CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,254
Total CVEs
22
Critical
304
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 21
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 18
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,254)

CVE-2025-37853
5.5

A NULL pointer dereference vulnerability in the Linux kernel's AMD GPU driver (drm/amdkfd) allows local attackers to crash the kernel when accessing t...

May 9, 2025
CVE-2025-37841
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's cpupower benchmarking tool. If memory allocation fails, the system c...

May 9, 2025
CVE-2025-37829
5.5

A NULL pointer dereference vulnerability in the Linux kernel's SCPI cpufreq driver allows local attackers to crash the system by triggering a kernel p...

May 8, 2025
CVE-2025-37831
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Apple Silicon CPU frequency driver allows local attackers to cause a kernel panic (syst...

May 8, 2025
CVE-2025-37821
5.5

A Linux kernel scheduling vulnerability in the EEVDF scheduler can cause kernel crashes when specific conditions trigger a sched_entity's slice value ...

May 8, 2025
CVE-2025-37827
5.5

A NULL pointer dereference vulnerability in the Linux kernel's BTRFS filesystem occurs when converting metadata from DUP to RAID1 profile on zoned dev...

May 8, 2025
CVE-2025-37809
5.5

A race condition in the Linux kernel's USB Type-C subsystem allows concurrent calls to typec_partner_unlink_device to cause a NULL pointer dereference...

May 8, 2025
CVE-2025-37800
5.5

A race condition vulnerability in the Linux kernel's dev_uevent() function could allow a local attacker to cause a kernel crash (denial of service) by...

May 8, 2025
CVE-2024-58237
5.5

This Linux kernel vulnerability in the BPF subsystem allows unsafe memory access when tail calls invalidate packet pointers. It affects systems runnin...

May 5, 2025
CVE-2023-53144
5.5

A kernel memory management vulnerability in the Linux kernel's EROFS filesystem when using LZMA compression on HIGHMEM platforms. It causes a NULL poi...

May 2, 2025
CVE-2023-53113
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's nl80211 WiFi subsystem. When operating in AP mode with an unactivate...

May 2, 2025
CVE-2023-53102
5.5

A race condition vulnerability in the Linux kernel's Intel ice driver allows a NULL pointer dereference when handling XDP socket operations. This can ...

May 2, 2025
CVE-2023-53105
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's mlx5e network driver. When unloading the mlx5_core module while traf...

May 2, 2025
CVE-2023-53110
5.5

A race condition vulnerability in the Linux kernel's SMC-R (Shared Memory Communications over RDMA) implementation allows a NULL pointer dereference w...

May 2, 2025
CVE-2023-53098
5.5

A NULL pointer dereference vulnerability in the Linux kernel's gpio-ir-recv driver can cause a kernel panic when the driver is removed while runtime p...

May 2, 2025
CVE-2023-53071
5.5

A NULL pointer dereference vulnerability in the MediaTek MT76 Wi-Fi driver for Linux kernels allows local attackers to cause a kernel panic (system cr...

May 2, 2025
CVE-2023-53056
5.5

A race condition in the QLogic Fibre Channel driver (qla2xxx) in Linux kernel versions before the fix can cause IOCB counts to become out of order, le...

May 2, 2025
CVE-2023-53049
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's USB Type-C Connector System Software Interface (UCSI) driver. When u...

May 2, 2025
CVE-2022-49931
5.5

A NULL pointer dereference vulnerability in the Linux kernel's HFI1 InfiniBand driver causes a kernel crash when a link goes down while there are wait...

May 1, 2025
CVE-2022-49925
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem. When the kernel module...

May 1, 2025
CVE-2022-49916
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ROSE protocol implementation allows local attackers to cause a kernel panic (denial of ...

May 1, 2025
CVE-2022-49894
5.5

This CVE-2022-49894 is a NULL pointer dereference vulnerability in the Linux kernel's CXL (Compute Express Link) region subsystem. It allows local att...

May 1, 2025
CVE-2022-49863
5.5

A NULL pointer dereference vulnerability in the Linux kernel's CAN (Controller Area Network) subsystem allows local attackers to crash the kernel by c...

May 1, 2025
CVE-2022-49869
5.5

A NULL pointer dereference vulnerability in the Linux kernel's bnxt_en driver allows local attackers to cause a kernel crash (denial of service) when ...

May 1, 2025
CVE-2022-49848
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Qualcomm QMP combo PHY driver allows local attackers to cause a kernel panic (system cr...

