Linux Kernel CVE Statistics
18 Linux Kernel CVEs in May 2023
Full month · Source: NIST NVD
In May 2023, 18 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 6 were rated High severity and 12 Medium. No CVEs from this month have been confirmed as actively exploited via the CISA KEV catalog. May's 18 CVEs represent 7% of all 2023 Linux kernel CVEs , down from April's 29 (a 38% month-over-month decrease) .
18
Total CVEs
0
Critical
6
High
12
Medium
0
Low
0
KEV Exploited
All CVEs — May 2023
18 CVEs
| CVE ID | Package | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|---|
| CVE-2023-2124 | linux | High | 7.8 | 2023-05-15 | An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image… | |
| CVE-2023-32233 | linux | High | 7.8 | 2023-05-08 | In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused… | |
| CVE-2023-2235 | linux | High | 7.8 | 2023-05-01 | A use-after-free vulnerability in the Linux Kernel Performance Events system can be exploited to achieve local privileg… | |
| CVE-2023-2236 | linux | High | 7.8 | 2023-05-01 | A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escal… | |
| CVE-2023-2156 | linux | High | 7.5 | 2023-05-09 | A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue re… | |
| CVE-2022-48502 | linux | High | 7.1 | 2023-05-31 | An issue was discovered in the Linux kernel before 6.2. The ntfs3 subsystem does not properly check for correctness dur… | |
| CVE-2023-2002 | linux | Medium | 6.8 | 2023-05-26 | A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock… | |
| CVE-2020-36694 | linux | Medium | 6.7 | 2023-05-21 | An issue was discovered in netfilter in the Linux kernel before 5.10. There can be a use-after-free in the packet proce… | |
| CVE-2023-2513 | linux | Medium | 6.7 | 2023-05-08 | A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode si… | |
| CVE-2023-32269 | linux | Medium | 6.7 | 2023-05-05 | An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c, there is a use-after-free because… | |
| CVE-2023-33203 | linux | Medium | 6.4 | 2023-05-18 | The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/e… | |
| CVE-2023-34256 | linux | Medium | 5.5 | 2023-05-31 | An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when c… | |
| CVE-2023-0459 | linux | Medium | 5.5 | 2023-05-25 | Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to … | |
| CVE-2023-1195 | linux | Medium | 5.5 | 2023-05-18 | A use-after-free flaw was found in reconn_set_ipaddr_from_hostname in fs/cifs/connect.c in the Linux kernel. The issue … | |
| CVE-2023-2898 | linux | Medium | 4.7 | 2023-05-26 | There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw al… |