cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 11 of 632
CVE-2023-38426P3CRITICALCVSS 9.1fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-38426 [CRITICAL] CVE-2023-38426: linux - An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bo... An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length. Scope: local bookworm: resolved (fixed in 6.1.37-1) bullseye: resolved forky: resolved (fixed in 6.3.7-1) sid: resolved (fixed in 6.3.7-1) trixie: resolved (fixed in 6.3.7-1)
debian
CVE-2019-17666P3HIGHCVSS 8.8fixed in linux 5.3.9-1 (bookworm)2019
CVE-2019-17666 [HIGH] CVE-2019-17666: linux - rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel ... rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow. Scope: local bookworm: resolved (fixed in 5.3.9-1) bullseye: resolved (fixed in 5.3.9-1) forky: resolved (fixed in 5.3.9-1) sid: resolved (fixed in 5.3.9-1) trixie: resolved (fixed in 5.3.9-1)
debian
CVE-2026-23450P3UNKNOWNfixed in linux 6.19.10-1 (forky)2026
CVE-2026-23450 CVE-2026-23450: linux - In the Linux kernel, the following vulnerability has been resolved: net/smc: fi... In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softirq) via icsk_af_ops->syn_recv_sock on the clcsock (TCP listening socket). It reads sk_user_data to get the smc_sock point
debian
CVE-2017-1000410P3HIGHCVSS 8.0fixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-1000410 [HIGH] CVE-2017-1000410: linux - The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies i... The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned to an attacker in their uninitialized state. By manipulating the code flows that precede the handling of these conf
debian
CVE-2024-47685P3CRITICALCVSS 9.1fixed in linux 6.1.115-1 (bookworm)2024
CVE-2024-47685 [CRITICAL] CVE-2024-47685: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ... In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put() syzbot reported that nf_reject_ip6_tcphdr_put() was possibly sending garbage on the four reserved tcp bits (th->res1) Use skb_put_zero() to clear the whole TCP header, as done in nf_reject_ip_tcphdr_put() BUG: KMSAN: uninit-value in nf_reje
debian
CVE-2013-3301P4LOWCVSS 7.2PoCfixed in linux 3.8.11-1 (bookworm)2013
CVE-2013-3301 [HIGH] CVE-2013-3301: linux - The ftrace implementation in the Linux kernel before 3.8.8 allows local users to... The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call. Scope: local bookworm:
debian
CVE-2014-3631P4HIGHCVSS 7.2PoCfixed in linux 3.16.3-1 (bookworm)2014
CVE-2014-3631 [HIGH] CVE-2014-3631: linux - The assoc_array_gc function in the associative-array implementation in lib/assoc... The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via multiple "keyctl newring" operations followed by a "keyct
debian
CVE-2013-2852P4LOWCVSS 6.9PoCfixed in linux 3.9.8-1 (bookworm)2013
CVE-2013-2852 [MEDIUM] CVE-2013-2852: linux - Format string vulnerability in the b43_request_firmware function in drivers/net/... Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message. Scope:
debian
CVE-2025-21760P3HIGHCVSS 7.8fixed in linux 6.1.129-1 (bookworm)2025
CVE-2025-21760 [HIGH] CVE-2025-21760: linux - In the Linux kernel, the following vulnerability has been resolved: ndisc: exte... In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU protection in ndisc_send_skb() ndisc_send_skb() can be called without RTNL or RCU held. Acquire rcu_read_lock() earlier, so that we can use dev_net_rcu() and avoid a potential UAF. Scope: local bookworm: resolved (fixed in 6.1.129-1) bullseye: resolved (fixed in 5.10.237-1) forky: re
debian
CVE-2013-1773P4MEDIUMCVSS 6.2PoCfixed in linux 3.2.15-1 (bookworm)2013
CVE-2013-1773 [MEDIUM] CVE-2013-1773: linux - Buffer overflow in the VFAT filesystem implementation in the Linux kernel before... Buffer overflow in the VFAT filesystem implementation in the Linux kernel before 3.3 allows local users to gain privileges or cause a denial of service (system crash) via a VFAT write operation on a filesystem with the utf8 mount option, which is not properly handled during UTF-8 to UTF-16 conversion. Scope: local bookworm: resolved (fixed in 3.2.15-1) bullseye: resol
debian
CVE-2022-23222P3HIGHCVSS 7.8fixed in linux 5.15.15-1 (bookworm)2022
