16 CVE-2022-36536 critical An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.
2026-07-07 CVE-2026-13020 high A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators sh
2026-07-17 CVE-2026-13448 high CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re
2026-07-14 CVE-2026-47304 high CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized
2026-06-09 CVE-2026-34691 critical CVE-2026-34691: Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are af
2026-06-04 CVE-2026-10972 critical CVE-2026-10972: Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed
2026-05-28 CVE-2026-9874 critical CVE-2026-9874: Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote
2026-05-26 CVE-2026-8856 high CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration
2026-05-26 CVE-2026-8855 high CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o
2026-05-26 CVE-2026-24212 high CVE-2026-24212: NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive infor
2026-05-22 CVE-2026-8673 medium CVE-2026-8673: Unprotected transport of credentials vulnerability in syslink software AG Avantr
2026-05-20 CVE-2026-24206 high CVE-2026-24206: NVIDIA Triton Inference Server contains a vulnerability where an attacker could
2026-04-03 CVE-2026-35561 high CVE-2026-35561: Insufficient authentication security controls in the browser-based authenticatio
2024-08-08 CVE-2024-42256 high CVE-2024-42256: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix s
2016-04-07 CVE-2016-1019 critical CVE-2016-1019: Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a den
Open questions: How effective are the security practices of the Linux kernel community in addressing vulnerabilities? · What is the overall impact of these vulnerabilities on the security of Linux-based systems?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-24 03:40:33.094558+00:00