CWE-667— Improper Locking
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.— MITRE CWE catalog
745 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-667page 14 of 15
- CVE-2024-0639MEDIUMCVSS 5.5EG 5.52024-01-17
A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially cr…
- CVE-2023-34320MEDIUMCVSS 5.5EG 5.52023-12-08
Cortex-A77 cores (r0p0 and r1p0) are affected by erratum 1508412 where software, under certain circumstances, could deadlock a core due to the execution of either a load to device or non-cacheable memory, and either a store exclusive or re…
- CVE-2023-2430MEDIUMCVSS 5.5EG 5.52023-07-23
A vulnerability was found due to missing lock for IOPOLL flaw in io_cqring_event_overflow() in io_uring.c in Linux Kernel. This flaw allows a local attacker with user privilege to trigger a Denial of Service threat.
- CVE-2021-43395MEDIUMCVSS 5.5EG 5.52022-12-26
An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via cr…
- CVE-2022-42329MEDIUMCVSS 5.5EG 5.52022-12-07
Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might…
- CVE-2022-42328MEDIUMCVSS 5.5EG 5.52022-12-07
Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might…
- CVE-2022-42775MEDIUMCVSS 5.5EG 5.52022-12-06
In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.
- CVE-2022-39131MEDIUMCVSS 5.5EG 5.52022-12-06
In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.
- CVE-2022-4129MEDIUMCVSS 5.5EG 5.52022-11-28
A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can lead to a race condition and NULL pointer dereference. A local user could use this flaw to potentially crash the system…
- CVE-2022-38690MEDIUMCVSS 5.5EG 5.52022-10-14
In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.
- CVE-2022-38791MEDIUMCVSS 5.5EG 5.52022-08-27
In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.
- CVE-2022-31624MEDIUMCVSS 5.5EG 5.52022-05-25
MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method log_statement_ex, the held lock lock_bigbuffer is not released correctly, which allows local users to trigger a de…
- CVE-2022-31623MEDIUMCVSS 5.5EG 5.52022-05-25
MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (i.e., going to the err label) while executing the method create_worker_threads, the held lock thd->ctrl_mutex is not …
- CVE-2022-31622MEDIUMCVSS 5.5EG 5.52022-05-25
MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (pthread_create returns a nonzero value) while executing the method create_worker_threads, the held lock is not releas…
- CVE-2022-31621MEDIUMCVSS 5.5EG 5.52022-05-25
MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_xbstream.cc, when an error occurs (stream_ctxt->dest_file == NULL) while executing the method xbstream_open, the held lock is not released correctly, wh…
- CVE-2021-4149MEDIUMCVSS 5.5EG 5.52022-03-23
A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock pro…
- CVE-2021-41213MEDIUMCVSS 5.5EG 5.52021-11-05
TensorFlow is an open source platform for machine learning. In affected versions the code behind `tf.function` API can be made to deadlock when two `tf.function` decorated Python functions are mutually recursive. This occurs due to using a…
- CVE-2021-1123MEDIUMCVSS 5.5EG 5.52021-10-29
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can deadlock, which may lead to denial of service.
- CVE-2021-38203MEDIUMCVSS 5.5EG 5.52021-08-08
btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.
- CVE-2021-28951MEDIUMCVSS 5.5EG 5.52021-03-20
An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (deadlock) because exit may be waiting to park a SQPOLL thread, but concurrently that SQPOLL thread is waiting fo…
- CVE-2020-27035MEDIUMCVSS 5.5EG 5.52020-12-15
In priorLinearAllocation of C2AllocatorIon.cpp, there is a possible use-after-free due to improper locking. This could lead to local information disclosure in the media codec with no additional execution privileges needed. User interaction…
- CVE-2020-12771MEDIUMCVSS 5.5EG 5.52020-05-09
An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails.
- CVE-2019-9268MEDIUMCVSS 5.5EG 5.52019-09-27
In libstagefright, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploita…
- CVE-2019-14763MEDIUMCVSS 5.5EG 5.52019-08-07
In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c may potentially cause a deadlock with f_hid.
