CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,257
Total CVEs
22
Critical
307
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 22
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 18
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,257)

CVE-2025-22062
5.5

A race condition vulnerability in the Linux kernel's SCTP protocol implementation allows concurrent calls to UDP socket start/stop functions, potentia...

Apr 16, 2025
CVE-2025-22051
5.5

A NULL pointer dereference vulnerability in the Linux kernel's GPIB driver for Agilent USB dongles allows local attackers to cause a kernel panic (sys...

Apr 16, 2025
CVE-2025-22037
5.5

A null pointer dereference vulnerability in the Linux kernel's ksmbd SMB server allows attackers to crash the kernel by sending a malformed SMB2 negot...

Apr 16, 2025
CVE-2025-22032
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's MediaTek MT7921 WiFi driver. It can cause kernel panics and system c...

Apr 16, 2025
CVE-2025-22018
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ATM subsystem allows local attackers to cause a kernel panic (denial of service) by tri...

Apr 16, 2025
CVE-2025-30301
5.5

Adobe Framemaker versions 2020.8, 2022.6 and earlier contain a NULL pointer dereference vulnerability that allows attackers to cause denial-of-service...

Apr 8, 2025
CVE-2025-22015
5.5

A Linux kernel memory management vulnerability allows corruption of xarray entries during shmem page migration. This can lead to kernel memory corrupt...

Apr 8, 2025
CVE-2025-22017
5.5

This Linux kernel vulnerability in the devlink subsystem involves improper error handling when xa_alloc_cyclic() returns a value of 1 (indicating wrap...

Apr 8, 2025
CVE-2025-22006
5.5

A race condition vulnerability in the Linux kernel's TI AM65 CPSW Ethernet driver causes a NULL pointer dereference when network traffic arrives befor...

Apr 3, 2025
CVE-2025-21990
5.5

A NULL pointer dereference vulnerability in the AMD GPU driver of the Linux kernel could cause a kernel panic or system crash when handling PRT (Page ...

Apr 2, 2025
CVE-2025-21980
5.5

A NULL pointer dereference vulnerability in the Linux kernel's GRED scheduler could cause kernel crashes when memory allocation fails. This affects Li...

Apr 1, 2025
CVE-2025-21970
5.5

A NULL pointer dereference vulnerability in the Linux kernel's mlx5 bridge driver can cause a kernel crash when removing a Link Aggregation Group (LAG...

Apr 1, 2025
CVE-2025-21975
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's mlx5 network driver. If exploited, it could cause a kernel panic or ...

Apr 1, 2025
CVE-2025-21933
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's ARM page table handling. When the kernel attempts to migrate memory ...

Apr 1, 2025
CVE-2025-21936
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's Bluetooth subsystem. When mgmt_alloc_skb() fails to allocate memory ...

Apr 1, 2025
CVE-2025-21940
5.5

A NULL pointer dereference vulnerability exists in the Linux kernel's AMD KFD (Kernel Fusion Driver) component. This vulnerability allows local attack...

Apr 1, 2025
CVE-2025-21904
5.5

A NULL pointer dereference vulnerability in the Linux kernel's caif_virtio driver could cause kernel crashes or denial of service. The issue occurs wh...

Apr 1, 2025
CVE-2023-52991
5.5

A NULL pointer dereference vulnerability in the Linux kernel's network stack can cause kernel panic when processing UDP packets with GRO/GSO fraglist ...

Mar 27, 2025
CVE-2023-52993
5.5

A Linux kernel vulnerability where legacy PIC interrupts aren't properly marked as level-triggered, causing the kernel to incorrectly resend timer int...

Mar 27, 2025
CVE-2023-52984
5.5

A NULL pointer dereference vulnerability in the Linux kernel's DP83822 PHY driver affects DP83825/DP83826 devices. This allows local attackers to caus...

Mar 27, 2025
CVE-2023-52976
5.5

A NULL pointer dereference vulnerability in the Linux kernel's EFI subsystem could cause kernel panic or system crash when the efi_mem_reserve_persist...

Mar 27, 2025
CVE-2023-52938
5.5

A null pointer dereference vulnerability in the Linux kernel's USB Type-C UCSI driver allows local attackers to cause a kernel panic or system crash b...

Mar 27, 2025
CVE-2022-49758
5.5

This vulnerability is a null pointer dereference in the Linux kernel's uniphier-glue reset driver. It occurs when platform_get_resource() returns NULL...

Mar 27, 2025
CVE-2022-49756
5.5

A null pointer dereference vulnerability in the Linux kernel's Sunplus USB PHY driver could allow local attackers to cause a kernel panic (system cras...

Mar 27, 2025
CVE-2025-21870
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Sound Open Firmware (SOF) subsystem could cause kernel crashes when processing malforme...

