FAIL › dossier
linux
VENDOR· dossier confidence 20%
Linux, an open-source operating system, has faced multiple security vulnerabilities, many of which have been addressed through timely patches. The system's strong community-driven approach to vulnerability management has generally led to a robust security posture.
PROFILE
CategorysoftwareWhat they doLinux is an open-source operating system developed by Linus Torvalds and the Linux kernel community. It is designed to be free, modular, and POSIX-compliant.
Websitehttps://www.kernel.org/ ↗
SECURITY POSTURE
Linux has a strong track record of addressing security vulnerabilities through timely patching and community-driven vulnerability management.
Notable failures
- CVE-2017-1000253
- CVE-2024-1086
- CVE-2018-14634
- CVE-2022-0492
- CVE-2025-04097
- CVE-2025-38352
- CVE-2025-0617
- CVE-2025-0205
- CVE-2024-53150
- CVE-2024-50302
- CVE-2025-0904
- CVE-2025-0626
- CVE-2025-0303
- CVE-2025-0266
- CVE-2022-1022
- CVE-2022-36536
- CVE-2026-13020
- CVE-2026-13448
- CVE-2026-10972
- CVE-2026-9874
- CVE-2026-8856
- CVE-2026-8855
- CVE-2026-8673
Patterns: repeated unpatched edge-device RCEs; buffer overflow vulnerabilities; use-after-free vulnerabilities; race conditions; insufficient input validation
FAILURE HISTORY · 49
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-10-20 | CVE-2021-3493 | high | Linux Kernel unpatched for privilege escalation |
| 2024-09-09 | CVE-2017-1000253 | critical | A local attacker can escalate privileges via a PIE stack buffer corruption vulnerability in the Linux kernel's load_elf_ binary() function. |
| 2024-08-21 | CVE-2022-0185 | high | Linux kernel heap-based buffer overflow in legacy_parse_param allows privilege escalation via unsupported filesystems. |
| 2024-05-30 | CVE-2024-1086 | critical | A use-after-free vulnerability in the Linux kernel's netfilter component allows local privilege escalation and has been actively exploited in the wild. |
| 2022-04-25 | CVE-2022-0847 | high | An unprivileged local user could escalate privileges on Linux systems via the 'Dirty Pipe' improper initialization vulnerability. |
| 2026-08-26 | CVE-2022-0995 | high | A local privilege escalation vulnerability in the Linux kernel was actively exploited in the wild, allowing attackers to gain root access or cause denial of service. |
| 2021-12-10 | CVE-2019-13272 | high | A local privilege escalation flaw in the Linux kernel allowed unprivileged users to gain root access via improper ptrace handling. |
| 2026-08-27 | CVE-2026-53362 | high | A Linux kernel vulnerability allows privilege escalation via the IPv6 networking subsystem, impacting multiple distributions including Suse and Red Hat. |
| 2022-03-03 | CVE-2016-5195 | high | A local privilege escalation vulnerability in the Linux kernel was actively exploited in the wild, allowing attackers to escalate privileges on unpatched systems. |
| 2026-01-26 | CVE-2018-14634 | high | Linux Kernel CVE-2018-14634 exploited for privilege escalation |
| 2025-10-06 | CVE-2021-22555 | high | Linux Kernel Heap Out-of-Bounds Write Vulnerability actively exploited |
| 2025-09-04 | CVE-2025-38352 | high | Linux Kernel TOCTOU race condition actively exploited |
| 2025-06-17 | CVE-2023-0386 | high | Linux Kernel escalation flaw exploited |
| 2025-04-09 | CVE-2024-53197 | high | A recently exploited Linux kernel vulnerability allows attackers with physical access to manipulate memory or execute code via a malicious USB device. |
| 2023-05-12 | CVE-2010-3904 | high | Linux Kernel RDS protocol vulnerability allows local privilege escalation. |
| 2023-05-12 | CVE-2014-0196 | high | Linux Kernel Race Condition Vulnerability allows local users to gain privileges. |
| 2023-03-30 | CVE-2023-0266 | high | Linux Kernel Use-After-Free Vulnerability exploited in wild |
| 2022-09-15 | CVE-2013-2094 | high | Linux Kernel CVE-2013-2094 allowed unauthorized escalation |
| 2022-09-15 | CVE-2013-6282 | high | Linux Kernel CVE-2013-6282 exposed to active exploitation on ARM v6k/v7, enabling unauthorized memory access and privilege escalation. |
| 2022-09-15 | CVE-2013-2596 | high | Linux Kernel CVE-2013-2596 allowed unauthorized escalation |
| 2026-06-02 | CVE-2022-0492 | high | Linux kernel privilege escalation via cgroups v1 release_agent was actively exploited in the wild. |
