Linux Enterprise High Availability Extension

Vendor:

First CVE: May 7, 2010 · Active for 16 years

28
Total CVEs
More Total CVEs than 97% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
7.1%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Linux Enterprise High Availability Extension over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 7, 2010
16 years ago
Most Recent CVE
Apr 22, 2026
96 days ago

CVE Severity & Scoring

Linux Enterprise High Availability Extension28 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local12 (42.9%)
Network2 (7.1%)
Unknown14 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (46.4%)
High1 (3.6%)
Unknown14 (50.0%)
User Interaction
None14 (50.0%)
Unknown14 (50.0%)
Required0 (0.0%)
Privileges Required
Low12 (42.9%)
High0 (0.0%)
None2 (7.1%)
Unknown14 (50.0%)

Top CVEs

Signals from CVEs in this product scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the c
Apr 22, 20267.899YESYES
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain priv
Jun 7, 20147.890YESYES
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hos
Mar 14, 20149.868NOYES
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-a
Jan 3, 20189.860NONO
Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and
Sep 8, 20107.235NOYES
Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory co
May 7, 20107.032NOYES
The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified
Apr 29, 20137.227NOYES
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot)
Mar 14, 20145.026NONO
The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of
May 17, 20127.826NONO
Integer overflow in the rds_rdma_pages function in net/rds/rdma.c in the Linux kernel allows local users to cause a denial of service (crash) and possibly execute arbitrary code vi
Jan 11, 20117.223NONO

Exploit Exposure

Signals from CVEs in this product scope (28 CVEs).

CISA KEV
2 CVEs
7.1% of CVEs· 98th percentile
Metasploit
2 CVEs
7.1% of CVEs· 97th percentile
Nuclei
2 CVEs
7.1% of CVEs· 97th percentile
ExploitDB
5 CVEs
17.9% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (28 CVEs).

Media Mentions

Signals from CVEs in this product scope (28 CVEs).

Top CNAs Publishing CVEs For Linux Enterprise High Availability Extension

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
16.017.894.5%11
1517.894.5%11
1215.04.3%00
11266.17.4%16