Mar 27, 2025
CVE-2025-21864
5.5

A Linux kernel vulnerability where TCP connections in specific network namespace configurations can retain security path (secpath) references after th...

Mar 12, 2025
CVE-2025-21854
5.5

A NULL pointer dereference vulnerability in the Linux kernel's sockmap subsystem for vsock sockets could cause kernel crashes or denial of service. At...

Mar 12, 2025
CVE-2025-21857
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's net/sched subsystem. The flaw occurs when error handling in tcf_exts...

Mar 12, 2025
CVE-2025-21847
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Sound Open Firmware (SOF) subsystem could cause kernel crashes or denial of service. Th...

Mar 12, 2025
CVE-2025-21852
5.5

A NULL pointer dereference vulnerability in the Linux kernel's BPF subsystem allows unprivileged BPF programs to crash the kernel when accessing the r...

Mar 12, 2025
CVE-2025-21170
5.5

Substance3D Modeler versions 1.15.0 and earlier contain a NULL pointer dereference vulnerability that allows attackers to crash the application by tri...

Mar 11, 2025
CVE-2025-21833
5.5

This CVE addresses a NULL pointer dereference vulnerability in the Linux kernel's Intel VT-d (Virtualization Technology for Directed I/O) subsystem. I...

Mar 6, 2025
CVE-2024-58084
5.5

This CVE describes a missing read memory barrier in the Linux kernel's Qualcomm SCM firmware driver, specifically in the qcom_scm_get_tzmem_pool() fun...

Mar 6, 2025
CVE-2024-58067
5.5

This CVE involves a NULL pointer dereference vulnerability in the Linux kernel's clock controller driver for PXA1908 processors. If exploited, it coul...

Mar 6, 2025
CVE-2024-58073
5.5

This CVE addresses a NULL pointer dereference vulnerability in the Linux kernel's Direct Rendering Manager (DRM) for MSM/DPU display hardware. The fla...

Mar 6, 2025
CVE-2024-58058
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's UBIFS filesystem implementation. When slab cache is cleared, it can ...

Mar 6, 2025
CVE-2024-58065
5.5

This CVE-2024-58065 is a NULL pointer dereference vulnerability in the Linux kernel's clock controller driver for PXA1908 processors. It allows local ...

Mar 6, 2025
CVE-2024-58052
5.5

This CVE describes a NULL pointer dereference vulnerability in the AMD GPU driver for Linux kernel. The vulnerability could allow an attacker with loc...

Mar 6, 2025
CVE-2024-58022
5.5

This CVE fixes a NULL pointer dereference vulnerability in the TH1520 mailbox driver in the Linux kernel. The bug occurs when devm_ioremap() returns N...

Feb 27, 2025
CVE-2025-21799
5.5

A Linux kernel vulnerability in the TI AM65x CPSW Ethernet driver allows improper IRQ handling when changing network channel configurations. This can ...

Feb 27, 2025
CVE-2025-21783
5.5

A NULL pointer dereference vulnerability in the Linux kernel's gpiolib subsystem can cause kernel crashes when gpiochip_get_ngpios() is called via bgp...

Feb 27, 2025
CVE-2025-21775
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ctucanfd CAN bus driver could cause kernel crashes or system instability when skb alloc...

Feb 27, 2025
CVE-2025-21779
5.5

A NULL pointer dereference vulnerability in the Linux kernel's KVM hypervisor allows a malicious guest VM to crash the host kernel when Hyper-V enligh...

Feb 27, 2025
CVE-2025-21773
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's CAN bus driver for ETAS ES58x USB devices. An attacker could trigger...

Feb 27, 2025
CVE-2024-58021
5.5

A NULL pointer dereference vulnerability exists in the Linux kernel's winwing HID driver. If devm_kasprintf() fails and returns NULL in winwing_init_l...

Feb 27, 2025
CVE-2024-58012
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Sound Open Firmware (SOF) subsystem for Intel HDA audio devices could cause kernel cras...

Feb 27, 2025
CVE-2024-58019
5.5

A memory corruption vulnerability in the Linux kernel's NVIDIA GPU System Processor (GSP) driver allows local attackers to trigger a kernel panic (den...

Feb 27, 2025
CVE-2024-57834
5.5

A null pointer dereference vulnerability in the Linux kernel's vidtv media test driver allows local attackers to cause a kernel panic (denial of servi...

Feb 27, 2025
CVE-2025-21720
5.5

A NULL pointer dereference vulnerability in the Linux kernel's XFRM subsystem when IP forwarding is enabled with IPsec hardware offload. This causes k...

Feb 27, 2025
CVE-2025-21723
5.5

A NULL pointer dereference vulnerability in the Linux kernel's mpi3mr SCSI driver can cause a kernel crash when the driver's BSG (Block SCSI Generic) ...

Feb 27, 2025

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,257 CVEs classified as CWE-476, with 22 rated critical and 307 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free