Udev is the Linux device manager responsible for dynamic device-file creation and permission management in the kernel interface, and its vulnerabilities center on low-level input handling and access-control configuration affecting system initialization and device access. The observed weakness classes include buffer overflows, incorrect default permissions, and origin validation errors, reflecting the challenges of parsing and authorizing diverse hardware interfaces at the point of device discovery. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Udev Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1185HIGH udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. | Apr 17, 2009 | 7.2 | 84 | NO | YES |
CVE-2011-0640MEDIUM The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attacke | Jan 25, 2011 | 6.9 | 23 | NO | NO |
CVE-2010-4176MEDIUM plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read | Dec 7, 2010 | 4.0 | 17 | NO | NO |
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that t | Apr 17, 2009 | 2.1 | 13 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Udev Project.
Media articles that mention a CVE ID that affects a product developed by Udev Project — matched by CVE ID, not by vendor name.