Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4153MEDIUM4310LOW358
Vulnerabilities
Page 194 of 498
CVE-2025-39738P3HIGHCVSS 7.8v11.02025-09-11
CVE-2025-39738 [HIGH] CVE-2025-39738: In the Linux kernel, the following vulnerability has been resolved: btrfs: do not allow relocation
In the Linux kernel, the following vulnerability has been resolved:
btrfs: do not allow relocation of partially dropped subvolumes
[BUG]
There is an internal report that balance triggered transaction abort,
with the following call trace:
item 85 key (594509824 169 0) itemoff 12599 itemsize 33
extent refs 1 gen 197740 flags 2
ref#0: tree block backref root 7
nvd
CVE-2025-38456P3HIGHCVSS 7.8v11.02025-07-25
CVE-2025-38456 [HIGH] CWE-787 CVE-2025-38456: In the Linux kernel, the following vulnerability has been resolved: ipmi:msghandler: Fix potential
In the Linux kernel, the following vulnerability has been resolved:
ipmi:msghandler: Fix potential memory corruption in ipmi_create_user()
The "intf" list iterator is an invalid pointer if the correct
"intf->intf_num" is not found. Calling atomic_dec(&intf->nr_users) on
and invalid pointer will lead to memory corruption.
We don't really need to call
nvd
CVE-2025-38227P3HIGHCVSS 7.8v11.02025-07-04
CVE-2025-38227 [HIGH] CWE-416 CVE-2025-38227: In the Linux kernel, the following vulnerability has been resolved: media: vidtv: Terminating the s
In the Linux kernel, the following vulnerability has been resolved:
media: vidtv: Terminating the subsequent process of initialization failure
syzbot reported a slab-use-after-free Read in vidtv_mux_init. [1]
After PSI initialization fails, the si member is accessed again, resulting
in this uaf.
After si initialization fails, the subsequent process
nvd
CVE-2025-38718P3HIGHCVSS 7.8v11.02025-09-04
CVE-2025-38718 [HIGH] CWE-908 CVE-2025-38718: In the Linux kernel, the following vulnerability has been resolved: sctp: linearize cloned gso pack
In the Linux kernel, the following vulnerability has been resolved:
sctp: linearize cloned gso packets in sctp_rcv
A cloned head skb still shares these frag skbs in fraglist with the
original head skb. It's not safe to access these frag skbs.
syzbot reported two use-of-uninitialized-memory bugs caused by this:
BUG: KMSAN: uninit-value in sctp_inq_p
nvd
CVE-2025-39873P3HIGHCVSS 7.8v11.02025-09-23
CVE-2025-39873 [HIGH] CWE-416 CVE-2025-39873: In the Linux kernel, the following vulnerability has been resolved: can: xilinx_can: xcan_write_fra
In the Linux kernel, the following vulnerability has been resolved:
can: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB
can_put_echo_skb() takes ownership of the SKB and it may be freed
during or after the call.
However, xilinx_can xcan_write_frame() keeps using SKB after the call.
Fix that by only calling can_put_echo_skb()
nvd
CVE-2023-39949P3HIGHCVSS 7.5v11.0v12.02023-08-11
CVE-2023-39949 [HIGH] CWE-617 CVE-2023-39949: eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Ma
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS process. Versions 2.9.1 and 2.6.5 contain a patch for this issue.
nvd
CVE-2023-39948P3HIGHCVSS 7.5v11.0v12.02023-08-11
CVE-2023-39948 [HIGH] CWE-248 CVE-2023-39948: eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Ma
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0 and 2.6.5, the `BadParamException` thrown by Fast CDR is not caught in Fast DDS. This can remotely crash any Fast DDS process. Versions 2.10.0 and 2.6.5 contain a patch for this issue.
nvd
CVE-2022-41916P3HIGHCVSS 7.5v10.0v11.02022-11-15
CVE-2022-41916 [HIGH] CWE-193 CVE-2022-41916: Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerabl
Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) and kinit (via PKINIT), as well as any third-party applications using Heimdal's libhx509. Users should upgrade to Heimdal 7.7.1 or 7.8
nvd
CVE-2025-39877P3HIGHCVSS 7.8v11.02025-09-23
CVE-2025-39877 [HIGH] CWE-416 CVE-2025-39877: In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: fix use-after-f
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/sysfs: fix use-after-free in state_show()
state_show() reads kdamond->damon_ctx without holding damon_sysfs_lock.
