Mdadm is a Linux software RAID management utility that directly manipulates kernel block devices and metadata, making it a core component of storage infrastructure on systems deploying hardware-agnostic RAID. Its disclosed vulnerabilities center on memory-safety issues such as classic buffer overflows, command-injection risks in metadata parsing and device handling, and uncontrolled resource consumption—weakness classes that reflect the utility's low-level access to untrusted disk structures and administrative command interfaces. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mdadm Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5220HIGH The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary c | Jun 8, 2018 | 7.8 | 24 | NO | NO |
CVE-2023-28736MEDIUM Buffer overflow in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a privileged user to potentially enable escalation of privilege via local access. | Aug 11, 2023 | 6.7 | 19 | NO | NO |
CVE-2023-28938MEDIUM Uncontrolled resource consumption in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a priviledged user to potentially enable denial of service via local ac | Aug 11, 2023 | 4.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mdadm Project.
Media articles that mention a CVE ID that affects a product developed by Mdadm Project — matched by CVE ID, not by vendor name.