CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,258
Total CVEs
22
Critical
308
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 22
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 18
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,258)

CVE-2025-21723
5.5

A NULL pointer dereference vulnerability in the Linux kernel's mpi3mr SCSI driver can cause a kernel crash when the driver's BSG (Block SCSI Generic) ...

Feb 27, 2025
CVE-2025-21713
5.5

A NULL pointer dereference vulnerability in the Linux kernel's powerpc/pseries/iommu subsystem allows local attackers to cause a kernel panic (denial ...

Feb 27, 2025
CVE-2024-57987
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Bluetooth subsystem allows kernel crashes when unsupported USB Bluetooth dongles are in...

Feb 27, 2025
CVE-2024-57989
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's MediaTek MT7925 WiFi driver. When the mt7925_change_vif_links() func...

Feb 27, 2025
CVE-2024-57981
5.5

A NULL pointer dereference vulnerability in the Linux kernel's xHCI USB driver can cause kernel crashes when certain USB commands are aborted. This af...

Feb 27, 2025
CVE-2024-57978
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's imx-jpeg media driver. The issue occurs when the detach_pm() functio...

Feb 27, 2025
CVE-2022-49731
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's ATA subsystem. If exploited, it could cause a kernel panic (system c...

Feb 26, 2025
CVE-2022-49703
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ibmvfc SCSI driver allows a crash during kexec/kdump operations on Power 9 systems with...

Feb 26, 2025
CVE-2022-49699
5.5

A race condition vulnerability in the Linux kernel's filemap subsystem can cause a NULL pointer dereference when handling sibling entries during concu...

Feb 26, 2025
CVE-2022-49688
5.5

A NULL pointer dereference vulnerability in the Linux kernel's AFS (Andrew File System) client allows local attackers to cause a kernel panic (denial ...

Feb 26, 2025
CVE-2022-49615
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ASoC rt711-sdca audio driver can cause kernel panic when an I/O error occurs during ini...

Feb 26, 2025
CVE-2022-49582
5.5

A NULL pointer dereference vulnerability in the Linux kernel's DSA (Distributed Switch Architecture) subsystem allows local attackers to cause a kerne...

Feb 26, 2025
CVE-2022-49569
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's BCM2835 SPI driver. When an IRQ-based SPI transfer times out, the er...

Feb 26, 2025
CVE-2022-49544
5.5

This CVE is a NULL pointer dereference vulnerability in the Linux kernel's ipw2x00 wireless driver. It could allow local attackers to cause a kernel p...

Feb 26, 2025
CVE-2022-49538
5.5

This CVE describes a race condition vulnerability in the Linux kernel's ALSA sound subsystem where the input_dev pointer could become NULL while being...

Feb 26, 2025
CVE-2022-49527
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Venus media driver could cause kernel panic or system crash when specific error conditi...

Feb 26, 2025
CVE-2022-49529
5.5

A null pointer dereference vulnerability in the Linux kernel's AMD GPU driver (amdgpu) can cause kernel panics when the software SMU (System Managemen...

Feb 26, 2025
CVE-2022-49510
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's OMAP DRM driver. An attacker could potentially cause a kernel panic ...

Feb 26, 2025
CVE-2022-49516
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's Intel Ethernet Connection (ice) driver. The vulnerability occurs whe...

Feb 26, 2025
CVE-2022-49490
5.5

A NULL pointer dereference vulnerability in the Linux kernel's MSM DRM driver could cause kernel crashes or denial of service. This affects systems us...

Feb 26, 2025
CVE-2022-49492
5.5

A NULL pointer dereference vulnerability in the Linux kernel's NVMe driver allows local attackers to cause a kernel panic (denial of service) by trigg...

Feb 26, 2025
CVE-2022-49494
5.5

This CVE describes a NULL pointer dereference vulnerability in the Cadence NAND driver of the Linux kernel. If exploited, it could cause a kernel pani...

Feb 26, 2025
CVE-2022-49498
5.5

This CVE addresses a null pointer dereference vulnerability in the Linux kernel's ALSA PCM subsystem. If exploited, it could cause a kernel panic lead...

Feb 26, 2025
CVE-2022-49484
5.5

A NULL pointer dereference vulnerability in the Linux kernel's MediaTek MT7915 wireless driver could cause kernel panics or system crashes when proces...

Feb 26, 2025
CVE-2022-49488
5.5

This vulnerability is a NULL pointer dereference in the Linux kernel's MSM DRM/MDP5 display driver. When a deadlock occurs while acquiring the modeset...

Feb 26, 2025
CVE-2022-49472
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Micrel PHY driver allows local attackers to cause a kernel panic (denial of service) by...