This allows a use-after-free race:
CPU 0 CPU 1
----- -----
state_show() damon_sysfs_turn_damon_on()
ctx = kdamond->damon_ctx; mutex_lock(&damon_sysfs_lock);
dam
nvd
CVE-2023-40462P3HIGHCVSS 7.5v10.02023-12-04
CVE-2023-40462 [HIGH] CWE-617 CVE-2023-40462: The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during aut
The ACEManager
component of ALEOS 4.16 and earlier does not
perform input
sanitization during authentication, which could
potentially result
in a Denial of Service (DoS) condition for
ACEManager without
impairing other router functions. ACEManager
recovers from the
DoS condition by restarting within ten seconds of
becoming
unavailable.
nvd
CVE-2010-2547P3HIGHCVSS 8.1v5.02010-08-05
CVE-2010-2547 [HIGH] CWE-416 CVE-2010-2547: Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote
Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large number of Subject Alternate Names, which is not properly handled in a realloc operation when importing the certificate or verifying its sign
nvd
CVE-2018-5248P3HIGHCVSS 8.8v8.0v9.02018-01-05
CVE-2018-5248 [HIGH] CWE-125 CVE-2018-5248: In ImageMagick 7.0.7-17 Q16, there is a heap-based buffer over-read in coders/sixel.c in the ReadSIX
In ImageMagick 7.0.7-17 Q16, there is a heap-based buffer over-read in coders/sixel.c in the ReadSIXELImage function, related to the sixel_decode function.
nvd
CVE-2019-19953P3CRITICALCVSS 9.1v8.0v9.0+1 more2019-12-24
CVE-2019-19953 [CRITICAL] CWE-125 CVE-2019-19953: In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function E
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
nvd
CVE-2021-37991P3HIGHCVSS 7.5v10.0v11.02021-11-02
CVE-2021-37991 [HIGH] CWE-362 CVE-2021-37991: Race in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit h
Race in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2015-0412P3HIGHCVSS 7.2v7.0v8.02015-01-21
CVE-2015-0412 [HIGH] CVE-2015-0412: Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect c
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS.
nvd
CVE-2024-1552P3HIGHCVSS 7.5v10.02024-02-20
CVE-2024-1552 [HIGH] CWE-681 CVE-2024-1552: Incorrect code generation could have led to unexpected numeric conversions and potential undefined b
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2009-4537P3HIGHCVSS 7.8v5.02010-01-12
CVE-2009-4537 [HIGH] CWE-20 CVE-2009-4537: drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly c
drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain pac
nvd
CVE-2017-12163P3HIGHCVSS 7.1v8.0v9.02018-07-26
CVE-2017-12163 [HIGH] CWE-200 CVE-2017-12163: An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16,
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.
nvd
CVE-2018-19968P3MEDIUMCVSS 6.5v8.02018-12-11
CVE-2018-19968 [MEDIUM] CWE-200 CVE-2018-19968: An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an e
An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in
nvd
CVE-2024-47619P3HIGHCVSS 7.5v11.02025-05-07
CVE-2024-47619 [HIGH] CWE-295 CVE-2024-47619: syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certif
syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not allowed. It is also possible to pass partial wildcards such as `foo.a*c.bar` which glib matches but should be avoided / invalidated. This issue could have an impact on TLS connections, such as in man-in-th
nvd