cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 114 of 632
CVE-2025-68283P3UNKNOWNfixed in linux 6.1.159-1 (bookworm)2025
CVE-2025-68283 CVE-2025-68283: linux - In the Linux kernel, the following vulnerability has been resolved: libceph: re... In the Linux kernel, the following vulnerability has been resolved: libceph: replace BUG_ON with bounds check for map->max_osd OSD indexes come from untrusted network packets. Boundary checks are added to validate these against map->max_osd. [ idryomov: drop BUG_ON in ceph_get_primary_affinity(), minor cosmetic edits ] Scope: local bookworm: resolved (fixed in 6.1.159-1) bul
debian
CVE-2025-40171P3UNKNOWNfixed in linux 6.1.158-1 (bookworm)2025
CVE-2025-40171 CVE-2025-40171: linux - In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: m... In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: move lsop put work to nvmet_fc_ls_req_op It’s possible for more than one async command to be in flight from __nvmet_fc_send_ls_req. For each command, a tgtport reference is taken. In the current code, only one put work item is queued at a time, which results in a leaked reference. To fix this, move
debian
CVE-2025-40158P3UNKNOWNfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40158 CVE-2025-40158: linux - In the Linux kernel, the following vulnerability has been resolved: ipv6: use R... In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_output() Use RCU in ip6_output() in order to use dst_dev_rcu() to prevent possible UAF. We can remove rcu_read_lock()/rcu_read_unlock() pairs from ip6_finish_output2(). Scope: local bookworm: open bullseye: open forky: resolved (fixed in 6.17.6-1) sid: resolved (fixed in 6.17.6-1) trixie
debian
CVE-2025-68770P3LOWfixed in linux 6.18.3-1 (forky)2025
CVE-2025-68770 [LOW] CVE-2025-68770: linux - In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fi... In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix XDP_TX path For XDP_TX action in bnxt_rx_xdp(), clearing of the event flags is not correct. __bnxt_poll_work() -> bnxt_rx_pkt() -> bnxt_rx_xdp() may be looping within NAPI and some event flags may be set in earlier iterations. In particular, if BNXT_TX_EVENT is set earlier indicating some
debian
CVE-2025-68241P3UNKNOWNfixed in linux 6.1.159-1 (bookworm)2025
CVE-2025-68241 CVE-2025-68241: linux - In the Linux kernel, the following vulnerability has been resolved: ipv4: route... In the Linux kernel, the following vulnerability has been resolved: ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe The sit driver's packet transmission path calls: sit_tunnel_xmit() -> update_or_create_fnhe(), which lead to fnhe_remove_oldest() being called to delete entries exceeding FNHE_RECLAIM_DEPTH+random. The race window is between fnhe_remove_oldes
debian
CVE-2025-40075P3UNKNOWNfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40075 CVE-2025-40075: linux - In the Linux kernel, the following vulnerability has been resolved: tcp_metrics... In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: use dst_dev_net_rcu() Replace three dst_dev() with a lockdep enabled helper. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 6.17.6-1) sid: resolved (fixed in 6.17.6-1) trixie: resolved (fixed in 6.12.63-1)
debian
CVE-2025-68232P3LOWfixed in linux 6.17.10-1 (forky)2025
CVE-2025-68232 [LOW] CVE-2025-68232: linux - In the Linux kernel, the following vulnerability has been resolved: veth: more ... In the Linux kernel, the following vulnerability has been resolved: veth: more robust handing of race to avoid txq getting stuck Commit dc82a33297fc ("veth: apply qdisc backpressure on full ptr_ring to reduce TX drops") introduced a race condition that can lead to a permanently stalled TXQ. This was observed in production on ARM64 systems (Ampere Altra Max). The race o
debian
CVE-2025-40141P3UNKNOWNfixed in linux 6.1.158-1 (bookworm)2025
CVE-2025-40141 CVE-2025-40141: linux - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ... In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix possible UAF on iso_conn_free This attempt to fix similar issue to sco_conn_free where if the conn->sk is not set to NULL may lead to UAF on iso_conn_free. Scope: local bookworm: resolved (fixed in 6.1.158-1) bullseye: resolved forky: resolved (fixed in 6.17.6-1) sid: resolved (fixed in 6
debian
CVE-2026-23427P3LOWfixed in linux 6.19.10-1 (forky)2026
CVE-2026-23427 [LOW] CVE-2026-23427: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ... In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in durable v2 replay of active file handles parse_durable_handle_context() unconditionally assigns dh_info->fp->conn to the current connection when handling a DURABLE_REQ_V2 context with SMB2_FLAGS_REPLAY_OPERATION. ksmbd_lookup_fd_cguid() does not filter by fp->conn, so it re
debian
CVE-2025-40309P3UNKNOWNfixed in linux 6.1.159-1 (bookworm)2025
CVE-2025-40309 CVE-2025-40309: linux - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ... In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix UAF on sco_conn_free BUG: KASAN: slab-use-after-free in sco_conn_free net/bluetooth/sco.c:87 [inline] BUG: KASAN: slab-use-after-free in kref_put include/linux/kref.h:65 [inline] BUG: KASAN: slab-use-after-free in sco_conn_put+0xdd/0x410 net/bluetooth/sco.c:107 Write of size 8 at addr fff
debian
CVE-2020-36158P3HIGHCVSS 8.8fixed in linux 5.10.5-1 (bookworm)2020
CVE-2020-36158 [HIGH] CVE-2020-36158: linux - mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c i... mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332. Scope: local bookworm: resolved (fixed in 5.10.5-1) bullseye: resolved (fixed in 5.10.5-1) forky: resolved (fixed in 5.10.5-1) sid: resolved (fixed in 5.10.
