Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 10 of 632
CVE-2015-8104P3CRITICALCVSS 10.0fixed in linux 4.2.6-2 (bookworm)2015
CVE-2015-8104 [CRITICAL] CVE-2015-8104: linux - The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x...
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.
Scope: local
bookworm: resolved (fixed in 4.2.6-2)
bullseye: resolved (fixed in 4.2.6-2)
forky: resolved (fixed in 4.2.6-2)
sid: resolved (fixed i
debian
CVE-2015-3331P3CRITICALCVSS 9.3fixed in linux 3.16.7-ckt9-3 (bookworm)2015
CVE-2015-3331 [CRITICAL] CVE-2015-3331: linux - The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in t...
The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attackers to cause a denial of service (buffer overflow and system crash) or possibly execute arbitrary code by triggering a crypto API call, as demonstr
debian
CVE-2023-25775P3MEDIUMCVSS 5.6fixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-25775 [MEDIUM] CVE-2023-25775: linux - Improper access control in the Intel(R) Ethernet Controller RDMA driver for linu...
Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
Scope: local
bookworm: resolved (fixed in 6.1.55-1)
bullseye: resolved (fixed in 5.10.205-2)
forky: resolved (fixed in 6.5.3-1)
sid: resolved (fixed in 6.5.3-1)
tri
debian
CVE-2023-1998P4MEDIUMCVSS 5.6PoCfixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-1998 [MEDIUM] CVE-2023-1998: linux - The Linux kernel allows userspace processes to enable mitigations by calling prc...
The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature as well as by using seccomp. We had noticed that on VMs of at least one major cloud provider, the kernel still left the victim process exposed to attacks in some cases even after enabling the spectre-BTI mitigation with
debian
CVE-2014-7822P4HIGHCVSS 7.2PoCfixed in linux 3.16.2-1 (bookworm)2014
CVE-2014-7822 [HIGH] CVE-2014-7822: linux - The implementation of certain splice_write file operations in the Linux kernel b...
The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a single file, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted splice system call, as demonstrated by use of a file descriptor associated with an ext4
debian
CVE-2019-9500P3HIGHCVSS 7.9fixed in linux 4.19.37-4 (bookworm)2019
CVE-2019-9500 [HIGH] CVE-2019-9500: linux - The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d...
The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can be constructed to trigger an heap buffer overflow in the brcmf_wowl_nd_results function. This vulnerability can be exploited with compromised chipsets t
debian
CVE-2019-9503P3HIGHCVSS 7.9fixed in linux 4.19.37-4 (bookworm)2019
CVE-2019-9503 [HIGH] CVE-2019-9503: linux - The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d0403...
The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfmac driver receives a firmware event frame from a remote source, the is_wlc_event_frame function will cause this frame to be discarded and unprocessed. If the driver receives the firmware event frame from the host, the approp
debian
CVE-2022-42896P3HIGHCVSS 8.0fixed in linux 6.0.10-1 (bookworm)2022
CVE-2022-42896 [HIGH] CVE-2022-42896: linux - There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2c...
There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth. A remote attacker could execute code leaking kernel memory via Bluetooth if within proximity of the victim. We recommend upgrading pa
debian
CVE-2017-16994P4MEDIUMCVSS 5.5PoCfixed in linux 4.14.2-1 (bookworm)2017
CVE-2017-16994 [MEDIUM] CVE-2017-16994: linux - The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14...
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kernel memory via crafted use of the mincore() system call.
Scope: local
bookworm: resolved (fixed in 4.14.2-1)
bullseye: resolved (fixed in 4.14.2-1)
forky: resolved (fixed
debian
CVE-2018-11508P4MEDIUMCVSS 5.5PoCfixed in linux 4.16.12-1 (bookworm)2018
CVE-2018-11508 [MEDIUM] CVE-2018-11508: linux - The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16...
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.
Scope: local
bookworm: resolved (fixed in 4.16.12-1)
bullseye: resolved (fixed in 4.16.12-1)
forky: resolved (fixed in 4.16.12-1)
sid: resolved (fixed in 4.16.12-1)
trixie: resolved (fixed in 4.16.12-1
debian
CVE-2019-15505P3CRITICALCVSS 9.8fixed in linux 5.2.17-1 (bookworm)2019
CVE-2019-15505 [CRITICAL] CVE-2019-15505: linux - drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has...
drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote via usbip or usbredir).
