In 2020, 119 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 0 were rated Critical, 36 High severity . Compared to 2019's 281 CVEs, 2020 represented a decrease of 58% year-on-year. May was the most active month, with 20 CVEs published.
Monthly CVE Breakdown — 2020
CVEs published per month with severity breakdown
May (20) was the most active month in 2020. Together the top months account for a significant share of 2020's 119 total CVEs. March (1) had the lowest volume.
Severity Distribution — 2020
Breakdown across 119 CVEs
67% Medium · 30% High · 0% Critical.
Monthly Counts — 2020
CVE counts by month and severity
May was the most active month with 20 CVEs — 17% of 2020's total. March (1) had the lowest volume.
| Month | Total | Critical | High | Medium | Low | Share of year |
|---|---|---|---|---|---|---|
| January | 7 | 0 | 2 | 5 | 0 |
6%
|
| February | 11 | 0 | 3 | 8 | 0 |
9%
|
| March | 1 | 0 | 0 | 1 | 0 |
1%
|
| April | 13 | 0 | 4 | 9 | 0 |
11%
|
| May | 20 | 0 | 4 | 16 | 0 |
17%
|
| June | 8 | 0 | 2 | 6 | 0 |
7%
|
| July | 5 | 0 | 1 | 3 | 1 |
4%
|
| August | 2 | 0 | 2 | 0 | 0 |
2%
|
| September | 20 | 0 | 5 | 15 | 0 |
17%
|
| October | 6 | 0 | 2 | 4 | 0 |
5%
|
| November | 15 | 0 | 4 | 9 | 2 |
13%
|
| December | 11 | 0 | 7 | 4 | 0 |
9%
|
| Total | 119 | 0 | 36 | 80 | 3 |
All CVEs — 2020
119 CVEs
| CVE ID | Package | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|---|
| CVE-2020-29569 | linux | High | 8.8 | 2020-12-15 | An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block … | |
| CVE-2020-14305 | linux | High | 8.1 | 2020-12-02 | An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking function… | |
| CVE-2020-27786 | linux | High | 7.8 | 2020-12-11 | A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissio… | |
| CVE-2020-29661 | linux | High | 7.8 | 2020-12-09 | A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allow… | |
| CVE-2020-14351 | linux | High | 7.8 | 2020-12-03 | A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local att… | |
| CVE-2020-14381 | linux | High | 7.8 | 2020-12-03 | A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory… | |
| CVE-2020-29534 | linux | High | 7.8 | 2020-12-03 | An issue was discovered in the Linux kernel before 5.9.3. io_uring takes a non-refcounted reference to the files_struct… | |
| CVE-2020-14386 | linux | High | 7.8 | 2020-09-16 | A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from un… | |
| CVE-2020-25220 | linux | High | 7.8 | 2020-09-10 | The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because … | |
| CVE-2020-25221 | linux | High | 7.8 | 2020-09-10 | get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incor… |
2020 Linux Kernel CVE Highlights
-
Volume without critical severity
Despite high CVE volume, 2020 produced only 0 Critical-rated vulnerabilities. 67% of 2020 CVEs are Medium severity. This means the surge in raw numbers does not represent a proportional surge in high-severity risk.
-
Monthly variation
CVE publication in 2020 was uneven across months. May was the most active with 20 CVEs. March (1) had the lowest volume. Monthly spikes typically correspond to coordinated batches of backfilled CVEs being processed at once.