CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,252
Total CVEs
21
Critical
303
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 21
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 18
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,252)

CVE-2022-50272
5.5

This vulnerability is a null pointer dereference in the Linux kernel's DVB USB driver for the AZ6027 device. It allows local attackers to cause a kern...

Sep 15, 2025
CVE-2022-50276
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's power supply subsystem. When the system fails to allocate memory for...

Sep 15, 2025
CVE-2022-50277
5.5

A vulnerability in the Linux kernel's ext4 filesystem allows a NULL pointer dereference when mounting a filesystem with a journal inode marked for enc...

Sep 15, 2025
CVE-2022-50266
5.5

A race condition vulnerability in the Linux kernel's kprobes subsystem where kill_kprobe() fails to properly disarm enabled probes before marking them...

Sep 15, 2025
CVE-2022-50267
5.5

This CVE-2022-50267 is a Linux kernel memory leak vulnerability in the mmc/rtsx_pci driver where mmc_add_host() return value isn't properly checked. I...

Sep 15, 2025
CVE-2022-50262
5.5

A NULL pointer dereference vulnerability in the Linux kernel's NTFS3 filesystem driver allows attackers to cause a kernel panic (denial of service) by...

Sep 15, 2025
CVE-2023-53198
5.5

A NULL pointer dereference vulnerability in the Linux kernel's raw socket implementation allows local attackers to cause a kernel panic (denial of ser...

Sep 15, 2025
CVE-2023-53167
5.5

A null pointer dereference vulnerability in the Linux kernel's tracing subsystem allows local users to cause a kernel panic by performing an lseek ope...

Sep 15, 2025
CVE-2023-53168
5.5

A race condition vulnerability in the Linux kernel's USB Type-C UCSI ACPI driver where an insufficient command completion timeout (1 second instead of...

Sep 15, 2025
CVE-2023-53147
5.5

A NULL pointer dereference vulnerability in the Linux kernel's XFRM subsystem allows local users to crash the kernel by triggering a specific conditio...

Sep 15, 2025
CVE-2023-53150
5.5

This CVE describes a NULL pointer dereference vulnerability in the QLogic Fibre Channel driver (qla2xxx) in the Linux kernel. An attacker could potent...

Sep 15, 2025
CVE-2025-39772
5.5

A NULL pointer dereference vulnerability in the Linux kernel's hibmc DRM driver occurs when the driver fails to load properly. This can cause kernel c...

Sep 11, 2025
CVE-2025-39765
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ALSA timer subsystem where ida_free() is called on an unallocated ID when kasprintf() f...

Sep 11, 2025
CVE-2025-0009
5.5

A NULL pointer dereference vulnerability in AMD Crash Defender could allow an attacker to cause a system crash by writing NULL output to a log file, r...

Sep 6, 2025
CVE-2025-39708
5.5

A NULL pointer dereference vulnerability in the Linux kernel's iris media driver could cause kernel crashes or system instability when handling certai...

Sep 5, 2025
CVE-2025-39709
5.5

A race condition in the Linux kernel's Venus media driver allows a NULL pointer dereference during system boot if an interrupt fires before the interr...

Sep 5, 2025
CVE-2025-39705
5.5

A null pointer dereference vulnerability in the AMD display driver (DC module) of the Linux kernel causes a kernel crash when display control context ...

Sep 5, 2025
CVE-2025-39706
5.5

A use-after-free vulnerability in the Linux kernel's AMD KFD driver occurs when debugfs entries are destroyed before work queues, causing a kernel NUL...

Sep 5, 2025
CVE-2025-39707
5.5

A NULL pointer dereference vulnerability in the AMD GPU driver for Linux kernels allows local attackers to cause a kernel panic (denial of service) by...

Sep 5, 2025
CVE-2025-39693
5.5

This CVE describes a NULL pointer dereference vulnerability in the AMD display driver component of the Linux kernel. If exploited, it could cause a ke...

Sep 5, 2025
CVE-2025-39694
5.5

This CVE-2025-39694 is a NULL pointer dereference vulnerability in the Linux kernel's SCLP (Service Call Logical Processor) subsystem on s390 architec...

Sep 5, 2025
CVE-2025-39699
5.5

A NULL pointer dereference vulnerability in the RISC-V IOMMU driver of the Linux kernel could cause kernel crashes or denial of service. This affects ...

Sep 5, 2025
CVE-2025-39674
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's UFS (Universal Flash Storage) driver for Qualcomm platforms. When th...

Sep 5, 2025
CVE-2025-39675
5.5

A null pointer dereference vulnerability in the Linux kernel's AMD display driver could cause kernel crashes or denial of service. This affects system...

