CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,529 vulnerabilities with CWE-362
CVE-2026-46058 HIGH
media: amphion: Fix race between m2m job_abort and device_run
CVSS 7.8
CVE-2026-46025 MEDIUM
mm/damon/core: fix damon_call() vs kdamond_fn() exit race
CVSS 4.7
CVE-2026-46017 MEDIUM
mm: fix deferred split queue races during migration
CVSS 4.7
CVE-2026-46008 MEDIUM
mm/damon/core: fix damos_walk() vs kdamond_fn() exit race
CVSS 4.7
CVE-2026-45949 MEDIUM
hwrng: core - use RCU and work_struct to fix race condition
CVSS 4.7
CVE-2026-45945 HIGH
iommu/vt-d: Fix race condition during PASID entry replacement
CVSS 8.8
CVE-2026-45942 HIGH
ext4: fix e4b bitmap inconsistency reports
CVSS 7.8
CVE-2026-45910 HIGH
RDMA/rxe: Fix race condition in QP timer handlers
CVSS 7.8
CVE-2026-45905 MEDIUM
xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path
CVSS 4.7
CVE-2026-44443 MEDIUM
Lumiverse: Sign-up nonce race condition allows unauthorized account registration
CVSS 4.8
CVE-2026-24199 MEDIUM
Nvidia GeForce - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 4.7
CVE-2026-43981 HIGH
Algernon: Race Condition in handle() shared LState
CVE-2026-46727 HIGH
Ruby < 4.0.5 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 8.1
CVE-2026-4635 MEDIUM
Persistent notification timing attack causing server denial of service
CVSS 6.5
CVE-2026-44059 MEDIUM
Netatalk 2.2.5-4.4.2 and >=4.5.0 - Race Condition in Privilege Toggle Mechanism
CVSS 4.5
CVE-2026-5947 HIGH
SIG(0) validation during query flood may lead to undefined behavior
CVSS 7.5
CVE-2026-42099 HIGH
Race Condition in Sparx Pro Cloud Server
CVSS 7.5
CVE-2026-23558 HIGH
grant table v2 race in status page mapping
CVSS 7.8
CVE-2026-32848 MEDIUM
NetBSD cryptodev Race Condition Double-Free via cryptodev_op()
CVSS 4.7
CVE-2026-8741 LOW
EMQX QoS 2 PUBLISH Packet emqx_persistent_session_ds.erl race condition
CVSS 3.1
CVE-2026-45675 HIGH
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
CVSS 8.1
CVE-2026-41964 HIGH
Huawei HarmonyOS - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 8.4
CVE-2026-8520 HIGH
Google Chrome - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 8.3
CVE-2026-42594 HIGH
Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
CVSS 7.5
CVE-2026-28379 MEDIUM
Viewer-triggered race condition in Grafana Live leads to complete server crash
CVSS 6.5
Details
Vulnerabilities 2,529
Exploit Likelihood Medium