cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 116 of 632
CVE-2022-3565P3MEDIUMCVSS 4.6fixed in linux 6.0.3-1 (bookworm)2022
CVE-2022-3565 [MEDIUM] CVE-2022-3565: linux - A vulnerability, which was classified as critical, has been found in Linux Kerne... A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function del_timer of the file drivers/isdn/mISDN/l1oip_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211088. Scope: local bookw
debian
CVE-2021-3772P3MEDIUMCVSS 6.5fixed in linux 5.14.16-1 (bookworm)2021
CVE-2021-3772 [MEDIUM] CVE-2021-3772: linux - A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill a... A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses. Scope: local bookworm: resolved (fixed in 5.14.16-1) bullseye: resolved (fixed in 5.10.84-1) forky: resolved (f
debian
CVE-2023-3866P3MEDIUMCVSS 5.5fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-3866 [MEDIUM] CVE-2023-3866: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: vali... In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in the compound request This patch validate session id and tree id in compound request. If first operation in the compound is SMB2 ECHO request, ksmbd bypass session and tree validation. So work->sess and work->tcon could be NULL. If secound request in the compou
debian
CVE-2017-7618P3HIGHCVSS 7.5fixed in linux 4.9.25-1 (bookworm)2017
CVE-2017-7618 [HIGH] CVE-2017-7618: linux - crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a de... crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue. Scope: local bookworm: resolved (fixed in 4.9.25-1) bullseye: resolved (fixed in 4.9.25-1) forky: resolved (fixed in 4.9.25-1) sid: resolved (fixed in 4.9.25-1) trixie: resol
debian
CVE-2019-19044P3HIGHCVSS 7.5fixed in linux 5.3.15-1 (bookworm)2019
CVE-2019-19044 [HIGH] CVE-2019-19044: linux - Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3... Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering kcalloc() or v3d_job_init() failures, aka CID-29cd13cfd762. Scope: local bookworm: resolved (fixed in 5.3.15-1) bullseye: resolved (fixed in 5.3.15-1) forky: resolved (
debian
CVE-2019-0136P3HIGHCVSS 7.4fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-0136 [HIGH] CVE-2019-0136: linux - Insufficient access control in the Intel(R) PROSet/Wireless WiFi Software driver... Insufficient access control in the Intel(R) PROSet/Wireless WiFi Software driver before version 21.10 may allow an unauthenticated user to potentially enable denial of service via adjacent access. Scope: local bookworm: resolved (fixed in 5.2.6-1) bullseye: resolved (fixed in 5.2.6-1) forky: resolved (fixed in 5.2.6-1) sid: resolved (fixed in 5.2.6-1) trixie: resolved (
debian
CVE-2018-3693P3MEDIUMCVSS 5.6fixed in linux 4.15.11-1 (bookworm)2018
CVE-2018-3693 [MEDIUM] CVE-2018-3693: linux - Systems with microprocessors utilizing speculative execution and branch predicti... Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis. Scope: local bookworm: resolved (fixed in 4.15.11-1) bullseye: resolved (fixed in 4.15.11-1) forky: resolved (fixed in 4.15.11-1) sid: reso
debian
CVE-2019-12615P3LOWCVSS 7.5fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-12615 [HIGH] CVE-2019-12615: linux - An issue was discovered in get_vdev_port_node_info in arch/sparc/kernel/mdesc.c ... An issue was discovered in get_vdev_port_node_info in arch/sparc/kernel/mdesc.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup_const of node_info->vdev_port.name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). Scope: local bookworm: resolved (fixed in 5.2.6-1) bullseye: resolved (fixed in 5.2.6
debian
CVE-2023-28410P3HIGHCVSS 8.8fixed in linux 5.17.3-1 (bookworm)2023
CVE-2023-28410 [HIGH] CVE-2023-28410: linux - Improper restriction of operations within the bounds of a memory buffer in some ... Improper restriction of operations within the bounds of a memory buffer in some Intel(R) i915 Graphics drivers for linux before kernel version 6.2.10 may allow an authenticated user to potentially enable escalation of privilege via local access. Scope: local bookworm: resolved (fixed in 5.17.3-1) bullseye: resolved (fixed in 5.10.113-1) forky: resolved (fixed in 5.17.
