Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 453 of 498
CVE-2021-4149P4MEDIUMCVSS 5.5v9.02022-03-23
CVE-2021-4149 [MEDIUM] CWE-667 CVE-2021-4149: A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to
A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem.
nvd
CVE-2005-2456P4MEDIUMCVSS 5.5v3.12005-08-04
CVE-2005-2456 [MEDIUM] CWE-667 CVE-2005-2456: Array index overflow in the xfrm_sk_policy_insert function in xfrm_user.c in Linux kernel 2.6 allows
Array index overflow in the xfrm_sk_policy_insert function in xfrm_user.c in Linux kernel 2.6 allows local users to cause a denial of service (oops or deadlock) and possibly execute arbitrary code via a p->dir value that is larger than XFRM_POLICY_OUT, which is used as an index in the sock->sk_policy array.
nvd
CVE-2016-7118P4MEDIUMCVSS 5.5v7.02016-08-31
CVE-2016-7118 [MEDIUM] CWE-476 CVE-2016-7118: fs/fcntl.c in the "aufs 3.2.x+setfl-debian" patch in the linux-image package 3.2.0-4 (kernel 3.2.81-
fs/fcntl.c in the "aufs 3.2.x+setfl-debian" patch in the linux-image package 3.2.0-4 (kernel 3.2.81-1) in Debian wheezy mishandles F_SETFL fcntl calls on directories, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via standard filesystem operations, as demonstrated by scp from an AUFS filesystem.
nvd
CVE-2008-1531P4MEDIUMCVSS 4.3v4.02008-03-27
CVE-2008-1531 [MEDIUM] CVE-2008-1531: The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x befo
The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.
nvd
CVE-2016-9811P4MEDIUMCVSS 4.7v8.0v9.02017-01-13
CVE-2016-9811 [MEDIUM] CWE-125 CVE-2016-9811: The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is s
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
nvd
CVE-2025-38514P4MEDIUMCVSS 5.5v11.02025-08-16
CVE-2025-38514 [MEDIUM] CVE-2025-38514: In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix oops due to non-exis
In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix oops due to non-existence of prealloc backlog struct
If an AF_RXRPC service socket is opened and bound, but calls are
preallocated, then rxrpc_alloc_incoming_call() will oops because the
rxrpc_backlog struct doesn't get allocated until the first preallocation is
made.
Fix this
nvd
CVE-2020-8003P4MEDIUMCVSS 5.5v10.02020-01-27
CVE-2020-8003 [MEDIUM] CWE-415 CVE-2020-8003: A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to c
A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service by triggering texture allocation failure, because vrend_renderer_resource_allocated_texture is not an appropriate place for a free.
nvd
CVE-2020-28941P4MEDIUMCVSS 5.5v9.02020-11-19
CVE-2020-28941 [MEDIUM] CWE-763 CVE-2020-28941: An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9
An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs because of an invalid free when the line discipline is used more than once.
nvd
CVE-2020-36310P4MEDIUMCVSS 5.5v11.02021-04-07
CVE-2020-36310 [MEDIUM] CWE-835 CVE-2020-36310: An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_r
An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite loop for certain nested page faults, aka CID-e72436bc3a52.
nvd
CVE-2022-38865P4MEDIUMCVSS 5.5v10.02022-09-15
CVE-2022-38865 [MEDIUM] CWE-369 CVE-2022-38865: Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_rea
Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi.c. This affects mplyer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
nvd
CVE-2022-39190P4MEDIUMCVSS 5.5v10.02022-09-02
CVE-2022-39190 [MEDIUM] CVE-2022-39190: An issue was discovered in net/netfilter/nf_tables_api.c in the Linux kernel before 5.19.6. A denial
An issue was discovered in net/netfilter/nf_tables_api.c in the Linux kernel before 5.19.6. A denial of service can occur upon binding to an already bound chain.
nvd
CVE-2024-26922P4MEDIUMCVSS 5.5v10.02024-04-23
CVE-2024-26922 [MEDIUM] CVE-2024-26922: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parame
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: validate the parameters of bo mapping operations more clearly
Verify the parameters of
amdgpu_vm_bo_(map/replace_map/clearing_mappings) in one common place.
nvd
CVE-2023-52650P4MEDIUMCVSS 5.5v10.02024-05-01
CVE-2023-52650 [MEDIUM] CWE-476 CVE-2023-52650: In the Linux kernel, the following vulnerability has been resolved: drm/tegra: dsi: Add missing che
In the Linux kernel, the following vulnerability has been resolved:
drm/tegra: dsi: Add missing check for of_find_device_by_node
Add check for the return value of of_find_device_by_node() and return
the error if it fails in order to avoid NULL pointer dereference.
nvd
CVE-2024-46955P4MEDIUMCVSS 5.5v12.02024-11-10
CVE-2024-46955 [MEDIUM] CWE-125 CVE-2024-46955: An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bo
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.
nvd
CVE-2025-37881P4MEDIUMCVSS 5.5v11.02025-05-09
CVE-2025-37881 [MEDIUM] CWE-476 CVE-2025-37881: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed: Add NULL p
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev()
The variable d->name, returned by devm_kasprintf(), could be NULL.
A pointer check is added to prevent potential NULL pointer dereference.
This is similar to the fix in commit 3027e7b15b02
("ice: Fix some null point
nvd
CVE-2025-37857P4MEDIUMCVSS 5.5v11.02025-05-09
CVE-2025-37857 [MEDIUM] CWE-190 CVE-2025-37857: In the Linux kernel, the following vulnerability has been resolved: scsi: st: Fix array overflow in
In the Linux kernel, the following vulnerability has been resolved:
scsi: st: Fix array overflow in st_setup()
Change the array size to follow parms size instead of a fixed value.
nvd
CVE-2011-3905P4MEDIUMCVSS 5.0v5.0v6.0+1 more2011-12-13
CVE-2011-3905 [MEDIUM] CWE-125 CVE-2011-3905: libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of s
libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2024-27077P4MEDIUMCVSS 5.5v10.02024-05-01
CVE-2024-27077 [MEDIUM] CWE-401 CVE-2024-27077: In the Linux kernel, the following vulnerability has been resolved: media: v4l2-mem2mem: fix a meml
In the Linux kernel, the following vulnerability has been resolved:
media: v4l2-mem2mem: fix a memleak in v4l2_m2m_register_entity
The entity->name (i.e. name) is allocated in v4l2_m2m_register_entity
but isn't freed in its following error-handling paths. This patch
adds such deallocation to prevent memleak of entity->name.
nvd
CVE-2020-35533P4MEDIUMCVSS 5.5v10.02022-09-01
CVE-2020-35533 [MEDIUM] CWE-125 CVE-2020-35533: In LibRaw, an out-of-bounds read vulnerability exists within the "LibRaw::adobe_copy_pixel()" functi
In LibRaw, an out-of-bounds read vulnerability exists within the "LibRaw::adobe_copy_pixel()" function (libraw\src\decoders\dng.cpp) when reading data from the image file.
nvd
CVE-2020-35531P4MEDIUMCVSS 5.5v10.02022-09-01
CVE-2020-35531 [MEDIUM] CWE-125 CVE-2020-35531: In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_diff() function (libraw
In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_diff() function (libraw\src\x3f\x3f_utils_patched.cpp) when reading data from an image file.
nvd