CWE-835: Infinite Loop
The product contains an iteration or loop with an exit condition that cannot be reached, leading to an infinite loop.
Yearly Trend
Top Affected Vendors
All Infinite Loop CVEs (137)
A Linux kernel vulnerability in Coresight debugging infrastructure on Qualcomm QCS615 systems creates an infinite loop when only source devices are en...
Aug 22, 2025A race condition vulnerability in the Linux kernel's IPv6 routing subsystem could cause an infinite loop in the fib6_info_uses_dev() function when RCU...
Aug 19, 2025A race condition vulnerability in the Linux kernel's IPv6 routing subsystem can cause an infinite loop in the rt6_nlmsg_size() function when reading R...
Aug 19, 2025A use-after-free vulnerability in the Linux kernel's HFSC scheduler allows local attackers to cause denial of service or potentially execute arbitrary...
Jun 6, 2025This CVE describes a denial-of-service vulnerability in the Linux kernel's dm-crypt subsystem where the dmcrypt_write() function could cause a soft lo...
May 2, 2025A race condition in the Linux kernel's BTRFS filesystem for zoned storage devices causes a deadlock when handling allocation failures. This vulnerabil...
Apr 1, 2025A Linux kernel vulnerability in the RDMA subsystem allows an integer overflow when registering DMA memory regions with specific alignment conditions. ...
Mar 27, 2025This CVE addresses a denial-of-service vulnerability in the Linux kernel's NFS writeback mechanism. In low memory conditions, NFS writeback threads co...
Feb 26, 2025A denial-of-service vulnerability in the Linux kernel's Open vSwitch (OVS) module causes system lockups when transmitting packets to network devices t...
Jan 31, 2025A missing loop break condition in the imx8mp-blk-ctrl power domain driver in the Linux kernel causes an out-of-bounds access during device shutdown, l...
Jan 31, 2025A denial-of-service vulnerability in the Linux kernel's exFAT filesystem driver where a corrupted filesystem with a self-referencing cluster chain cau...
Jan 21, 2025A denial-of-service vulnerability in the Linux kernel's Ceph filesystem driver where ceph_mdsc_build_path() enters an endless retry loop when processi...
Jan 11, 2025A Linux kernel vulnerability in the BPF subsystem allows an infinite loop when using tail calls with freplace programs, leading to kernel panic and de...
Jan 11, 2025A race condition in the Linux kernel's IPv6 routing subsystem can cause soft lockups and system panics when routers experience high next-hop churn in ...
Dec 28, 2024A Linux kernel vulnerability in the iwlwifi driver causes an infinite loop when constructing 6 GHz scans if more than 255 colocated access points are ...
Nov 19, 2024This Linux kernel vulnerability involves a missing empty item in the ASoC Intel RPL matching code, which could cause the kernel to read beyond array b...
Oct 21, 2024A deadlock vulnerability in the Linux kernel's SGX (Software Guard Extensions) NUMA node search can cause soft lockups when the current CPU node lacks...
Oct 21, 2024A Linux kernel vulnerability in the SUNRPC subsystem causes an infinite loop when a BPF program returns -EPERM during TCP connection setup. This can l...
Aug 7, 2024This CVE describes a kernel warning issue in Linux systems with Branch History Injection (BHI) mitigation enabled. When SYSENTER is invoked with the s...
Aug 7, 2024A vulnerability in the Linux kernel's vhost subsystem allows a local attacker to cause a denial of service by sending a malformed IOTLB message that c...
Jul 16, 2024A Linux kernel vulnerability in the SMC (Shared Memory Communications) networking subsystem allows infinite recursion when fallback occurs multiple ti...
Jul 16, 2024This CVE describes a memory access vulnerability in the Linux kernel's SUNRPC implementation where the gss_free_in_token_pages() function incorrectly ...
Jun 21, 2024A vulnerability in the Linux kernel's ext4 filesystem implementation allows an infinite loop condition during fast commit replay when processing corru...
May 21, 2024A vulnerability in the Linux kernel's virtio_net driver causes a kernel infinite loop when attempting to configure RSS (Receive Side Scaling) on virti...
May 20, 2024This Android vulnerability allows local attackers with user privileges to trigger a persistent reboot loop through improper input validation, causing ...
Mar 24, 2023This Android vulnerability allows local attackers with user privileges to trigger a persistent reboot loop through improper input validation, causing ...
Mar 24, 2023This vulnerability in bn.js versions before 5.2.3 allows attackers to cause denial of service by calling maskn(0) on any BN instance, which corrupts i...
Feb 20, 2026CVE-2025-58190 is a denial-of-service vulnerability in Go's html.Parse function that causes infinite parsing loops when processing specially crafted H...
Feb 5, 2026This vulnerability in NGINX Unit with the Java Language Module allows remote attackers to send specific requests that trigger an infinite loop, causin...
Mar 4, 2025CVE-2024-34484 is a denial-of-service vulnerability in Faucet SDN Ryu's OFPBucket parser where setting action.len=0 triggers an infinite loop. This af...
May 5, 2024This vulnerability in Wireshark's HTTP3 protocol dissector causes an infinite loop when processing specially crafted packets, leading to denial of ser...
Jan 14, 2026CVE-2026-24688 is an infinite loop vulnerability in pypdf, a Python PDF library. Attackers can craft malicious PDFs that cause denial of service when ...
Jan 27, 2026A denial-of-service vulnerability in GitLab CE/EE allows attackers to cause background jobs to become unresponsive by exploiting CI artifacts metadata...
Jan 28, 2025This CVE describes an infinite loop vulnerability in the ChangeDomainAction.java component of the datavane TIS platform. Attackers could trigger this ...
Jan 27, 2026This CVE describes an infinite loop vulnerability in jsonrpc4j's NoCloseOutputStream.java that can cause denial of service. Applications using affecte...
Jan 27, 2026This CVE describes an infinite loop vulnerability in the mt7615d Wi-Fi driver security modules of the coolsnowwolf LEDE firmware. Attackers could caus...
Jan 27, 2026This CVE describes an infinite loop vulnerability in the mt7603 WiFi driver module of the coolsnowwolf LEDE router firmware. An attacker could cause d...
Jan 27, 2026About Infinite Loop (CWE-835)
The product contains an iteration or loop with an exit condition that cannot be reached, leading to an infinite loop.
Our database tracks 137 CVEs classified as CWE-835, with 1 rated critical and 85 rated high severity. The average CVSS score for Infinite Loop vulnerabilities is 6.9.
External reference: View CWE-835 on MITRE CWE →
Monitor Infinite Loop Vulnerabilities
Get alerted when new Infinite Loop CVEs affect your infrastructure.
Start Monitoring Free