May 1, 2025
CVE-2022-49832
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's pinctrl device tree subsystem. When kasprintf() fails to allocate me...

May 1, 2025
CVE-2022-49823
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's libata-transport subsystem. When the ata_tdev_add() function fails t...

May 1, 2025
CVE-2022-49825
5.5

A NULL pointer dereference vulnerability in the Linux kernel's libata-transport subsystem allows local attackers to cause a kernel panic (denial of se...

May 1, 2025
CVE-2022-49810
5.5

A race condition vulnerability in the Linux kernel's netfs subsystem can cause a NULL pointer dereference when iterating through xarray data structure...

May 1, 2025
CVE-2022-49796
5.5

A NULL pointer dereference vulnerability in the Linux kernel's tracing subsystem allows local attackers to cause a kernel panic (denial of service) by...

May 1, 2025
CVE-2025-37793
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ASoC Intel AVS driver allows local attackers to cause a kernel panic (system crash) or ...

May 1, 2025
CVE-2025-37783
5.5

A NULL pointer dereference vulnerability in the Linux kernel's DRM/MSM DPU driver could cause kernel crashes or instability when handling certain grap...

May 1, 2025
CVE-2025-37758
5.5

A NULL pointer dereference vulnerability in the Linux kernel's PATA PXA driver could cause kernel crashes or denial of service. This affects systems u...

May 1, 2025
CVE-2025-37748
5.5

This vulnerability is a NULL pointer dereference in the MediaTek IOMMU driver of the Linux kernel, occurring during device initialization. It allows l...

May 1, 2025
CVE-2025-23146
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's ENE-KB3930 MFD driver. If exploited, it could cause a kernel panic o...

May 1, 2025
CVE-2025-23148
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Exynos ChipID driver could cause kernel panic or system crash when accessing uninitiali...

May 1, 2025
CVE-2025-46399
5.5

A NULL pointer dereference vulnerability exists in fig2dev's genge_itp_spline function, allowing local attackers to cause denial of service through in...

Apr 23, 2025
CVE-2025-38049
5.5

A NULL pointer dereference vulnerability in the Linux kernel's x86 resctrl subsystem occurs when creating new control groups on platforms without cach...

Apr 18, 2025
CVE-2025-38240
5.5

This vulnerability is a NULL pointer dereference in the Linux kernel's MediaTek DisplayPort driver. It occurs when error logging functions attempt to ...

Apr 18, 2025
CVE-2020-36789
5.5

This Linux kernel vulnerability in the CAN network subsystem could cause a kernel warning or potential NULL pointer dereference when CAN drivers proce...

Apr 17, 2025
CVE-2025-23137
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's AMD CPU frequency scaling driver (amd-pstate). If exploited, it coul...

Apr 16, 2025
CVE-2025-22099
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's Xilinx ZynqMP display subsystem driver. If exploited, it could cause...

Apr 16, 2025
CVE-2025-22103
5.5

A race condition in the Linux kernel's networking subsystem causes a NULL pointer dereference when deleting L3S mode ipvlan interfaces. This vulnerabi...

Apr 16, 2025
CVE-2025-22089
5.5

A Linux kernel vulnerability in the RDMA subsystem allows exposure of hardware counters to non-initial network namespaces, leading to a kernel NULL po...

Apr 16, 2025
CVE-2025-22093
5.5

A NULL pointer dereference vulnerability in the Linux kernel's AMD display driver allows local attackers to cause a kernel panic (denial of service) w...

Apr 16, 2025
CVE-2025-22084
5.5

A race condition in the Linux kernel's w1 (1-Wire) subsystem can cause a NULL pointer dereference when initializing UART-based 1-Wire bus masters. Thi...

Apr 16, 2025
CVE-2025-22066
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's ASoC imx-card driver. When devm_kasprintf() fails to allocate memory...

Apr 16, 2025
CVE-2025-22062
5.5

A race condition vulnerability in the Linux kernel's SCTP protocol implementation allows concurrent calls to UDP socket start/stop functions, potentia...

Apr 16, 2025
CVE-2025-22051
5.5

A NULL pointer dereference vulnerability in the Linux kernel's GPIB driver for Agilent USB dongles allows local attackers to cause a kernel panic (sys...

Apr 16, 2025
CVE-2025-22037
5.5

A null pointer dereference vulnerability in the Linux kernel's ksmbd SMB server allows attackers to crash the kernel by sending a malformed SMB2 negot...

Apr 16, 2025

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,254 CVEs classified as CWE-476, with 22 rated critical and 304 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free