Linux Enterprise High Availability Extension
Vendor:
First CVE: May 7, 2010 · Active for 16 years
28
Total CVEs
More Total CVEs than 97% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
7.1%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Linux Enterprise High Availability Extension over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 7, 2010
16 years ago
Most Recent CVE
Apr 22, 2026
96 days ago
CVE Severity & Scoring
Linux Enterprise High Availability Extension28 CVEs
14%
36%
43%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local12 (42.9%)
Network2 (7.1%)
Unknown14 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (46.4%)
High1 (3.6%)
Unknown14 (50.0%)
User Interaction
None14 (50.0%)
Unknown14 (50.0%)
Required0 (0.0%)
Privileges Required
Low12 (42.9%)
High0 (0.0%)
None2 (7.1%)
Unknown14 (50.0%)
Top CVEs
Signals from CVEs in this product scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31431HIGH In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the c | Apr 22, 2026 | 7.8 | 99 | YES | YES |
CVE-2014-3153HIGH The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain priv | Jun 7, 2014 | 7.8 | 90 | YES | YES |
CVE-2014-2323CRITICAL SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hos | Mar 14, 2014 | 9.8 | 68 | NO | YES |
CVE-2017-18017CRITICAL The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-a | Jan 3, 2018 | 9.8 | 60 | NO | NO |
CVE-2010-2959HIGH Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and | Sep 8, 2010 | 7.2 | 35 | NO | YES |
CVE-2010-1437HIGH Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory co | May 7, 2010 | 7.0 | 32 | NO | YES |
CVE-2013-3301HIGH The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified | Apr 29, 2013 | 7.2 | 27 | NO | YES |
CVE-2014-2324MEDIUM Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) | Mar 14, 2014 | 5.0 | 26 | NO | NO |
CVE-2012-1097HIGH The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of | May 17, 2012 | 7.8 | 26 | NO | NO |
CVE-2010-3865HIGH Integer overflow in the rds_rdma_pages function in net/rds/rdma.c in the Linux kernel allows local users to cause a denial of service (crash) and possibly execute arbitrary code vi | Jan 11, 2011 | 7.2 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (28 CVEs).
CISA KEV
2 CVEs
7.1% of CVEs· 98th percentile
Metasploit
2 CVEs
7.1% of CVEs· 97th percentile
Nuclei
2 CVEs
7.1% of CVEs· 97th percentile
ExploitDB
5 CVEs
17.9% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (28 CVEs).
Media Mentions
Signals from CVEs in this product scope (28 CVEs).
Top CNAs Publishing CVEs For Linux Enterprise High Availability Extension
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 16.0 | 1 | 7.8 | 94.5% | 1 | 1 |
| 15 | 1 | 7.8 | 94.5% | 1 | 1 |
| 12 | 1 | 5.0 | 4.3% | 0 | 0 |
| 11 | 26 | 6.1 | 7.4% | 1 | 6 |