Scope: local
bookworm: resolved (fixed in 5.2.17-1)
bullseye: resolved (fixed in 5.2.17-1)
forky: resolved (fixed in 5.2.17-1)
sid: resolved (fixed in 5.2.17-1)
trixie: resolved (fixed in
debian
CVE-2015-4002P3LOWCVSS 9.0fixed in linux 4.1.3-1 (bookworm)2015
CVE-2015-4002 [CRITICAL] CVE-2015-4002: linux - drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel thro...
drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel through 4.0.5 does not ensure that certain length values are sufficiently large, which allows remote attackers to cause a denial of service (system crash or large loop) or possibly execute arbitrary code via a crafted packet, related to the (1) oz_usb_rx and (2) oz_usb_handle_ep_data functio
debian
CVE-2025-40271P4UNKNOWNPoCfixed in linux 6.1.159-1 (bookworm)2025
CVE-2025-40271 CVE-2025-40271: linux - In the Linux kernel, the following vulnerability has been resolved: fs/proc: fi...
In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtree through rb_erase(), but not set the node to EMPTY, which may result in uaf access. We should use RB_CLEAR_NODE() set the erased node to EMPTY, then pde_subdir_next() will return NULL to avoid uaf access. We found an uaf issue while using
debian
CVE-2021-47323P3HIGHCVSS 8.8fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-47323 [HIGH] CVE-2021-47323: linux - In the Linux kernel, the following vulnerability has been resolved: watchdog: s...
In the Linux kernel, the following vulnerability has been resolved: watchdog: sc520_wdt: Fix possible use-after-free in wdt_turnoff() This module's remove path calls del_timer(). However, that function does not wait until the timer handler finishes. This means that the timer handler may still be running after the driver's remove function has finished, which would resu
debian
CVE-2021-47324P3HIGHCVSS 8.8fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-47324 [HIGH] CVE-2021-47324: linux - In the Linux kernel, the following vulnerability has been resolved: watchdog: F...
In the Linux kernel, the following vulnerability has been resolved: watchdog: Fix possible use-after-free in wdt_startup() This module's remove path calls del_timer(). However, that function does not wait until the timer handler finishes. This means that the timer handler may still be running after the driver's remove function has finished, which would result in a use
debian
CVE-2026-23246P3LOWCVSS 8.8fixed in linux 6.19.8-1 (forky)2026
CVE-2026-23246 [HIGH] CVE-2026-23246: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80...
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration link_id is taken from the ML Reconfiguration element (control & 0x000f), so it can be 0..15. link_removal_timeout[] has IEEE80211_MLD_MAX_NUM_LINKS (15) elements, so index 15 is out-of-bounds. Skip subelements with link_id >= IEEE802
debian
CVE-2014-5207P4MEDIUMCVSS 6.2PoCfixed in linux 3.16.2-1 (bookworm)2014
CVE-2014-5207 [MEDIUM] CVE-2014-5207: linux - fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict cle...
fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing MNT_ATIME_MASK during a remount of a bind mount, which allows local users to gain privileges, interfere with backups and auditing on systems that had atime enabled, or cause a denial of service (excessive filesystem updating) on syst
debian
CVE-2023-6200P3LOWCVSS 7.5fixed in linux 6.6.9-1 (forky)2023
CVE-2023-6200 [HIGH] CVE-2023-6200: linux - A race condition was found in the Linux Kernel. Under certain conditions, an una...
A race condition was found in the Linux Kernel. Under certain conditions, an unauthenticated attacker from an adjacent network could send an ICMPv6 router advertisement packet, causing arbitrary code execution.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.6.9-1)
sid: resolved (fixed in 6.6.9-1)
trixie: resolved (fixed in 6.6.9-1)
debian
CVE-2016-4578P4MEDIUMCVSS 5.5PoCfixed in linux 4.5.5-1 (bookworm)2016
CVE-2016-4578 [MEDIUM] CVE-2016-4578: linux - sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r...
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.
Scope: local
bookworm: resolved (fixed in 4.5.5-1)
bull
debian
CVE-2021-47548P3CRITICALCVSS 9.8fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-47548 [CRITICAL] CVE-2021-47548: linux - In the Linux kernel, the following vulnerability has been resolved: ethernet: h...
In the Linux kernel, the following vulnerability has been resolved: ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port() The if statement: if (port >= DSAF_GE_NUM) return; limits the value of port less than DSAF_GE_NUM (i.e., 8). However, if the value of port is 6 or 7, an array overflow could occur: port_rst_off = d
debian