CWE-667

Improper Locking

Parent: CWE-662 - Improper Synchronization

The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.

682 vulnerabilities with CWE-667
CVE-2026-31756 MEDIUM
usb: dwc2: gadget: Fix spin_lock/unlock mismatch in dwc2_hsotg_udc_stop()
CVSS 5.5
CVE-2026-31687 MEDIUM
gpio: omap: do not register driver in probe()
CVSS 5.5
CVE-2026-31667 HIGH
Input: uinput - fix circular locking dependency with ff-core
CVSS 7.8
CVE-2026-31629 HIGH
nfc: llcp: add missing return after LLCP_CLOSED checks
CVSS 8.8
CVE-2026-31598 HIGH
ocfs2: fix possible deadlock between unlink and dio_end_io_write
CVSS 7.5
CVE-2026-31565 MEDIUM
RDMA/irdma: Fix deadlock during netdev reset with active connections
CVSS 5.5
CVE-2026-31526 MEDIUM
bpf: Fix exception exit lock checking for subprogs
CVSS 5.5
CVE-2026-31509 MEDIUM
nfc: nci: fix circular locking dependency in nci_close_device
CVSS 5.5
CVE-2026-31499 MEDIUM
Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del()
CVSS 5.5
CVE-2026-31487 MEDIUM
spi: use generic driver_override infrastructure
CVSS 5.5
CVE-2026-31486 HIGH
hwmon: (pmbus/core) Protect regulator operations with mutex
CVSS 7.1
CVE-2026-31480 MEDIUM
tracing: Fix potential deadlock in cpu hotplug with osnoise
CVSS 5.5
CVE-2026-31467 HIGH
erofs: add GFP_NOIO in the bio completion if needed
CVSS 7.5
CVE-2026-31420 MEDIUM
bridge: mrp: reject zero test interval to avoid OOM panic
CVSS 5.5
CVE-2026-23470 MEDIUM
drm/imagination: Fix deadlock in soft reset sequence
CVSS 5.5
CVE-2026-23419 HIGH
net/rds: Fix circular locking dependency in rds_tcp_tune
CVSS 7.5
CVE-2026-23368 MEDIUM
net: phy: register phy led_triggers during probe to avoid AB-BA deadlock
CVSS 5.5
CVE-2026-23362 MEDIUM
can: bcm: fix locking for bcm_op runtime updates
CVSS 5.5
CVE-2026-23357 MEDIUM
can: mcp251x: fix deadlock in error path of mcp251x_open
CVSS 5.5
CVE-2026-23311 MEDIUM
perf/core: Fix invalid wait context in ctx_sched_in()
CVSS 5.5
CVE-2026-23295 MEDIUM
accel/amdxdna: Fix dead lock for suspend and resume
CVSS 5.5
CVE-2026-22735 LOW
Server Sent Event stream corruption
CVSS 2.6
CVE-2026-20065 MEDIUM
Cisco Snort 3 Detection Engine - Unauthenticated Denial of Service via Binder Module Initialization
CVSS 5.8
CVE-2026-23232 MEDIUM
Linux Kernel 6.19-6.19.2 - Denial of Service via Deadlock in f2fs Checkpoint Mechanism
CVSS 5.5
CVE-2026-20757 LOW
Gallagher Command Centre Server - DoS
CVSS 2.5
Details
Vulnerabilities 682