305 Linux Kernel CVEs in 2019

Full year · Source: NIST NVD

2018 2020

In 2019, 305 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 24 were rated Critical, 113 High severity , and 2 were confirmed as actively exploited in the wild (CISA KEV) . Compared to 2018's 456 CVEs, 2019 represented a decrease of 33% year-on-year. November was the most active month, with 80 CVEs published.

305
Total CVEs
24
Critical
113
High
156
Medium
12
Low
2
KEV Exploited

Monthly CVE Breakdown — 2019

CVEs published per month with severity breakdown

Monthly highlight

November (80) was the most active month in 2019. Together the top months account for a significant share of 2019's 305 total CVEs. January (7) had the lowest volume.

Critical
High
Medium
Low
Source: NIST NVD API.

Severity Distribution — 2019

Breakdown across 305 CVEs

Critical 8%
High 37%
Medium 51%
Low 4%
Severity breakdown

51% Medium · 37% High · 8% Critical.

Percentages rounded to nearest integer.

Monthly Counts — 2019

CVE counts by month and severity

Monthly highlight

November was the most active month with 80 CVEs — 26% of 2019's total. January (7) had the lowest volume.

Month Total Critical High Medium Low Share of year
January 7 0 2 5 0
2%
February 19 1 10 8 0
6%
March 8 2 2 4 0
3%
April 15 0 6 8 1
5%
May 17 1 7 8 1
6%
June 12 1 8 3 0
4%
July 22 5 8 8 1
7%
August 38 3 10 25 0
12%
September 34 2 14 17 1
11%
October 12 1 5 1 5
4%
November 80 7 31 41 1
26%
December 41 1 10 28 2
13%
Total 305 24 113 156 12
Click any month to view all CVEs published that month.

Actively exploited CVEs — 2019

2 CVEs confirmed in CISA KEV catalog

CVE ID Severity CVSS Published Description
CVE-2019-13272 High KEV 7.8 2019-07-17 In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the c…
CVE-2019-2215 High KEV 7.8 2019-10-11 A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kern…
KEV data sourced from CISA Known Exploited Vulnerabilities catalog.

All CVEs — 2019

305 CVEs

All (305) Critical (24) High (113) Medium (156) Low (12)
CVE ID Package Severity CVSS Published Description
CVE-2019-10557 linux Critical 9.8 2019-12-18 Out-of-bound read in the wireless driver in the Linux kernel due to lack of check of buffer length. in Snapdragon Auto,…
CVE-2019-14895 linux Critical 9.8 2019-11-29 A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell…
CVE-2019-14897 linux Critical 9.8 2019-11-29 A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An att…
CVE-2019-14901 linux Critical 9.8 2019-11-29 A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip dr…
CVE-2019-14896 linux Critical 9.8 2019-11-27 A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip d…
CVE-2019-18814 linux Critical 9.8 2019-11-07 An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_…
CVE-2019-18805 linux Critical 9.8 2019-11-07 An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.…
CVE-2019-17133 linux Critical 9.8 2019-10-04 In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE…
CVE-2019-16746 linux Critical 9.8 2019-09-24 An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of v…
CVE-2019-15504 linux Critical 9.8 2019-08-23 drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traff…

2019 Linux Kernel CVE Highlights

  • Monthly variation

    CVE publication in 2019 was uneven across months. November was the most active with 80 CVEs. January (7) had the lowest volume. Monthly spikes typically correspond to coordinated batches of backfilled CVEs being processed at once.

Frequently Asked Questions

How many Linux kernel CVEs were published in 2019?

305 Linux kernel CVEs were published in 2019, sourced from the NIST National Vulnerability Database. 24 were rated Critical, 113 High severity , and 2 were confirmed as actively exploited via CISA KEV .

Which month had the most Linux kernel CVEs in 2019?

November 2019 had the most Linux kernel CVEs of any month in 2019, with 80 published — 26% of all 2019 CVEs. View November 2019 CVEs →

How many Linux kernel CVEs in 2019 are actively exploited?

2 Linux kernel CVEs from 2019 are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. The actively exploited rate for 2019 is 7 per 1,000 CVEs. View actively exploited CVEs from 2019 →

Why were there so many Linux kernel CVEs in 2019?

The volume of Linux kernel CVEs in 2019 reflects the kernel project's expanded use of its own CVE Numbering Authority (CNA), which began systematically publishing CVEs for a broader range of subsystem-level bugs — including many previously unreported or patched without a CVE assignment. This explains why volume remained high while critical severity counts remained very low.

How does 2019 compare to previous years for Linux kernel CVEs?

2019 had 305 CVEs — decrease of 33% compared to 2018's 456 . View the full year-by-year breakdown →

2018 statistics All-time stats 2020 statistics