CWE-617: Reachable Assertion — known CVE vulnerabilities
CVEs classified under CWE-617 (Reachable Assertion), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2024-35884 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: udp: do not accept non-tunnel GSO skbs landing in a tunnel When…
CVE-2020-3615 — CVSS 9.8 (critical): Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disassoc frames due to…
CVE-2019-9795 — CVSS 9.8 (critical): A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to…
CVE-2026-52952 — CVSS 8.8 (high): In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset In…
CVE-2026-31739 — CVSS 8.8 (high): In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - Add missing CRYPTO_ALG_ASYNC The tegra crypto driver…
CVE-2020-12417 — CVSS 8.8 (high): Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a…
CVE-2026-29116: A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet…
CVE-2025-34458: wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the…
CVE-2024-24429 — CVSS 8.6 (high): A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a…
CVE-2024-34235 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-37023 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its…
CVE-2023-37021 — CVSS 8.6 (high): Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-37020 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-37019 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-37018 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-37017 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-37016 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-37015 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-49286 — CVSS 8.6 (high): Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Incorrect Check of Function Return Value bug Squid is…
CVE-2026-63388 — CVSS 8.4 (high): Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c…
CVE-2021-30335 — CVSS 8.4 (high): Possible assertion in QOS request due to improper validation when multiple add or update request are received simultaneously in Snapdragon…
CVE-2026-46117 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()…
CVE-2026-31398 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: mm/rmap: fix incorrect pte restoration for lazyfree folios We batch…
CVE-2023-53683 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()…
CVE-2025-39803 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Remove WARN_ON_ONCE() call from ufshcd_uic_cmd_compl()…
CVE-2022-49154 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: fix panic on out-of-bounds guest IRQ As guest_irq is coming…
CVE-2021-47351 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix races between xattr_{set|get} and listxattr operations UBIFS…
CVE-2023-52621 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() before calling bpf map helpers…
CVE-2024-25445 — CVSS 7.8 (high): Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure.
CVE-2021-36409 — CVSS 7.8 (high): There is an Assertion `scaling_list_pred_matrix_id_delta==1' failed at sps.cc:925 in libde265 v1.0.8 when decoding file, which allows…
CVE-2019-14049 — CVSS 7.8 (high): Stage-2 fault will occur while writing to an ION system allocation which has been assigned to non-HLOS memory which is non-standard in…
CVE-2018-19963 — CVSS 7.8 (high): An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly gain host OS…
CVE-2017-7605 — CVSS 7.8 (high): aacplusenc.c in HE-AAC+ Codec (aka libaacplus) 2.0.2 has an assertion failure, which might allow remote attackers to cause a denial of…
CVE-2026-41485 — CVSS 7.7 (high): Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type…
CVE-2021-1422 — CVSS 7.7 (high): A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense…
CVE-2026-52829 — CVSS 7.5 (high): ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra…
CVE-2026-18697 — CVSS 7.5 (high): An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate…
CVE-2026-45815 — CVSS 7.5 (high): Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP)…
CVE-2026-13204 — CVSS 7.5 (high): If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these…
CVE-2026-12617 — CVSS 7.5 (high): The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A…
CVE-2025-56365 — CVSS 7.5 (high): A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing…
CVE-2025-56362 — CVSS 7.5 (high): A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control…
CVE-2025-56361 — CVSS 7.5 (high): A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control…
CVE-2026-52954 — CVSS 7.5 (high): In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in decode_choose_args() A…
CVE-2026-37233 — CVSS 7.5 (high): FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ric_gen_id() in…
CVE-2026-37229 — CVSS 7.5 (high): FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote unauthenticated…
CVE-2026-37228 — CVSS 7.5 (high): FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a fixed 32KB receive…