| 2022-05-25 | CVE-2014-3153 | high | A local privilege escalation flaw in the Linux kernel's futex_requeue function allowed attackers to escalate privileges without remote access. |
| 2022-04-11 | CVE-2021-22600 | high | A local user could exploit a Linux kernel packet socket flaw for denial-of-service or privilege escalation. |
| 2025-04-09 | CVE-2024-53150 | high | A recently exploited Linux kernel vulnerability allows local attackers to read sensitive information via the USB-audio driver. |
| 2025-03-04 | CVE-2024-50302 | high | A Linux kernel vulnerability allows attackers to leak kernel memory via crafted HID reports, and is currently being exploited in the wild. |
| 2025-02-05 | CVE-2024-53104 | high | A recently exploited Linux kernel vulnerability allows for privilege escalation via an out-of-bounds write in the UVC driver. |
| 2026-05-01 | CVE-2026-31431 | high | Linux kernel vulnerability CVE-2026-31431 enables privilege escalation via incorrect resource transfer between spheres. |
| 2024-06-26 | CVE-2022-2586 | high | Linux kernel use-after-free vulnerability in nft_object allows local privilege escalation. |
| 2026-07-06 | CVE-2026-9182 | medium | ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload. |
| 2026-06-30 | CVE-2026-13775 | critical | Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-13782 | critical | Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-13781 | critical | Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-13780 | critical | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2026-06-30 | CVE-2026-13776 | critical | Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 2022-09-16 | CVE-2022-36536 | critical | An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens. |
| 2026-07-07 | CVE-2026-13020 | high | A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators sh |
| 2026-07-17 | CVE-2026-13448 | high | CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re |
| 2026-07-14 | CVE-2026-47304 | high | CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized |
| 2026-06-09 | CVE-2026-34691 | critical | CVE-2026-34691: Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are af |
| 2026-06-04 | CVE-2026-10972 | critical | CVE-2026-10972: Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed |
| 2026-05-28 | CVE-2026-9874 | critical | CVE-2026-9874: Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote |
| 2026-05-26 | CVE-2026-8856 | high | CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration |
| 2026-05-26 | CVE-2026-8855 | high | CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o |
| 2026-05-26 | CVE-2026-24212 | high | CVE-2026-24212: NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive infor |
| 2026-05-22 | CVE-2026-8673 | medium | CVE-2026-8673: Unprotected transport of credentials vulnerability in syslink software AG Avantr |
| 2026-05-20 | CVE-2026-24206 | high | CVE-2026-24206: NVIDIA Triton Inference Server contains a vulnerability where an attacker could |
| 2026-04-03 | CVE-2026-35561 | high | CVE-2026-35561: Insufficient authentication security controls in the browser-based authenticatio |
| 2024-08-08 | CVE-2024-42256 | high | CVE-2024-42256: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix s |
| 2016-04-07 | CVE-2016-1019 | critical | CVE-2016-1019: Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a den |
DOSSIER SOURCES
- Linux - Wikipedia · en.wikipedia.org
- Linux Kernel CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- Linux CVE Hub: Kernel Bugs, Local Privilege Escalation, and Safe ... · www.penligent.ai
- Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default ... · The Hacker News
- Linux Security Teams Face Unprecedented Strain After Surge in Kernel ... · securityboulevard.com
- Linux Security Updates Pattern Analysis Kernel Identity Risks July 2026 · linuxsecurity.com
- Linux Kernel Team Publishes 440 CVE Security Advisories ... - GBHackers · gbhackers.com
Open questions: How effective are the security practices of the Linux kernel community in addressing vulnerabilities? · What is the overall impact of these vulnerabilities on the security of Linux-based systems?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-24 03:40:33.094558+00:00