LineageOS is a community-maintained custom Android distribution deployed across a diverse installed base of mobile devices, and its vulnerability disclosures reflect both its role as an alternative operating system and upstream dependency exposure. The recurring weakness signals—insufficient information placeholder entries alongside NULL pointer dereference reports—suggest a mix of incomplete CVE characterization and memory-safety issues typical of Android's native components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lineageos over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-1010221MEDIUM LineageOS 16.0 and earlier is affected by: Incorrect Access Control. The impact is: The property checked by `adb root` can also be set in a normal adb shell session. The component | Jul 23, 2019 | 6.8 | 21 | NO | NO |
CVE-2017-6899MEDIUM The msm_bus_dbg_update_request_write function in drivers/platform/msm/msm_bus/msm_bus_dbg.c in android_kernel_huawei_msm8916 through 2017-06-16 in LineageOS, and possibly other ker | Jun 16, 2017 | 6.2 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lineageos.
Media articles that mention a CVE ID that affects a product developed by Lineageos — matched by CVE ID, not by vendor name.