CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,251
Total CVEs
20
Critical
303
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 21
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 18
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,251)

CVE-2023-53599
5.5

A NULL pointer dereference vulnerability in the Linux kernel's crypto subsystem affects the af_alg interface when processing empty ciphertext with the...

Oct 4, 2025
CVE-2023-53595
5.5

A NULL pointer dereference vulnerability in the Linux kernel's octeontx2-pf driver for Marvell OcteonTX2 network adapters causes kernel crashes when r...

Oct 4, 2025
CVE-2023-53576
5.5

A NULL pointer dereference vulnerability in the Linux kernel's null_blk driver allows local attackers to cause a kernel oops (crash) by setting queue_...

Oct 4, 2025
CVE-2023-53566
5.5

A null pointer dereference vulnerability in the Linux kernel's netfilter nft_set_rbtree component can cause kernel crashes or potential privilege esca...

Oct 4, 2025
CVE-2023-53565
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Broadcom FullMAC wireless driver (brcmfmac) can cause system crashes when resuming from...

Oct 4, 2025
CVE-2023-53534
5.5

This CVE describes a NULL pointer dereference vulnerability in the MediaTek DRM driver in the Linux kernel. If devm_kcalloc fails to allocate memory a...

Oct 4, 2025
CVE-2023-53538
5.5

A race condition in the Linux kernel's Btrfs filesystem tree modification logging can lead to a NULL pointer dereference and kernel panic when perform...

Oct 4, 2025
CVE-2022-50501
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's CODA video codec driver. If exploited, it could cause a kernel panic...

Oct 4, 2025
CVE-2022-50503
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's LPDDR2 NVM driver. If exploited, it could cause a kernel panic or sy...

Oct 4, 2025
CVE-2022-50506
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's DRBD (Distributed Replicated Block Device) subsystem. When a DRBD de...

Oct 4, 2025
CVE-2025-39950
5.5

A NULL pointer dereference vulnerability exists in the Linux kernel's TCP-AO (Authentication Option) implementation when used with TCP_REPAIR mode. Th...

Oct 4, 2025
CVE-2025-39934
5.5

A race condition in the Linux kernel's ANX7625 DisplayPort bridge driver allows an interrupt to occur before device initialization completes, potentia...

Oct 4, 2025
CVE-2025-39937
5.5

A NULL pointer dereference vulnerability in the Linux kernel's rfkill-gpio driver could cause kernel crashes on specific x86 systems with BCM4752 or L...

Oct 4, 2025
CVE-2023-53531
5.5

A race condition in the Linux kernel's null_blk driver can cause a kernel panic when poll requests timeout during I/O operations. This affects systems...

Oct 1, 2025
CVE-2023-53523
5.5

A NULL pointer dereference vulnerability in the Linux kernel's gs_usb CAN bus driver allows denial of service when specific race conditions occur duri...

Oct 1, 2025
CVE-2023-53497
5.5

A race condition vulnerability in the Linux kernel's VSP1 video driver causes a NULL pointer dereference when streaming video. This allows local attac...

Oct 1, 2025
CVE-2023-53498
5.5

This CVE describes a NULL pointer dereference vulnerability in the AMD GPU display driver within the Linux kernel. If exploited, it could cause a kern...

Oct 1, 2025
CVE-2023-53503
5.5

A Linux kernel vulnerability in the ext4 filesystem allows attackers with write access to block devices to trigger a denial-of-service condition. By m...

Oct 1, 2025
CVE-2023-53483
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's ACPI processor driver. If devm_kzalloc() fails during fch_misc_setup...

Oct 1, 2025
CVE-2023-53480
5.5

A NULL pointer dereference vulnerability in the Linux kernel's kobject subsystem allows local attackers to cause a kernel panic (denial of service) by...

Oct 1, 2025
CVE-2023-53476
5.5

A NULL pointer dereference vulnerability exists in the Linux kernel's iw_cxgb4 driver, which handles Chelsio T4/T5/T6 RDMA hardware. This vulnerabilit...

Oct 1, 2025
CVE-2023-53464
5.5

This CVE addresses a null pointer dereference vulnerability in the Linux kernel's iSCSI TCP module. An attacker could potentially cause a kernel panic...

Oct 1, 2025
CVE-2023-53457
5.5

A NULL pointer dereference vulnerability exists in the JFS filesystem implementation in the Linux kernel. When txBegin is called on a read-only mounte...

Oct 1, 2025
CVE-2023-53458
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's cx23885 media driver. When DMA memory allocation fails during buffer...

Oct 1, 2025
CVE-2023-53451
5.5

This CVE describes a NULL pointer dereference vulnerability in the qla2xxx SCSI driver in the Linux kernel. If exploited, it could cause a kernel pani...

Oct 1, 2025
CVE-2022-50467
5.5

A null pointer dereference vulnerability in the Linux kernel's lpfc SCSI driver allows local attackers to cause a kernel panic (denial of service) by ...

