cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 238 of 498
CVE-2017-7493P3HIGHCVSS 7.8v8.02017-05-17
CVE-2017-7493 [HIGH] CWE-732 CVE-2017-7493: Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) sup Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode. A guest user could use this flaw to escalate their privileges inside guest.
nvd
CVE-2022-28390P3HIGHCVSS 7.8v9.0v10.0+1 more2022-04-03
CVE-2022-28390 [HIGH] CWE-415 CVE-2022-28390: ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.
nvd
CVE-2017-9780P3HIGHCVSS 7.8v9.02017-06-21
CVE-2017-9780 [HIGH] CWE-732 CVE-2017-9780: In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain file In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location. In the case of the "system helper" c
nvd
CVE-2021-28709P3HIGHCVSS 7.8v11.02021-11-24
CVE-2021-28709 [HIGH] CVE-2021-28709: issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain
nvd
CVE-2021-28705P3HIGHCVSS 7.8v11.02021-11-24
CVE-2021-28705 [HIGH] CWE-755 CVE-2021-28705: issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control
nvd
CVE-2021-23961P3HIGHCVSS 7.4v9.0v10.02021-02-26
CVE-2021-23961 [HIGH] CVE-2021-23961: Further techniques that built on the slipstream research combined with a malicious webpage could hav Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.
nvd
CVE-2024-27024P3HIGHCVSS 7.8v10.02024-05-01
CVE-2024-27024 [HIGH] CVE-2024-27024: In the Linux kernel, the following vulnerability has been resolved: net/rds: fix WARNING in rds_con In the Linux kernel, the following vulnerability has been resolved: net/rds: fix WARNING in rds_conn_connect_if_down If connection isn't established yet, get_mr() will fail, trigger connection after get_mr().
nvd
CVE-2017-12136P3HIGHCVSS 7.8v8.0v9.02017-08-24
CVE-2017-12136 [HIGH] CWE-362 CVE-2017-12136: Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrato Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.
nvd
CVE-2024-27073P3HIGHCVSS 7.8v10.02024-05-01
CVE-2024-27073 [HIGH] CWE-401 CVE-2024-27073: In the Linux kernel, the following vulnerability has been resolved: media: ttpci: fix two memleaks In the Linux kernel, the following vulnerability has been resolved: media: ttpci: fix two memleaks in budget_av_attach When saa7146_register_device and saa7146_vv_init fails, budget_av_attach should free the resources it allocates, like the error-handling of ttpci_budget_init does. Besides, there are two fixme comment refers to such deallocations.
nvd
CVE-2024-26928P3HIGHCVSS 7.8v11.02024-04-28
CVE-2024-26928 [HIGH] CWE-416 CVE-2024-26928: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_debug_files_proc_show() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.
nvd
CVE-2024-26739P3HIGHCVSS 7.8v11.02024-04-03
CVE-2024-26739 [HIGH] CWE-416 CVE-2024-26739: In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't ov In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb If we're redirecting the skb, and haven't called tcf_mirred_forward(), yet, we need to tell the core to drop the skb by setting the retcode to SHOT. If we have called tcf_mirred_forward(), however, the skb is out
nvd
CVE-2024-49966P3HIGHCVSS 7.8v11.02024-10-21
CVE-2024-49966 [HIGH] CWE-416 CVE-2024-49966: In the Linux kernel, the following vulnerability has been resolved: ocfs2: cancel dqi_sync_work bef In the Linux kernel, the following vulnerability has been resolved: ocfs2: cancel dqi_sync_work before freeing oinfo ocfs2_global_read_info() will initialize and schedule dqi_sync_work at the end, if error occurs after successfully reading global quota, it will trigger the following warning with CONFIG_DEBUG_OBJECTS_* enabled: ODEBUG: free active (a
nvd
CVE-2024-26704P3HIGHCVSS 7.8v10.02024-04-03
CVE-2024-26704 [HIGH] CWE-415 CVE-2024-26704: In the Linux kernel, the following vulnerability has been resolved: ext4: fix double-free of blocks In the Linux kernel, the following vulnerability has been resolved: ext4: fix double-free of blocks due to wrong extents moved_len In ext4_move_extents(), moved_len is only updated when all moves are successfully executed, and only discards orig_inode and donor_inode preallocations when moved_len is not zero. When the loop fails to exit after success
nvd
CVE-2024-35867P3HIGHCVSS 7.8v11.02024-05-19
CVE-2024-35867 [HIGH] CWE-416 CVE-2024-35867: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_stats_proc_show() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.
nvd
CVE-2024-46821P3HIGHCVSS 7.8v11.02024-09-27
CVE-2024-46821 [HIGH] CWE-129 CVE-2024-46821: In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Fix negative array In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Fix negative array index read Avoid using the negative values for clk_idex as an index into an array pptable->DpmDescriptor. V2: fix clk_index return check (Tim Huang)
nvd
CVE-2019-17341P3HIGHCVSS 7.8v9.0v10.02019-10-08
CVE-2019-17341 [HIGH] CWE-362 CVE-2019-17341: An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of se An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability race condition during addition of a passed-through PCI device.
nvd
CVE-2024-46812P3HIGHCVSS 7.8v11.02024-09-27
CVE-2024-46812 [HIGH] CVE-2024-46812: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Skip inactive In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Skip inactive planes within ModeSupportAndSystemConfiguration [Why] Coverity reports Memory - illegal accesses. [How] Skip inactive planes.
nvd
CVE-2024-26772P3HIGHCVSS 7.8v10.02024-04-03
CVE-2024-26772 [HIGH] CVE-2024-26772: In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks f In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal() Places the logic for checking if the group's block bitmap is corrupt under the protection of the group lock to avoid allocating blocks from the group with a corrupted block bitmap.
nvd
CVE-2024-44977P3HIGHCVSS 7.8v11.02024-09-04
CVE-2024-44977 [HIGH] CWE-787 CVE-2024-44977: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Validate TA binary In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Validate TA binary size Add TA binary size validation to avoid OOB write. (cherry picked from commit c0a04e3570d72aaf090962156ad085e37c62e442)
nvd
CVE-2023-52679P3HIGHCVSS 7.8v10.02024-05-17
CVE-2023-52679 [HIGH] CWE-415 CVE-2023-52679: In the Linux kernel, the following vulnerability has been resolved: of: Fix double free in of_parse In the Linux kernel, the following vulnerability has been resolved: of: Fix double free in of_parse_phandle_with_args_map In of_parse_phandle_with_args_map() the inner loop that iterates through the map entries calls of_node_put(new) to free the reference acquired by the previous iteration of the inner loop. This assumes that the value of "new" is NU
nvd
Debian Linux vulnerabilities | cvebase