Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 395 of 498
CVE-2025-38001P4MEDIUMCVSS 5.5v11.0v12.02025-06-06
CVE-2025-38001 [MEDIUM] CWE-835 CVE-2025-38001: In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Address reentr
In the Linux kernel, the following vulnerability has been resolved:
net_sched: hfsc: Address reentrant enqueue adding class to eltree twice
Savino says:
"We are writing to report that this recent patch
(141d34391abbb315d68556b7c67ad97885407547) [1]
can be bypassed, and a UAF can still occur when HFSC is utilized with
NETEM.
The patch only checks t
nvd
CVE-2020-26088P4MEDIUMCVSS 5.5v9.02020-09-24
CVE-2020-26088 [MEDIUM] CWE-276 CVE-2020-26088: A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5
A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.
nvd
CVE-2020-26570P4MEDIUMCVSS 5.5v9.02020-10-06
CVE-2020-26570 [MEDIUM] CWE-787 CVE-2020-26570: The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow
The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.
nvd
CVE-2022-1204P4MEDIUMCVSS 5.5v10.02022-08-29
CVE-2022-1204 [MEDIUM] CWE-416 CVE-2022-1204: A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in
A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user connects with the protocol. This flaw allows a local user to crash the system.
nvd
CVE-2025-38608P4MEDIUMCVSS 5.5v11.02025-08-19
CVE-2025-38608 [MEDIUM] CWE-908 CVE-2025-38608: In the Linux kernel, the following vulnerability has been resolved: bpf, ktls: Fix data corruption
In the Linux kernel, the following vulnerability has been resolved:
bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls
When sending plaintext data, we initially calculated the corresponding
ciphertext length. However, if we later reduced the plaintext data length
via socket policy, we failed to recalculate the ciphertext length.
T
nvd
CVE-2020-25641P4MEDIUMCVSS 5.5v9.02020-10-06
CVE-2020-25641 [MEDIUM] CWE-835 CVE-2020-25641: A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-
A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic privileges to issue requests to a block device, resulting in a denial of se
nvd
CVE-2012-0842P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-11-19
CVE-2012-0842 [MEDIUM] CWE-200 CVE-2012-0842: surf: cookie jar has read access from other local user
surf: cookie jar has read access from other local user
nvd
CVE-2021-3527P4MEDIUMCVSS 5.5v9.0v10.02021-05-26
CVE-2021-3527 [MEDIUM] CWE-770 CVE-2021-3527: A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined in
A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to reduce the overhead and improve performance. The combined size of the bulk transfer is used to dynamically allocate a variable length array (VLA) on the stack without proper validation. Since the total size is not
nvd
CVE-2020-25686P4LOWCVSS 3.7v10.02021-01-20
CVE-2020-25686 [LOW] CVE-2020-25686: A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for
A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstream servers, so there can be at most 150 queries for the same name. This flaw allows an off-path attacker on the network to
nvd
CVE-2023-46316P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-10-25
CVE-2023-46316 [MEDIUM] CWE-234 CVE-2023-46316: In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse comma
In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines.
nvd
CVE-2021-29647P4MEDIUMCVSS 5.5v9.02021-03-30
CVE-2021-29647 [MEDIUM] CWE-909 CVE-2021-29647: An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows a
An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID-50535249f624.
nvd
CVE-2025-39703P4MEDIUMCVSS 5.5v11.02025-09-05
CVE-2025-39703 [MEDIUM] CWE-476 CVE-2025-39703: In the Linux kernel, the following vulnerability has been resolved: net, hsr: reject HSR frame if s
In the Linux kernel, the following vulnerability has been resolved:
net, hsr: reject HSR frame if skb can't hold tag
Receiving HSR frame with insufficient space to hold HSR tag in the skb
can result in a crash (kernel BUG):
[ 45.390915] skbuff: skb_under_panic: text:ffffffff86f32cac len:26 put:14 head:ffff888042418000 data:ffff888042417ff4 tail:0x
nvd
CVE-2022-26373P4MEDIUMCVSS 5.5v10.02022-08-18
CVE-2022-26373 [MEDIUM] CVE-2022-26373: Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
nvd
CVE-2017-17087P4MEDIUMCVSS 5.5v8.0v9.02017-12-01
CVE-2017-17087 [MEDIUM] CVE-2017-17087: fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary gr
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.
nvd
CVE-2016-0495P4MEDIUMCVSS 4.3v8.02016-01-21
CVE-2016-0495 [MEDIUM] CVE-2016-0495: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.36 and 5.0.14 allows remote attackers to affect availability via unknown vectors related to Core.
nvd
CVE-2024-36905P4MEDIUMCVSS 5.5v10.02024-05-30
CVE-2024-36905 [MEDIUM] CWE-369 CVE-2024-36905: In the Linux kernel, the following vulnerability has been resolved: tcp: defer shutdown(SEND_SHUTDO
In the Linux kernel, the following vulnerability has been resolved:
tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets
TCP_SYN_RECV state is really special, it is only used by
cross-syn connections, mostly used by fuzzers.
In the following crash [1], syzbot managed to trigger a divide
by zero in tcp_rcv_space_adjust()
A socket makes the
nvd
CVE-2025-40300P4MEDIUMCVSS 5.5v11.02025-09-11
CVE-2025-40300 [MEDIUM] CVE-2025-40300: In the Linux kernel, the following vulnerability has been resolved: x86/vmscape: Add conditional IB
In the Linux kernel, the following vulnerability has been resolved:
x86/vmscape: Add conditional IBPB mitigation
VMSCAPE is a vulnerability that exploits insufficient branch predictor
isolation between a guest and a userspace hypervisor (like QEMU). Existing
mitigations already protect kernel/KVM from a malicious guest. Userspace
can additionally be protec
nvd
CVE-2017-14737P4MEDIUMCVSS 5.5v9.02017-09-26
CVE-2017-14737 [MEDIUM] CVE-2017-14737: A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11
A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.
nvd
CVE-2022-3341P4MEDIUMCVSS 5.3v10.02023-01-12
CVE-2022-3341 [MEDIUM] CWE-476 CVE-2022-3341: A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of liba
A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and triggers the null pointer dereference error, causing an application to crash.
nvd
CVE-2022-2873P4MEDIUMCVSS 5.5v11.02022-08-22
CVE-2022-2873 [MEDIUM] CWE-131 CVE-2022-2873: An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller
An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to crash the system.
nvd