CWE-667

Improper Locking

Parent: CWE-662 - Improper Synchronization

The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.

722 vulnerabilities with CWE-667
CVE-2025-71309 MEDIUM
fs/ntfs3: fix deadlock in ni_read_folio_cmpr
CVSS 5.5
CVE-2025-71181 MEDIUM
Linux Kernel 6.18-6.18.5 - Deadlock via Recursive Locking in rust_shrink_free_page
CVSS 5.5
CVE-2025-69198 MEDIUM
Pterodactyl Panel < 1.12.0 - Unauthenticated Uncontrolled Resource Consumption via Concurrent Requests
CVSS 6.5
CVE-2025-71126 HIGH
Linux Kernel < 6.1.160, 6.2.0-6.6.120, 6.7.0-6.12.64, 6.13.0-6.18.3 - Deadlock via MPTCP Reinjection
CVSS 7.5
CVE-2025-71117 MEDIUM
Linux Kernel 6.11-6.18.2 - Deadlock via Sysfs Store Callback Queue Freezing
CVSS 5.5
CVE-2025-71104 MEDIUM
Linux Kernel - Denial of Service via APIC Timer Expiration Handling
CVSS 5.5
CVE-2025-71079 MEDIUM
Linux kernel - Lock Ordering Inversion
CVSS 5.5
CVE-2025-68823 MEDIUM
Linux Kernel - Deadlock in ublk Partition Table Handling
CVSS 5.5
CVE-2025-68657 MEDIUM
Espressif USB Host HID Driver < 1.1.0 - Double Free in hid_host_device_close
CVSS 6.4
CVE-2025-34467 MEDIUM
ZwiiCMS < 13.7.00 - Authenticated Denial of Service via Administrative Page Lock Persistence
CVSS 4.3
CVE-2025-68333 MEDIUM
Linux Kernel - Deadlock in sched_ext deferred_irq_workfn
CVSS 5.5
CVE-2025-68223 MEDIUM
Linux Kernel - Deadlock in DRM Radeon Fence Processing
CVSS 5.5
CVE-2025-43510 HIGH KEV
iPadOS < 18.7.2 - Memory Corruption via Improper Locking
CVSS 7.8
CVE-2025-14345 MEDIUM
MongoDB Server <8 - Privilege Escalation
CVSS 4.2
CVE-2025-48618 MEDIUM
Android - Physical Escalation of Privilege via Lockscreen Browser Interaction
CVSS 6.8
CVE-2025-63396 LOW
PyTorch 2.5 and 2.7.1 - Denial of Service via Profiler Finalization
CVSS 3.3
CVE-2025-10151 HIGH
Softing Industrial Automation GmbH - Buffer Overflow
CVE-2025-58153 MEDIUM
F5 BIG-IP 15.1.0-15.1.10.8 - Denial of Service via High-Speed Bridge Lockup
CVSS 5.9
CVE-2025-39915 MEDIUM
Linux Kernel 6.14-6.16.7 - Improper Locking in phylink_resolve
CVSS 5.5
CVE-2025-39910 MEDIUM
Linux Kernel 5.17-6.16.7 - Improper Locking in kasan_populate_vmalloc
CVSS 5.5
CVE-2025-39885 MEDIUM
Linux Kernel - Denial of Service via Recursive Semaphore Deadlock in OCFS2 FIEMAP
CVSS 5.5
CVE-2025-39884 MEDIUM
Linux Kernel 6.11-6.12.47, 6.13-6.15.7 - Denial of Service via Inode Eviction Race Condition
CVSS 4.7
CVE-2025-39843 MEDIUM
Linux Kernel 5.19-6.1.150, 6.2-6.6.104, 6.7-6.12.45, 6.13-6.16.5 - Deadlock via set_track_prepare Lock Recursion
CVSS 5.5
CVE-2025-39832 MEDIUM
Linux Kernel 6.5-6.6.103, 6.7-6.12.44, 6.13-6.16.4 - Improper Locking in mlx5 Sync Reset Unload Event
CVSS 5.5
CVE-2025-39791 HIGH
Linux Kernel 6.10-6.12.43, 6.13-6.16.3, 6.17 - Deadlock and Data Corruption via dm-crypt BIO Splitting
CVSS 7.8
Details
Vulnerabilities 722