Oct 1, 2025
CVE-2022-50459
5.5

A race condition vulnerability in the Linux kernel's iSCSI TCP implementation allows local attackers to trigger a NULL pointer dereference crash (kern...

Oct 1, 2025
CVE-2022-50452
5.5

This is a NULL pointer dereference vulnerability in the Linux kernel's CAKE (Common Applications Kept Enhanced) queuing discipline. When CAKE initiali...

Oct 1, 2025
CVE-2022-50440
5.5

This CVE is a NULL pointer dereference vulnerability in the VMware graphics driver (vmwgfx) in the Linux kernel. It allows local attackers to cause a ...

Oct 1, 2025
CVE-2022-50441
5.5

This vulnerability in the Linux kernel's mlx5 network driver allows a NULL pointer dereference when delayed bond work isn't properly cancelled before ...

Oct 1, 2025
CVE-2022-50425
5.5

A NULL pointer dereference vulnerability in the Linux kernel's x86 FPU (Floating Point Unit) handling allows local attackers to cause a kernel panic (...

Oct 1, 2025
CVE-2025-39920
5.5

A NULL pointer dereference vulnerability in the Linux kernel's PCMCIA subsystem could allow local attackers to cause a kernel panic or potentially exe...

Oct 1, 2025
CVE-2025-39906
5.5

A null pointer dereference vulnerability in the AMD display driver for Linux kernels allows local attackers to cause a kernel panic or system crash by...

Oct 1, 2025
CVE-2025-39895
5.5

A NULL pointer dereference vulnerability in the Linux kernel's scheduler function sched_numa_find_nth_cpu() can cause kernel panic when all CPUs in a ...

Oct 1, 2025
CVE-2025-39897
5.5

A NULL pointer dereference vulnerability in the Xilinx AXI Ethernet driver of the Linux kernel could cause kernel crashes or undefined behavior when D...

Oct 1, 2025
CVE-2025-39902
5.5

A NULL pointer dereference vulnerability in the Linux kernel's SLUB memory allocator can cause kernel crashes when debugging code attempts to access i...

Oct 1, 2025
CVE-2025-39887
5.5

A NULL pointer dereference vulnerability in the Linux kernel's tracing/osnoise subsystem allows local users to crash the kernel by writing malformed d...

Sep 23, 2025
CVE-2025-39876
5.5

A NULL pointer dereference vulnerability in the Linux kernel's FEC (Fast Ethernet Controller) driver could cause kernel panic and system crashes when ...

Sep 23, 2025
CVE-2025-39879
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Ceph filesystem driver can cause kernel crashes when handling write operations. This af...

Sep 23, 2025
CVE-2025-39875
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's igb network driver when executing the ethtool loopback test. The vul...

Sep 23, 2025
CVE-2025-39865
5.5

A NULL pointer dereference vulnerability in the Linux kernel's TEE (Trusted Execution Environment) subsystem allows local attackers to cause a kernel ...

Sep 19, 2025
CVE-2025-39857
5.5

A NULL pointer dereference vulnerability in the Linux kernel's SMC (Shared Memory Communications) module allows local attackers to cause a kernel pani...

Sep 19, 2025
CVE-2025-39858
5.5

A NULL pointer dereference vulnerability exists in the mlx4 Ethernet driver in the Linux kernel. This occurs when the page_pool_create() function retu...

Sep 19, 2025
CVE-2025-39846
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's PCMCIA subsystem. If exploited, it could cause a kernel panic or sys...

Sep 19, 2025
CVE-2025-39851
5.5

A NULL pointer dereference vulnerability in the Linux kernel's VXLAN implementation allows local attackers to cause a kernel panic (denial of service)...

Sep 19, 2025
CVE-2023-53440
5.5

This vulnerability in the Linux kernel's nilfs2 filesystem involves improper sysfs interface lifetime management, potentially leading to null pointer ...

Sep 18, 2025
CVE-2023-53442
5.5

A Linux kernel vulnerability in the Intel Ethernet Controller (ice) driver allows a null pointer dereference when both Application Device Queues (ADQ)...

Sep 18, 2025
CVE-2023-53444
5.5

A memory corruption vulnerability in the Linux kernel's Direct Rendering Manager (DRM) TTM (Translation Table Maps) subsystem can cause kernel crashes...

Sep 18, 2025
CVE-2023-53419
5.5

This CVE describes a race condition vulnerability in the Linux kernel's RCU (Read-Copy-Update) subsystem that can lead to a NULL pointer dereference. ...

Sep 18, 2025
CVE-2023-53421
5.5

A NULL pointer dereference vulnerability in the Linux kernel's block cgroup subsystem can cause kernel panics when resetting block I/O statistics. Thi...

Sep 18, 2025

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,251 CVEs classified as CWE-476, with 20 rated critical and 303 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free