CVE-2022-23222 [HIGH] CVE-2022-23222: linux - kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to ... kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types. Scope: local bookworm: resolved (fixed in 5.15.15-1) bullseye: resolved (fixed in 5.10.92-1) forky: resolved (fixed in 5.15.15-1) sid: resolved (fixed in 5.15.15-1) trixie: resolved (fixe
debian
CVE-2017-18379P3CRITICALCVSS 9.8fixed in linux 4.14.2-1 (bookworm)2017
CVE-2017-18379 [CRITICAL] CVE-2017-18379: linux - In the Linux kernel before 4.14, an out of boundary access happened in drivers/n... In the Linux kernel before 4.14, an out of boundary access happened in drivers/nvme/target/fc.c. Scope: local bookworm: resolved (fixed in 4.14.2-1) bullseye: resolved (fixed in 4.14.2-1) forky: resolved (fixed in 4.14.2-1) sid: resolved (fixed in 4.14.2-1) trixie: resolved (fixed in 4.14.2-1)
debian
CVE-2018-14633P3HIGHCVSS 7.0fixed in linux 4.18.10-1 (bookworm)2018
CVE-2018-14633 [HIGH] CVE-2018-14633: linux - A security flaw was found in the chap_server_compute_md5() function in the ISCSI... A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker can cause a stack buffer overflow and smash up to 17 bytes of the stack. The attack requires the iSCSI target to be enabled on the victim host. Depen
debian
CVE-2017-9150P4MEDIUMCVSS 5.5PoCfixed in linux 4.9.30-1 (bookworm)2017
CVE-2017-9150 [MEDIUM] CVE-2017-9150: linux - The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1... The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting the output of the print_bpf_insn function, which allows local users to obtain sensitive address information via crafted bpf system calls. Scope: local bookworm: resolved (fixed in 4.9.30-1) bullseye: resolved (fixed in 4.9.
debian
CVE-2018-20836P3HIGHCVSS 8.1fixed in linux 5.2.6-1 (bookworm)2018
CVE-2018-20836 [HIGH] CVE-2018-20836: linux - An issue was discovered in the Linux kernel before 4.20. There is a race conditi... An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free. Scope: local bookworm: resolved (fixed in 5.2.6-1) bullseye: resolved (fixed in 5.2.6-1) forky: resolved (fixed in 5.2.6-1) sid: resolved (fixed in 5.2.6-1) trixie: resolved (f
debian
CVE-2018-18397P4MEDIUMCVSS 5.5PoCfixed in linux 4.19.9-1 (bookworm)2018
CVE-2018-18397 [MEDIUM] CVE-2018-18397: linux - The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles acce... The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c. Scope: local bookworm: resolved (f
debian
CVE-2026-23240P3CRITICALCVSS 9.8fixed in linux 6.19.6-1 (forky)2026
CVE-2026-23240 [CRITICAL] CVE-2026-23240: linux - In the Linux kernel, the following vulnerability has been resolved: tls: Fix ra... In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() This issue was discovered during a code audit. After cancel_delayed_work_sync() is called from tls_sk_proto_close(), tx_work_handler() can still be scheduled from paths such as the Delayed ACK handler or ksoftirqd. As a result, the tx_work_handler
debian
CVE-2023-2156P3HIGHCVSS 7.5fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-2156 [HIGH] CVE-2023-2156: linux - A flaw was found in the networking subsystem of the Linux kernel within the hand... A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system. Scope: local bookworm: resolved (fixed in 6.1.
debian
CVE-2019-11815P3HIGHCVSS 8.1fixed in linux 4.19.37-1 (bookworm)2019
CVE-2019-11815 [HIGH] CVE-2019-11815: linux - An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kerne... An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup. Scope: local bookworm: resolved (fixed in 4.19.37-1) bullseye: resolved (fixed in 4.19.37-1) forky: resolved (fixed in 4.19.37-1) sid: resolved (fixed in 4.19.37-1) trixie: resolved (fi
debian
CVE-2026-31405P3UNKNOWNfixed in linux 6.19.10-1 (forky)2026
CVE-2026-31405 CVE-2026-31405: linux - In the Linux kernel, the following vulnerability has been resolved: media: dvb-... In the Linux kernel, the following vulnerability has been resolved: media: dvb-net: fix OOB access in ULE extension header tables The ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tables in handle_one_ule_extension() are declared with 255 elements (valid indices 0-254), but the index htype is derived from network-controlled data as (ule_sndu_type & 0x00FF), gi
debian
Debian Linux vulnerabilities | cvebase