Debian Linux vulnerabilities
9,956 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358
Vulnerabilities
Page 480 of 498
CVE-2011-2800P4MEDIUMCVSS 4.3v6.0v7.02011-08-03
CVE-2011-2800 [MEDIUM] CWE-200 CVE-2011-2800: Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive informatio
Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive information about client-side redirect targets via a crafted web site.
nvd
CVE-2018-19489P4MEDIUMCVSS 4.7v8.0v9.02018-12-13
CVE-2018-19489 [MEDIUM] CWE-362 CVE-2018-19489: v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) becaus
v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renaming.
nvd
CVE-2010-3442P4MEDIUMCVSS 4.7v5.02010-10-04
CVE-2010-3442 [MEDIUM] CWE-190 CVE-2010-3442: Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel b
Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted (1) SNDRV_CTL_IOCTL_ELEM_ADD or (2) SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl call.
nvd
CVE-2025-38393P4MEDIUMCVSS 4.7v11.02025-07-25
CVE-2025-38393 [MEDIUM] CWE-362 CVE-2025-38393: In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Fix a race to wake
In the Linux kernel, the following vulnerability has been resolved:
NFSv4/pNFS: Fix a race to wake on NFS_LAYOUT_DRAIN
We found a few different systems hung up in writeback waiting on the same
page lock, and one task waiting on the NFS_LAYOUT_DRAIN bit in
pnfs_update_layout(), however the pnfs_layout_hdr's plh_outstanding count
was zero.
It seems m
nvd
CVE-2020-25604P4MEDIUMCVSS 4.7v10.02020-09-23
CVE-2020-25604 [MEDIUM] CWE-362 CVE-2020-25604: An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers betwe
An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. When migrating timers of x86 HVM guests between its vCPUs, the locking model used allows for a second vCPU of the same guest (also operating on the timers) to release a lock that it didn't acquire. The most likely effect of the issue
nvd
CVE-2015-5707P4MEDIUMCVSS 4.6v7.0v8.02015-10-19
CVE-2015-5707 [MEDIUM] CWE-190 CVE-2015-5707: Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through
Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request.
nvd
CVE-2024-26874P4MEDIUMCVSS 4.7v10.02024-04-17
CVE-2024-26874 [MEDIUM] CWE-476 CVE-2024-26874: In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Fix a null pointe
In the Linux kernel, the following vulnerability has been resolved:
drm/mediatek: Fix a null pointer crash in mtk_drm_crtc_finish_page_flip
It's possible that mtk_crtc->event is NULL in
mtk_drm_crtc_finish_page_flip().
pending_needs_vblank value is set by mtk_crtc->event, but in
mtk_drm_crtc_atomic_flush(), it's is not guarded by the same
lock in
nvd
CVE-2021-2341P4LOWCVSS 3.1v9.0v10.02021-07-21
CVE-2021-2341 [LOW] CVE-2021-2341: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to c
nvd
CVE-2022-21443P4LOWCVSS 3.7v9.0v10.0+1 more2022-04-19
CVE-2022-21443 [LOW] CVE-2022-21443: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network acces
nvd
CVE-2023-2898P4MEDIUMCVSS 4.7v10.0v11.0+1 more2023-05-26
CVE-2023-2898 [MEDIUM] CWE-476 CVE-2023-2898: There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux k
There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem.
nvd
CVE-2024-27419P4MEDIUMCVSS 4.7v10.02024-05-17
CVE-2024-27419 [MEDIUM] CWE-362 CVE-2024-27419: In the Linux kernel, the following vulnerability has been resolved: netrom: Fix data-races around s
In the Linux kernel, the following vulnerability has been resolved:
netrom: Fix data-races around sysctl_net_busy_read
We need to protect the reader reading the sysctl value because the
value can be changed concurrently.
nvd
CVE-2024-26878P4MEDIUMCVSS 4.7v10.02024-04-17
CVE-2024-26878 [MEDIUM] CWE-362 CVE-2024-26878: In the Linux kernel, the following vulnerability has been resolved: quota: Fix potential NULL point
In the Linux kernel, the following vulnerability has been resolved:
quota: Fix potential NULL pointer dereference
Below race may cause NULL pointer dereference
P1 P2
dquot_free_inode quota_off
drop_dquot_ref
remove_dquot_ref
dquots = i_dquot(inode)
dquots = i_dquot(inode)
srcu_read_lock
dquots[cnt]) != NULL (1)
dquots[type] = NULL (2)
spin_lock(&d
nvd
CVE-2015-2684P4MEDIUMCVSS 4.0v7.02015-03-31
CVE-2015-2684 [MEDIUM] CWE-20 CVE-2015-2684: Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.
nvd
CVE-2019-19523P4MEDIUMCVSS 4.6v8.02019-12-03
CVE-2019-19523 [MEDIUM] CWE-416 CVE-2019-19523: In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious US
In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/adutux.c driver, aka CID-44efc269db79.
nvd
CVE-2025-38112P4MEDIUMCVSS 4.7v11.02025-07-03
CVE-2025-38112 [MEDIUM] CWE-367 CVE-2025-38112: In the Linux kernel, the following vulnerability has been resolved: net: Fix TOCTOU issue in sk_is_
In the Linux kernel, the following vulnerability has been resolved:
net: Fix TOCTOU issue in sk_is_readable()
sk->sk_prot->sock_is_readable is a valid function pointer when sk resides
in a sockmap. After the last sk_psock_put() (which usually happens when
socket is removed from sockmap), sk->sk_prot gets restored and
sk->sk_prot->sock_is_readable b
nvd
CVE-2025-38461P4MEDIUMCVSS 4.7v11.02025-07-25
CVE-2025-38461 [MEDIUM] CWE-367 CVE-2025-38461: In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_* TOCTOU
In the Linux kernel, the following vulnerability has been resolved:
vsock: Fix transport_* TOCTOU
Transport assignment may race with module unload. Protect new_transport
from becoming a stale pointer.
This also takes care of an insecure call in vsock_use_local_transport();
add a lockdep assert.
BUG: unable to handle page fault for address: fffffbff
nvd
CVE-2025-38462P4MEDIUMCVSS 4.7v11.02025-07-25
CVE-2025-38462 [MEDIUM] CWE-367 CVE-2025-38462: In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_{g2h,h2g}
In the Linux kernel, the following vulnerability has been resolved:
vsock: Fix transport_{g2h,h2g} TOCTOU
vsock_find_cid() and vsock_dev_do_ioctl() may race with module unload.
transport_{g2h,h2g} may become NULL after the NULL check.
Introduce vsock_transport_local_cid() to protect from a potential
null-ptr-deref.
KASAN: null-ptr-deref in range [
nvd
CVE-2020-14781P4LOWCVSS 3.7v9.0v10.02020-10-21
CVE-2020-14781 [LOW] CVE-2020-14781: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supporte
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful atta
nvd
CVE-2020-2778P4LOWCVSS 3.7v10.02020-04-15
CVE-2020-2778 [LOW] CVE-2020-2778: Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that ar
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE ac
nvd
CVE-2017-11334P4MEDIUMCVSS 4.4v9.02017-08-02
CVE-2017-11334 [MEDIUM] CWE-125 CVE-2017-11334: The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest
The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest ram block area.
nvd