Sep 5, 2025
CVE-2025-39676
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's qla4xxx SCSI driver. The vulnerability occurs when error pointers ar...

Sep 5, 2025
CVE-2025-38733
5.5

This Linux kernel vulnerability on s390 architecture allows NULL pointer dereferences to succeed instead of causing exceptions. This occurs because th...

Sep 5, 2025
CVE-2025-38726
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's ftgmac100 network driver. The flaw occurs when the driver attempts t...

Sep 4, 2025
CVE-2025-38706
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ASoC (Audio System on Chip) subsystem could cause kernel crashes when removing PCM runt...

Sep 4, 2025
CVE-2025-38693
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's w7090p DVB frontend driver. Attackers with local access can trigger ...

Sep 4, 2025
CVE-2025-38694
5.5

A null pointer dereference vulnerability in the Linux kernel's DVB frontend driver allows local attackers to crash the system or potentially execute a...

Sep 4, 2025
CVE-2025-38695
5.5

A null pointer dereference vulnerability in the Linux kernel's lpfc SCSI driver could cause kernel panic or system crash when specific error condition...

Sep 4, 2025
CVE-2025-38684
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Enhanced Transmission Selection (ETS) queuing discipline allows local attackers to caus...

Sep 4, 2025
CVE-2025-38674
5.5

A NULL pointer dereference vulnerability in the Linux kernel's DRM (Direct Rendering Manager) subsystem allows local attackers to cause a kernel panic...

Aug 22, 2025
CVE-2025-38668
5.5

A NULL pointer dereference vulnerability in the Linux kernel's regulator subsystem can cause kernel panics when accessing regulator coupling data afte...

Aug 22, 2025
CVE-2025-38669
5.5

A NULL pointer dereference vulnerability in the Linux kernel's DRM graphics subsystem allows local attackers to cause a kernel panic (denial of servic...

Aug 22, 2025
CVE-2025-38672
5.5

A NULL-pointer dereference vulnerability in the Linux kernel's DRM GEM DMA subsystem allows local attackers to cause a kernel panic or system crash. T...

Aug 22, 2025
CVE-2025-38673
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Direct Rendering Manager (DRM) subsystem allows local attackers to cause a kernel panic...

Aug 22, 2025
CVE-2025-38659
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's GFS2 filesystem. When a node withdraws while being the only node wit...

Aug 22, 2025
CVE-2025-38664
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's ice driver, which handles Intel Ethernet Connection network adapters...

Aug 22, 2025
CVE-2025-38665
5.5

A NULL pointer dereference vulnerability in the Linux kernel's CAN (Controller Area Network) subsystem allows local attackers to crash the kernel when...

Aug 22, 2025
CVE-2025-38655
5.5

A NULL pointer dereference vulnerability exists in the Canaan K230 pinctrl driver in the Linux kernel. If a device tree node lacks the 'pinmux' proper...

Aug 22, 2025
CVE-2025-38648
5.5

A NULL pointer dereference vulnerability in the STM32 SPI driver of the Linux kernel could cause a kernel panic or system crash when accessing uniniti...

Aug 22, 2025
CVE-2025-38641
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's Bluetooth USB driver (btusb). If exploited, it could cause a kernel ...

Aug 22, 2025
CVE-2025-38645
5.5

A NULL pointer dereference vulnerability in the Linux kernel's mlx5 network driver could cause kernel crashes when device memory allocation fails. Thi...

Aug 22, 2025
CVE-2025-38646
5.5

A NULL pointer dereference vulnerability in the Linux kernel's rtw89 WiFi driver allows a kernel panic when receiving malformed packets on unsupported...

Aug 22, 2025
CVE-2025-38635
5.5

A NULL pointer dereference vulnerability exists in the Linux kernel's davinci_lpsc_clk_register() function when devm_kasprintf() fails to allocate mem...

Aug 22, 2025
CVE-2025-38629
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's ALSA USB driver for Scarlett2 audio interfaces. If exploited, it cou...

Aug 22, 2025
CVE-2025-38630
5.5

This vulnerability in the Linux kernel's imxfb framebuffer driver could allow a local attacker to cause a kernel null pointer dereference, leading to ...

Aug 22, 2025
CVE-2025-38619
5.5

A race condition in the Texas Instruments J721E CSI-2 receiver driver in the Linux kernel causes list corruption when DMA buffer handling fails, leadi...

Aug 22, 2025
CVE-2025-38609
5.5

A NULL pointer dereference vulnerability in the Linux kernel's devfreq subsystem could cause kernel panics or system crashes when accessing governor i...

Aug 19, 2025

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,252 CVEs classified as CWE-476, with 21 rated critical and 303 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free