Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Grsecurity

First CVE: Dec 31, 2002Active for: 24 yearsTotal CVEs: 6

Grsecurity specializes in a focused kernel-hardening patch and associated testing tools designed to enhance the security posture of Linux systems through memory protection and access-control mechanisms. The vendor's disclosure surface is narrow but prominent in security-conscious deployments, and its vulnerabilities frequently acquire public exploit code reflecting the visibility and value of kernel-level security enhancements to the adversarial and defensive communities. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Grsecurity over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Oct 29, 2019
2,460 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-0257HIGH
Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspecified vectors. NOTE: the grsecurity developer has disputed
Jan 16, 20077.828NOYES
CVE-2002-1826MEDIUM
grsecurity 1.9.4 for Linux kernel 2.4.18 allows local users to bypass read-only permissions by using mmap to directly map /dev/mem or /dev/kmem to kernel memory.
Dec 31, 20024.621NOYES
CVE-2010-3373MEDIUM
paxtest handles temporary files insecurely
Oct 29, 20195.520NONO
CVE-2006-0228HIGH
The RBAC functionality in grsecurity before 2.1.8 does not properly handle when the admin role creates a service and then exits the shell without unauthenticating, which causes the
Jan 17, 20067.220NONO
CVE-2007-0253HIGH
Unspecified vulnerability in the grsecurity patch has unspecified impact and remote attack vectors, a different vulnerability than the expand_stack vulnerability from the Digital A
Jan 16, 20077.218NONO
CVE-2008-1940MEDIUM
The RBAC functionality in grsecurity before 2.1.11-2.6.24.5 and 2.1.11-2.4.36.2 does not enforce user_transition_deny and user_transition_allow rules for the (1) sys_setfsuid and (
Apr 25, 20084.614NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (33.3%)
Network0 (0.0%)
Unknown4 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (33.3%)
High0 (0.0%)
Unknown4 (66.7%)
User Interaction
None2 (33.3%)
Unknown4 (66.7%)
Required0 (0.0%)
Privileges Required
Low2 (33.3%)
High0 (0.0%)
None0 (0.0%)
Unknown4 (66.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
33.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Grsecurity.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Grsecurity — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Grsecurity's Products

View all 1 CNAs →

Top CWEs