Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 418 of 498
CVE-2018-5803P4MEDIUMCVSS 5.5v7.0v8.0+1 more2018-06-12
CVE-2018-5803 [MEDIUM] CWE-20 CVE-2018-5803: In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error i
In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited to cause a kernel crash.
nvd
CVE-2019-5765P4MEDIUMCVSS 5.5v9.02019-02-19
CVE-2019-5765 [MEDIUM] CWE-312 CVE-2019-5765: An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allow
An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.
nvd
CVE-2021-4115P4MEDIUMCVSS 5.5v11.02022-02-21
CVE-2021-4115 [MEDIUM] CWE-400 CVE-2021-4115: There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to proc
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
nvd
CVE-2016-5403P4MEDIUMCVSS 5.5v8.02016-08-02
CVE-2016-5403 [MEDIUM] CWE-400 CVE-2016-5403: The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cau
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
nvd
CVE-2020-12771P4MEDIUMCVSS 5.5v9.02020-05-09
CVE-2020-12771 [MEDIUM] CWE-667 CVE-2020-12771: An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/b
An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails.
nvd
CVE-2020-25596P4MEDIUMCVSS 5.5v10.02020-09-23
CVE-2020-25596 [MEDIUM] CWE-74 CVE-2020-25596: An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service
An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. One of Xen's sanitization paths injects a #GP fault, and incorrectly delivers it twice to the guest. This causes the guest kernel to observe a kernel-priv
nvd
CVE-2022-33748P4MEDIUMCVSS 5.6v11.02022-10-11
CVE-2022-33748 [MEDIUM] CWE-755 CVE-2022-33748: lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was
lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an error handling path. While doing so, locking requirements were not paid attention to. As a result two cooperating guests granting each other transitive grants can cause locks to be acquired nested within one another, but in respectivel
nvd
CVE-2022-0617P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-02-16
CVE-2022-0617 [MEDIUM] CWE-476 CVE-2022-0617: A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the w
A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.
nvd
CVE-2025-22042P4MEDIUMCVSS 5.5v11.02025-04-16
CVE-2025-22042 [MEDIUM] CVE-2025-22042: In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for cre
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: add bounds check for create lease context
Add missing bounds check for create lease context.
nvd
CVE-2022-26356P4MEDIUMCVSS 5.6v11.02022-04-05
CVE-2022-26356 [MEDIUM] CWE-667 CVE-2022-26356: Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirt
Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirty hypercalls. A suitably timed call to XEN_DMOP_track_dirty_vram can enable log dirty while another CPU is still in the process of
nvd
CVE-2021-38198P4MEDIUMCVSS 5.5v9.02021-08-08
CVE-2021-38198 [MEDIUM] CVE-2021-38198: arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access pe
arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page, leading to a missing guest protection page fault.
nvd
CVE-2016-1981P4MEDIUMCVSS 5.5v7.0v8.02016-12-29
CVE-2016-1981 [MEDIUM] CWE-835 CVE-2016-1981: QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite lo
QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head (TDH/RDH) is set outside the allocated descriptor buffer. A privileged user inside guest could use this flaw to cra
nvd
CVE-2019-20811P4MEDIUMCVSS 5.5v8.0v9.02020-06-03
CVE-2019-20811 [MEDIUM] CVE-2019-20811: An issue was discovered in the Linux kernel before 5.0.6. In rx_queue_add_kobject() and netdev_queue
An issue was discovered in the Linux kernel before 5.0.6. In rx_queue_add_kobject() and netdev_queue_add_kobject() in net/core/net-sysfs.c, a reference count is mishandled, aka CID-a3e23f719f5c.
nvd
CVE-2024-26926P4MEDIUMCVSS 5.5v10.02024-04-25
CVE-2024-26926 [MEDIUM] CVE-2024-26926: In the Linux kernel, the following vulnerability has been resolved: binder: check offset alignment
In the Linux kernel, the following vulnerability has been resolved:
binder: check offset alignment in binder_get_object()
Commit 6d98eb95b450 ("binder: avoid potential data leakage when copying
txn") introduced changes to how binder objects are copied. In doing so,
it unintentionally removed an offset alignment check done through calls
to binder_alloc_copy_
nvd
CVE-2016-1922P4MEDIUMCVSS 5.5v7.0v8.02016-12-29
CVE-2016-1922 [MEDIUM] CWE-476 CVE-2016-1922: QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulne
QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulnerable to a null pointer dereference flaw. It occurs while doing I/O port write operations via hmp interface. In that, 'current_cpu' remains null, which leads to the null pointer dereference. A user or process could use this flaw to crash the QEMU instan
nvd
CVE-2020-13253P4MEDIUMCVSS 5.5v9.0v10.02020-05-27
CVE-2020-13253 [MEDIUM] CWE-125 CVE-2020-13253: sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds
sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process.
nvd
CVE-2016-9401P4MEDIUMCVSS 5.5v8.02017-01-23
CVE-2016-9401 [MEDIUM] CWE-416 CVE-2016-9401: popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a
popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
nvd
CVE-2012-0844P4MEDIUMCVSS 5.5v8.0v9.02020-02-21
CVE-2012-0844 [MEDIUM] CWE-200 CVE-2012-0844: Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.
Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.
nvd
CVE-2016-9776P4MEDIUMCVSS 5.5v8.02016-12-29
CVE-2016-9776 [MEDIUM] CWE-835 CVE-2016-9776: QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulne
QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur while receiving packets in 'mcf_fec_receive'. A privileged user/process inside guest could use this issue to crash the QEMU process on the host leading to DoS.
nvd
CVE-2020-15305P4MEDIUMCVSS 5.5v9.0v10.02020-06-26
CVE-2020-15305 [MEDIUM] CWE-416 CVE-2020-15305: An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepS
An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp.
nvd