CWE-908: CWE-908

203
Total CVEs
22
Critical
71
High
6.7
Avg CVSS

Yearly Trend

2026
7
2025
85
2024
70
2023
10
2022
3

Top Affected Vendors

1 Linux 117
2 Debian 25
3 Microsoft 24
4 Google 11
5 Mozilla 3
6 Gnu 2
7 Redhat 2
8 Messagepack Rs Project 2
9 Ivanti 1
10 Synchro 1

All CWE-908 CVEs (203)

CVE-2024-57877
6.1

This CVE describes an information disclosure vulnerability in the Linux kernel's ARM64 ptrace subsystem. When a zero-length SETREGSET call is made to ...

Jan 11, 2025
CVE-2025-50157
5.7

This vulnerability in Windows Routing and Remote Access Service (RRAS) involves uninitialized resource usage that could allow authenticated attackers ...

Aug 12, 2025
CVE-2024-11991
5.6

CVE-2024-11991 is an uninitialized memory access vulnerability in Motoko's incremental garbage collector that could allow unauthorized read or write a...

Dec 9, 2024
CVE-2025-68365
5.5

This CVE describes an uninitialized memory vulnerability in the Linux kernel's NTFS3 filesystem driver. When reading NTFS headers, the driver uses mem...

Dec 24, 2025
CVE-2022-50482
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's Intel VT-d (Virtualization Technology for Directed I/O) subsystem. When the init_...

Oct 4, 2025
CVE-2025-39931
5.5

A use-after-free vulnerability in the Linux kernel's cryptographic subsystem (af_alg) could cause kernel crashes or potential privilege escalation. Th...

Oct 4, 2025
CVE-2023-53525
5.5

This CVE-2023-53525 is a kernel memory initialization vulnerability in the Linux kernel's RDMA/CMA subsystem. It allows uninitialized memory access wh...

Oct 1, 2025
CVE-2023-53532
5.5

A logic error in the Linux kernel's ath11k WiFi driver causes a NULL pointer dereference during system shutdown or module removal on certain Qualcomm ...

Oct 1, 2025
CVE-2023-53462
5.5

This CVE describes an uninitialized value access vulnerability in the Linux kernel's HSR (High-availability Seamless Redundancy) protocol implementati...

Oct 1, 2025
CVE-2025-39904
5.5

This CVE describes an uninitialized memory vulnerability in the Linux kernel's kexec functionality on arm64 and riscv architectures. The uninitialized...

Oct 1, 2025
CVE-2023-53351
5.5

A race condition vulnerability in the Linux kernel's DRM scheduler component can cause a NULL pointer dereference during GPU fault handling, leading t...

Sep 17, 2025
CVE-2023-53344
5.5

This CVE-2023-53344 is a Linux kernel vulnerability in the CAN (Controller Area Network) subsystem's bcm_tx_setup function where uninitialized memory ...

Sep 17, 2025
CVE-2022-50374
5.5

A race condition vulnerability in the Linux kernel's Bluetooth subsystem where failure to initialize synchronization primitives can lead to NULL point...

Sep 17, 2025
CVE-2022-50346
5.5

A race condition vulnerability in the Linux kernel's ext4 filesystem during rename operations can trigger a kernel warning and potential denial of ser...

Sep 16, 2025
CVE-2025-39833
5.5

This CVE describes a kernel timer initialization bug in the Linux kernel's mISDN hfcpci driver that causes a warning/panic when unloading the module w...

Sep 16, 2025
CVE-2025-39812
5.5

This CVE describes an uninitialized memory vulnerability in the Linux kernel's SCTP IPv6 implementation. When sin6_scope_id and sin6_flowinfo fields a...

Sep 16, 2025
CVE-2022-50335
5.5

This CVE-2022-50335 is a use-after-free vulnerability in the Linux kernel's 9p filesystem client. It allows attackers to cause kernel memory corruptio...

Sep 15, 2025
CVE-2022-50282
5.5

A race condition vulnerability in the Linux kernel's cdev_device_add() function can cause a kernel panic when device registration fails. This affects ...

Sep 15, 2025
CVE-2023-53165
5.5

A memory access vulnerability in the Linux kernel's UDF filesystem driver allows reading uninitialized memory when processing certain filenames. This ...

Sep 15, 2025
CVE-2022-50236
5.5

This CVE describes a race condition vulnerability in the MediaTek IOMMU driver in the Linux kernel where an interrupt service routine (ISR) can be tri...

Sep 15, 2025
CVE-2025-53799
5.5

CVE-2025-53799 is an information disclosure vulnerability in Windows Imaging Component where uninitialized memory resources can be accessed by a local...

Sep 9, 2025
CVE-2025-39684
5.5

This CVE describes an information leak vulnerability in the Linux kernel's comedi subsystem, where uninitialized kernel memory can be exposed to users...

Sep 5, 2025
CVE-2025-39690
5.5

This CVE involves an uninitialized memory vulnerability in the Linux kernel's SCA3300 accelerometer driver. It could allow attackers to read uninitial...

Sep 5, 2025
CVE-2025-38691
5.5

This CVE describes a use-after-free vulnerability in the Linux kernel's pNFS block/scsi layout code where uninitialized pointers in the 'layoutupdate_...

Sep 4, 2025
CVE-2025-38658
5.5

A double completion vulnerability in the Linux kernel's NVMe over Fabrics target subsystem can cause kernel crashes when processing invalid NVMe comma...