- CVE-2019-2119MEDIUMCVSS 5.5EG 5.52019-07-08
In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to improper locking. This could lead to local information disclosure of protected data with no additional execution privileges needed. User inte…
- CVE-2009-2857MEDIUMCVSS 5.5EG 5.52009-08-19
The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and sys…
- CVE-2009-1388MEDIUMCVSS 5.5EG 5.52009-07-05
The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution of the do_coredump function, which allows local users to cause a denial of service (deadlock) via vectors involving the…
- CVE-2009-1243MEDIUMCVSS 5.5EG 5.52009-04-06
net/ipv4/udp.c in the Linux kernel before 2.6.29.1 performs an unlocking step in certain incorrect circumstances, which allows local users to cause a denial of service (panic) by reading zero bytes from the /proc/net/udp file and unspecifi…
- CVE-2009-0935MEDIUMCVSS 5.5EG 5.52009-03-18
The inotify_read function in the Linux kernel 2.6.27 to 2.6.27.13, 2.6.28 to 2.6.28.2, and 2.6.29-rc3 allows local users to cause a denial of service (OOPS) via a read with an invalid address to an inotify instance, which causes the device…
- CVE-2008-4302MEDIUMCVSS 5.5EG 5.52008-09-29
fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to c…
- CVE-2006-4342MEDIUMCVSS 5.5EG 5.52006-10-17
The kernel in Red Hat Enterprise Linux 3, when running on SMP systems, allows local users to cause a denial of service (deadlock) by running the shmat function on an shm at the same time that shmctl is removing that shm (IPC_RMID), which p…
- CVE-2006-2374MEDIUMCVSS 5.5EG 5.52006-06-13
The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with th…
- CVE-2005-3847MEDIUMCVSS 5.5EG 5.52005-11-27
The handle_stop_signal function in signal.c in Linux kernel 2.6.11 up to other versions before 2.6.13 and 2.6.12.6 allows local users to cause a denial of service (deadlock) by sending a SIGKILL to a real-time threaded process while it is …
- CVE-2005-2456MEDIUMCVSS 5.5EG 5.52005-08-04
Array index overflow in the xfrm_sk_policy_insert function in xfrm_user.c in Linux kernel 2.6 allows local users to cause a denial of service (oops or deadlock) and possibly execute arbitrary code via a p->dir value that is larger than XFR…
- CVE-2002-1914MEDIUMCVSS 5.5EG 5.52002-12-31
dump 0.4 b10 through b29 allows local users to cause a denial of service (execution prevention) by using flock() to lock the /etc/dumpdates file.
- CVE-2002-1915MEDIUMCVSS 5.5EG 5.52002-12-31
tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.
- CVE-2000-1198MEDIUMCVSS 5.5EG 5.52001-08-31
qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.
- CVE-2001-0682MEDIUMCVSS 5.5EG 5.52001-08-29
ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting.
- CVE-2000-0338MEDIUMCVSS 5.5EG 5.52000-04-23
Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.
- CVE-2024-42114MEDIUMCVSS 4.4EG 5.52024-07-30
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: restrict NL80211_ATTR_TXQ_QUANTUM values syzbot is able to trigger softlockups, setting NL80211_ATTR_TXQ_QUANTUM to 2^31. We had a similar issue in sch_…
- CVE-2023-2269MEDIUMCVSS 4.4EG 5.52023-04-25
A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component.
- CVE-2026-46223MEDIUMEG 5.52026-05-28
In the Linux kernel, the following vulnerability has been resolved: cgroup: Defer css percpu_ref kill on rmdir until cgroup is depopulated A chain of commits going back to v7.0 reworked rmdir to satisfy the controller invariant that a su…
- CVE-2026-46165MEDIUMEG 5.52026-05-28
In the Linux kernel, the following vulnerability has been resolved: openvswitch: vport: fix self-deadlock on release of tunnel ports vports are used concurrently and protected by RCU, so netdev_put() must happen after the RCU grace perio…
- CVE-2026-46156MEDIUMEG 5.52026-05-28
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang() The switch case in loongson_gpu_fixup_dma_hang() may not DC2 or DC3, and readl(crtc_reg) will access with r…
- CVE-2025-21767MEDIUMEG 5.52025-02-27
In the Linux kernel, the following vulnerability has been resolved: clocksource: Use migrate_disable() to avoid calling get_random_u32() in atomic context The following bug report happened with a PREEMPT_RT kernel: BUG: sleeping funct…
- CVE-2025-14345MEDIUMCVSS 5.4EG 5.42025-12-09
A post-authentication flaw in the network two-phase commit protocol used for cross-shard transactions in MongoDB Server may lead to logical data inconsistencies under specific conditions which are not predictable and exist for a very shor…
- CVE-2026-10647MEDIUMCVSS 5.3EG 5.32026-06-29
The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep_enqueue() in its ethernet transmit callback cdc_ncm_send(). When the enqueue fails, the function still calls k_sem_take(&data->s…
- CVE-2026-42489MEDIUMCVSS 5.3EG 5.32026-06-18
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To create and manage guests, domctl operations are used by the control domain, a possible Xenstore domain, or…
- CVE-2024-38582MEDIUMCVSS 5.3EG 5.32024-06-19
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential hang in nilfs_detach_log_writer() Syzbot has reported a potential hang in nilfs_detach_log_writer() called during nilfs2 unmount. Analysis reveale…
- CVE-2023-52699MEDIUMCVSS 5.3EG 5.32024-05-19
In the Linux kernel, the following vulnerability has been resolved: sysv: don't call sb_bread() with pointers_lock held syzbot is reporting sleep in atomic context in SysV filesystem [1], for sb_bread() is called with rw_spinlock held. …
Map vulnerabilities like CWE-667 to your infrastructure
EchelonGraph correlates every CVE — across CWE-667 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →