The Linux kernel and its core userspace utilities (util-linux, Linux-PAM) comprise a foundational software layer present in nearly all Unix-like systems, with an attack surface that extends across countless downstream distributions and embedded deployments. Vulnerabilities in this tier recur through weakness classes including improper memory-buffer handling, link-following flaws, and access-control issues around file and directory permissions—flaws that reflect the low-level, privilege-sensitive nature of kernel and system-utility code. These weakness patterns are durable across the vendor's footprint and matter to defenders because even localized or moderate-severity instances can propagate widely through the supply chain and affect system stability or containment. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kernel over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-13595MEDIUM A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent | Jun 29, 2026 | 6.8 | 34 | NO | NO |
CVE-2018-7738HIGH In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount co | Mar 7, 2018 | 7.8 | 26 | NO | NO |
CVE-2014-9114HIGH Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code. | Mar 31, 2017 | 7.8 | 26 | NO | NO |
CVE-2026-3184MEDIUM A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before sett | Apr 3, 2026 | 5.3 | 25 | NO | NO |
CVE-2015-5224CRITICAL The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks. | Aug 23, 2017 | 9.8 | 25 | NO | NO |
CVE-2016-2779HIGH runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. | Feb 7, 2017 | 7.8 | 25 | NO | NO |
CVE-2026-27456MEDIUM util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mo | Apr 3, 2026 | 4.7 | 23 | NO | NO |
CVE-2021-3996MEDIUM A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vuln | Aug 23, 2022 | 5.5 | 21 | NO | NO |
CVE-2021-3995MEDIUM A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local | Aug 23, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-0563MEDIUM A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the lib | Feb 21, 2022 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kernel.
Media articles that mention a CVE ID that affects a product developed by Kernel — matched by CVE ID, not by vendor name.