debian
CVE-2025-40331P3UNKNOWNfixed in linux 6.1.159-1 (bookworm)2025
CVE-2025-40331 CVE-2025-40331: linux - In the Linux kernel, the following vulnerability has been resolved: sctp: Preve... In the Linux kernel, the following vulnerability has been resolved: sctp: Prevent TOCTOU out-of-bounds write For the following path not holding the sock lock, sctp_diag_dump() -> sctp_for_each_endpoint() -> sctp_ep_dump() make sure not to exceed bounds in case the address list has grown between buffer allocation (time-of-check) and write (time-of-use). Scope: local bookworm:
debian
CVE-2025-68347P3UNKNOWNfixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-68347 CVE-2025-68347: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: firew... In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events The DSP event handling code in hwdep_read() could write more bytes to the user buffer than requested, when a user provides a buffer smaller than the event header size (8 bytes). Fix by using min_t() to clamp the copy size, This ensures we
debian
CVE-2025-40118P3UNKNOWNfixed in linux 6.1.158-1 (bookworm)2025
CVE-2025-40118 CVE-2025-40118: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: pm80x... In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod Since commit f7b705c238d1 ("scsi: pm80xx: Set phy_attached to zero when device is gone") UBSAN reports: UBSAN: array-index-out-of-bounds in drivers/scsi/pm8001/pm8001_sas.c:786:17 index 28 is out of range for type 'pm8001_phy [16]' on rmmod when using a
debian
CVE-2025-40027P3UNKNOWNfixed in linux 6.1.158-1 (bookworm)2025
CVE-2025-40027 CVE-2025-40027: linux - In the Linux kernel, the following vulnerability has been resolved: net/9p: fix... In the Linux kernel, the following vulnerability has been resolved: net/9p: fix double req put in p9_fd_cancelled Syzkaller reports a KASAN issue as below: general protection fault, probably for non-canonical address 0xfbd59c0000000021: 0000 [#1] PREEMPT SMP KASAN NOPTI KASAN: maybe wild-memory-access in range [0xdead000000000108-0xdead00000000010f] CPU: 0 PID: 5083 Comm: sy
debian
CVE-2025-39971P3UNKNOWNfixed in linux 6.1.158-1 (bookworm)2025
CVE-2025-39971 CVE-2025-39971: linux - In the Linux kernel, the following vulnerability has been resolved: i40e: fix i... In the Linux kernel, the following vulnerability has been resolved: i40e: fix idx validation in config queues msg Ensure idx is within range of active/initialized TCs when iterating over vf->ch[idx] in i40e_vc_config_queues_msg(). Scope: local bookworm: resolved (fixed in 6.1.158-1) bullseye: resolved (fixed in 5.10.247-1) forky: resolved (fixed in 6.16.10-1) sid: resolved (
debian
CVE-2025-39969P3UNKNOWNfixed in linux 6.1.158-1 (bookworm)2025
CVE-2025-39969 CVE-2025-39969: linux - In the Linux kernel, the following vulnerability has been resolved: i40e: fix v... In the Linux kernel, the following vulnerability has been resolved: i40e: fix validation of VF state in get resources VF state I40E_VF_STATE_ACTIVE is not the only state in which VF is actually active so it should not be used to determine if a VF is allowed to obtain resources. Use I40E_VF_STATE_RESOURCES_LOADED that is set only in i40e_vc_get_vf_resources_msg() and cleared
debian
CVE-2025-40054P3UNKNOWNfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40054 CVE-2025-40054: linux - In the Linux kernel, the following vulnerability has been resolved: f2fs: fix U... In the Linux kernel, the following vulnerability has been resolved: f2fs: fix UAF issue in f2fs_merge_page_bio() As JY reported in bugzilla [1], Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 pc : [0xffffffe51d249484] f2fs_is_cp_guaranteed+0x70/0x98 lr : [0xffffffe51d24adbc] f2fs_merge_page_bio+0x520/0x6d4 CPU: 3 UID: 0 PID: 6790 Comm: k
debian
CVE-2025-39972P3UNKNOWNfixed in linux 6.1.158-1 (bookworm)2025
CVE-2025-39972 CVE-2025-39972: linux - In the Linux kernel, the following vulnerability has been resolved: i40e: fix i... In the Linux kernel, the following vulnerability has been resolved: i40e: fix idx validation in i40e_validate_queue_map Ensure idx is within range of active/initialized TCs when iterating over vf->ch[idx] in i40e_validate_queue_map(). Scope: local bookworm: resolved (fixed in 6.1.158-1) bullseye: resolved (fixed in 5.10.247-1) forky: resolved (fixed in 6.16.10-1) sid: resolv
debian
CVE-2025-40079P3LOWfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40079 [LOW] CVE-2025-40079: linux - In the Linux kernel, the following vulnerability has been resolved: riscv, bpf:... In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Sign extend struct ops return values properly The ns_bpf_qdisc selftest triggers a kernel panic: Unable to handle kernel paging request at virtual address ffffffffa38dbf58 Current test_progs pgtable: 4K pagesize, 57-bit VAs, pgdp=0x00000001109cc000 [ffffffffa38dbf58] pgd=000000011fffd801, p
debian
Debian Linux vulnerabilities | cvebase