debian
CVE-2024-2193P3MEDIUMCVSS 5.7fixed in xen 4.17.5+23-ga4e5191dc0-1 (bookworm)2024
CVE-2024-2193 [MEDIUM] CVE-2024-2193: linux - A Speculative Race Condition (SRC) vulnerability that impacts modern CPU archite... A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths. Scope: local bookworm: open bullseye
debian
CVE-2025-39946P3CRITICALCVSS 9.8fixed in linux 6.1.158-1 (bookworm)2025
CVE-2025-39946 [CRITICAL] CVE-2025-39946: linux - In the Linux kernel, the following vulnerability has been resolved: tls: make s... In the Linux kernel, the following vulnerability has been resolved: tls: make sure to abort the stream if headers are bogus Normally we wait for the socket to buffer up the whole record before we service it. If the socket has a tiny buffer, however, we read out the data sooner, to prevent connection stalls. Make sure that we abort the connection when we find out l
debian
CVE-2024-26945P3LOWCVSS 8.4fixed in linux 6.8.9-1 (forky)2024
CVE-2024-26945 [HIGH] CVE-2024-26945: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: iaa... In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - Fix nr_cpus < nr_iaa case If nr_cpus < nr_iaa, the calculated cpus_per_iaa will be 0, which causes a divide-by-0 in rebalance_wq_table(). Make sure cpus_per_iaa is 1 in that case, and also in the nr_iaa == 0 case, even though cpus_per_iaa is never used if nr_iaa == 0, for paranoia. Scope
debian
CVE-2013-4348P3HIGHCVSS 7.1fixed in linux 3.11.6-2 (bookworm)2013
CVE-2013-4348 [HIGH] CVE-2013-4348: linux - The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel t... The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of a packet with IPIP encapsulation. Scope: local bookworm: resolved (fixed in 3.11.6-2) bullseye: resolved (fixed in 3.11.6-2) forky: resolved (fixed in 3.11.6-2) sid: resolve
debian
CVE-2016-4486P4LOWCVSS 3.3PoCfixed in linux 4.5.4-1 (bookworm)2016
CVE-2016-4486 [LOW] CVE-2016-4486: linux - The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel be... The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message. Scope: local bookworm: resolved (fixed in 4.5.4-1) bullseye: resolved (fixed in 4.5.4-1) forky: resolved (fixed in 4.5.4-1)
debian
CVE-2015-8967P3LOWCVSS 7.8fixed in linux 4.0.2-1 (bookworm)2015
CVE-2015-8967 [HIGH] CVE-2015-8967: linux - arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to byp... arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and consequently gain privileges, by leveraging write access. Scope: local bookworm: resolved (fixed in 4.0.2-1) bullseye: resolved (fixed in 4.0.2-1) forky: resolved (fixed in 4.0.2-1) sid: resolved (fi
debian
CVE-2018-10878P3HIGHCVSS 7.8fixed in linux 4.17.3-1 (bookworm)2018
CVE-2018-10878 [HIGH] CVE-2018-10878: linux - A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a... A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image. Scope: local bookworm: resolved (fixed in 4.17.3-1) bullseye: resolved (fixed in 4.17.3-1) forky: resolved (fixed in 4.17.3-1) sid: resolved (fix
debian
CVE-2022-3526P3MEDIUMCVSS 5.3fixed in linux 5.17.6-1 (bookworm)2022
CVE-2022-3526 [MEDIUM] CVE-2022-3526: linux - A vulnerability classified as problematic was found in Linux Kernel. This vulner... A vulnerability classified as problematic was found in Linux Kernel. This vulnerability affects the function macvlan_handle_frame of the file drivers/net/macvlan.c of the component skb. The manipulation leads to memory leak. The attack can be initiated remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211024. S
debian
CVE-2022-3541P3MEDIUMCVSS 5.5fixed in linux 6.0.3-1 (bookworm)2022
CVE-2022-3541 [MEDIUM] CVE-2022-3541: linux - A vulnerability classified as critical has been found in Linux Kernel. This affe... A vulnerability classified as critical has been found in Linux Kernel. This affects the function spl2sw_nvmem_get_mac_address of the file drivers/net/ethernet/sunplus/spl2sw_driver.c of the component BPF. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211041 was assigned to this vulnerability. Scope:
debian
CVE-2020-13974P3HIGHCVSS 7.8fixed in linux 5.7.6-1 (bookworm)2020
CVE-2020-13974 [HIGH] CVE-2020-13974: linux - An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/ke... An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_ascii is called several times in a row, aka CID-b86dab054059. NOTE: Members in the community argue that the integer overflow does not lead to a security issue in this case. Scope: local bookworm: resolved (fixed in 5.7.6-1) bullseye: resolved (fixed in
debian
CVE-2018-13406P3HIGHCVSS 7.8fixed in linux 4.17.6-1 (bookworm)2018
CVE-2018-13406 [HIGH] CVE-2018-13406: linux - An integer overflow in the uvesafb_setcmap function in drivers/video/fbdev/uvesa... An integer overflow in the uvesafb_setcmap function in drivers/video/fbdev/uvesafb.c in the Linux kernel before 4.17.4 could result in local attackers being able to crash the kernel or potentially elevate privileges because kmalloc_array is not used. Scope: local bookworm: resolved (fixed in 4.17.6-1) bullseye: resolved (fixed in 4.17.6-1) forky: resolved (fixed in 4.
debian
Debian Linux vulnerabilities | cvebase