Feb 26, 2025
CVE-2022-49475
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's SPI-FSL-QSPI driver. If exploited, it could cause a kernel panic lea...

Feb 26, 2025
CVE-2022-49445
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's Renesas pinctrl driver. If exploited, it could cause a kernel panic ...

Feb 26, 2025
CVE-2022-49429
5.5

A NULL pointer dereference vulnerability in the Linux kernel's hfi1 RDMA driver causes kernel panic when SDMA capability is disabled. This affects sys...

Feb 26, 2025
CVE-2022-49435
5.5

A null pointer dereference vulnerability in the Linux kernel's davinci_voicecodec driver could cause kernel crashes or system instability when the dri...

Feb 26, 2025
CVE-2022-49417
5.5

A NULL pointer dereference vulnerability in the iwlwifi driver's MEI component in the Linux kernel could cause kernel crashes or potential privilege e...

Feb 26, 2025
CVE-2022-49423
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's rtla (Real-Time Linux Analysis) tools. If exploited, it could cause ...

Feb 26, 2025
CVE-2022-49425
5.5

This CVE describes a use-after-free vulnerability in the Linux kernel's F2FS filesystem driver where a stale list iterator pointer could be dereferenc...

Feb 26, 2025
CVE-2022-49400
5.5

This is a NULL pointer dereference vulnerability in the Linux kernel's RAID0 implementation that can cause kernel panics and system crashes. It affect...

Feb 26, 2025
CVE-2022-49392
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's 8250_aspeed_vuart driver. If platform_get_resource() fails and retur...

Feb 26, 2025
CVE-2022-49375
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's MediaTek MT6397 RTC driver. If platform_get_resource() returns NULL,...

Feb 26, 2025
CVE-2022-49335
5.5

A NULL pointer dereference vulnerability in the AMD GPU driver for Linux kernel allows local attackers to cause a kernel panic (denial of service) by ...

Feb 26, 2025
CVE-2022-49329
5.5

CVE-2022-49329 is a NULL pointer dereference vulnerability in the Linux kernel's vduse (vDPA Device in Userspace) subsystem. When accessing the contro...

Feb 26, 2025
CVE-2022-49302
5.5

A null pointer dereference vulnerability in the Linux kernel's ISP116x USB host controller driver allows local attackers to cause a kernel panic (syst...

Feb 26, 2025
CVE-2022-49285
5.5

A NULL pointer dereference vulnerability in the Linux kernel's MMA8452 accelerometer driver allows local attackers to cause a kernel panic (denial of ...

Feb 26, 2025
CVE-2022-49271
5.5

A NULL pointer dereference vulnerability in the Linux kernel's CIFS/SMB2 implementation allows local users to cause a kernel panic or potentially esca...

Feb 26, 2025
CVE-2022-49273
5.5

A null pointer dereference vulnerability in the Linux kernel's PL031 RTC driver allows local attackers to cause a kernel panic (system crash) when the...

Feb 26, 2025
CVE-2022-49262
5.5

A NULL pointer dereference vulnerability in the Linux kernel's octeontx2 crypto driver allows local attackers to cause a kernel panic (denial of servi...

Feb 26, 2025
CVE-2022-49264
5.5

This Linux kernel vulnerability allows privilege escalation when execve() is called with an empty argv (argument vector). It affects Linux systems whe...

Feb 26, 2025
CVE-2022-49268
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Sound Open Firmware (SOF) subsystem for Intel platforms occurs when memory allocation f...

Feb 26, 2025
CVE-2022-49257
5.5

This is a NULL pointer dereference vulnerability in the Linux kernel's watch_queue subsystem. It allows local attackers to trigger a kernel panic (den...

Feb 26, 2025
CVE-2022-49232
5.5

This CVE describes a NULL pointer dereference vulnerability in the AMD GPU display driver component of the Linux kernel. If exploited, it could cause ...

Feb 26, 2025
CVE-2022-49228
5.5

A NULL pointer dereference vulnerability in the Linux kernel's BPF subsystem allows local attackers to cause a denial of service (kernel panic) by tri...

Feb 26, 2025
CVE-2022-49214
5.5

This CVE describes a Linux kernel bug on PowerPC systems where SLB (Segment Lookaside Buffer) faults incorrectly report read operations as writes in e...

Feb 26, 2025
CVE-2022-49195
5.5

A NULL pointer dereference vulnerability in the Linux kernel's DSA (Distributed Switch Architecture) subsystem causes kernel panics during system shut...

Feb 26, 2025

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,258 CVEs classified as CWE-476, with 22 rated critical and 308 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free