Aug 22, 2025
CVE-2025-38644
5.5

This CVE describes a vulnerability in the Linux kernel's WiFi subsystem where TDLS (Tunneled Direct Link Setup) operations could be triggered before a...

Aug 22, 2025
CVE-2025-38608
5.5

This CVE describes a data corruption vulnerability in the Linux kernel's BPF subsystem when used with kTLS (Kernel TLS). When bpf_msg_pop_data() reduc...

Aug 19, 2025
CVE-2025-38613
5.5

This CVE involves an information disclosure vulnerability in the Linux kernel's GPIB (General Purpose Interface Bus) staging driver. Uninitialized pad...

Aug 19, 2025
CVE-2025-38531
5.5

This CVE describes a use-after-initialization vulnerability in the Linux kernel's IIO subsystem for STMicroelectronics sensors. When device probe func...

Aug 16, 2025
CVE-2025-38478
5.5

A kernel memory initialization vulnerability in Linux Comedi subsystem allows reading uninitialized kernel memory when handling certain device instruc...

Jul 28, 2025
CVE-2025-38441
5.5

A Linux kernel vulnerability in the netfilter flowtable component where the nf_flow_pppoe_proto() function fails to account for Ethernet header length...

Jul 25, 2025
CVE-2025-38086
5.5

This vulnerability in the Linux kernel's ch9200 network driver allows uninitialized memory access during MII (Media Independent Interface) operations....

Jun 28, 2025
CVE-2022-50165
5.5

This CVE-2022-50165 is an uninitialized variable vulnerability in the Linux kernel's wil6210 WiFi driver debugfs interface. It could allow local attac...

Jun 18, 2025
CVE-2022-50127
5.5

This vulnerability in the Linux kernel's RDMA over Converged Ethernet (RoCE) implementation causes a kernel panic (system crash) when error handling o...

Jun 18, 2025
CVE-2025-38072
5.5

A divide-by-zero vulnerability in the Linux kernel's libnvdimm driver occurs when a faulty CXL memory device reports a zero LSA size, causing a kernel...

Jun 18, 2025
CVE-2025-38006
5.5

A Linux kernel vulnerability in the MCTP (Management Component Transport Protocol) subsystem allows reading uninitialized memory when dumping network ...

Jun 18, 2025
CVE-2025-37996
5.5

A memory management vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) for ARM64 systems allows uninitialized memory pointer usage...

May 29, 2025
CVE-2025-37961
5.5

This CVE describes an uninitialized memory vulnerability in the Linux kernel's IPVS (IP Virtual Server) subsystem. The flaw occurs when the do_output_...

May 20, 2025
CVE-2022-49813
5.5

This CVE describes a resource leak vulnerability in the Linux kernel's Elastic Network Adapter (ENA) driver. When pci_register_driver() fails during i...

May 1, 2025
CVE-2025-37742
5.5

This CVE describes an uninitialized memory access vulnerability in the JFS filesystem implementation in the Linux kernel. When mounting a JFS filesyst...

May 1, 2025
CVE-2025-22119
5.5

A race condition vulnerability in the Linux kernel's cfg80211 WiFi subsystem where wiphy_work_lock is accessed before proper initialization when rfkil...

Apr 16, 2025
CVE-2025-22123
5.5

A use-after-free vulnerability in the Linux kernel's F2FS filesystem allows attackers to cause a kernel panic (denial of service) by accessing uniniti...

Apr 16, 2025
CVE-2025-21922
5.5

A memory initialization vulnerability in the Linux kernel's PPP driver allows uninitialized data to be read by carefully crafted BPF programs. This co...

Apr 1, 2025
CVE-2025-21787
5.5

A Linux kernel vulnerability in the team networking driver allows uninitialized memory disclosure when processing TEAM_OPTION_TYPE_STRING options. Thi...

Feb 27, 2025
CVE-2025-21716
5.5

A vulnerability in the Linux kernel's VXLAN virtual network filtering function allows reading uninitialized memory when processing malformed netlink m...

Feb 27, 2025
CVE-2025-21707
5.5

This CVE describes an uninitialized variable vulnerability in the Linux kernel's MPTCP (Multipath TCP) implementation. Attackers could potentially exp...

Feb 27, 2025
CVE-2022-49675
5.5

This CVE describes a Linux kernel vulnerability where an incorrectly exported initialization function could cause kernel panic if accessed after syste...

Feb 26, 2025
CVE-2022-49567
5.5

This CVE describes an uninitialized memory access vulnerability in the Linux kernel's memory policy subsystem. When a memory policy is set to MPOL_LOC...

Feb 26, 2025
CVE-2022-49433
5.5

This vulnerability in the Linux kernel's RDMA hfi1 driver allows a use-after-initialization condition where a lock is accessed before being properly i...

Feb 26, 2025
CVE-2022-49350
5.5

This CVE describes a Linux kernel vulnerability where the mdio_bus_init() function was incorrectly marked with both EXPORT_SYMBOL and __init annotatio...

Feb 26, 2025

About CWE-908 (CWE-908)

Our database tracks 203 CVEs classified as CWE-908, with 22 rated critical and 71 rated high severity. The average CVSS score for CWE-908 vulnerabilities is 6.7.

External reference: View CWE-908 on MITRE CWE →

Monitor CWE-908 Vulnerabilities

Get alerted when new CWE-908 CVEs affect your infrastructure.

Start Monitoring Free