cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 12 of 632
CVE-2016-3707P3LOWCVSS 8.1fixed in linux 3.15~rc5-1~exp1 (bookworm)2016
CVE-2016-3707 [HIGH] CVE-2016-3707: linux - The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt p... The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Real Time 7 and other products, allows remote attackers to execute SysRq commands via crafted ICMP Echo Request packets, as demonstrated by a brute-force attack to discover a
debian
CVE-2021-47347P3HIGHCVSS 8.8fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-47347 [HIGH] CVE-2021-47347: linux - In the Linux kernel, the following vulnerability has been resolved: wl1251: Fix... In the Linux kernel, the following vulnerability has been resolved: wl1251: Fix possible buffer overflow in wl1251_cmd_scan Function wl1251_cmd_scan calls memcpy without checking the length. Harden by checking the length is within the maximum allowed size. Scope: local bookworm: resolved (fixed in 5.14.6-1) bullseye: resolved (fixed in 5.10.70-1) forky: resolved (fixe
debian
CVE-2024-35955P3HIGHCVSS 8.8fixed in linux 6.1.90-1 (bookworm)2024
CVE-2024-35955 [HIGH] CVE-2024-35955: linux - In the Linux kernel, the following vulnerability has been resolved: kprobes: Fi... In the Linux kernel, the following vulnerability has been resolved: kprobes: Fix possible use-after-free issue on kprobe registration When unloading a module, its state is changing MODULE_STATE_LIVE -> MODULE_STATE_GOING -> MODULE_STATE_UNFORMED. Each change will take a time. `is_module_text_address()` and `__module_text_address()` works with MODULE_STATE_LIVE and MOD
debian
CVE-2024-35854P3HIGHCVSS 8.8fixed in linux 6.1.90-1 (bookworm)2024
CVE-2024-35854 [HIGH] CVE-2024-35854: linux - In the Linux kernel, the following vulnerability has been resolved: mlxsw: spec... In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash The rehash delayed work migrates filters from one region to another according to the number of available credits. The migrated from region is destroyed at the end of the work if the number of credits is non-negative as the assumption
debian
CVE-2019-14821P3HIGHCVSS 8.8fixed in linux 5.2.17-1 (bookworm)2019
CVE-2019-14821 [HIGH] CVE-2019-14821: linux - An out-of-bounds access issue was found in the Linux kernel, all versions throug... An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged h
debian
CVE-2022-32250P3HIGHCVSS 7.8fixed in linux 5.18.2-1 (bookworm)2022
CVE-2022-32250 [HIGH] CVE-2022-32250: linux - net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local ... net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free. Scope: local bookworm: resolved (fixed in 5.18.2-1) bullseye: resolved (fixed in 5.10.120-1) forky: resolved (fixed in 5.18.2-1) sid: resolved (f
debian
CVE-2026-23395P3HIGHCVSS 8.8fixed in linux 6.19.10-1 (forky)2026
CVE-2026-23395 [HIGH] CVE-2026-23395: linux - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ... In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ Currently the code attempts to accept requests regardless of the command identifier which may cause multiple requests to be marked as pending (FLAG_DEFER_SETUP) which can cause more than L2CAP_ECRED_MAX_CID(5) to be allocated in l2cap_ecred
debian
CVE-2022-25636P3HIGHCVSS 7.8fixed in linux 5.16.11-1 (bookworm)2022
CVE-2022-25636 [HIGH] CVE-2022-25636: linux - net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows loca... net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload. Scope: local bookworm: resolved (fixed in 5.16.11-1) bullseye: resolved (fixed in 5.10.103-1) forky: resolved (fixed in 5.16.11-1) sid: resolved (fixed in 5.16.11-1) trixie: resolved (fi
debian
CVE-2013-0268P4MEDIUMCVSS 6.2PoCfixed in linux 3.2.39-1 (bookworm)2013
CVE-2013-0268 [MEDIUM] CVE-2013-0268: linux - The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 ... The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by executing a crafted application as root, as demonstrated by msr32.c. Scope: local bookworm: resolved (fixed in 3.2.39-1) bullseye: resolved (fixed in 3.2.39-1) forky: resolved (fixed in 3.2.39-1) sid: resolved (fixed in 3.2.3
debian
CVE-2016-9555P3CRITICALCVSS 9.8fixed in linux 4.8.11-1 (bookworm)2016
CVE-2016-9555 [CRITICAL] CVE-2016-9555: linux - The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before ... The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data. Scope: local bookworm: resolved (fixed in 4.8.11-1) bullseye: resolved (fixed in
debian
CVE-2017-8797P3HIGHCVSS 7.5fixed in linux 4.9.30-1 (bookworm)2017
CVE-2017-8797 [HIGH] CVE-2017-8797: linux - The NFSv4 server in the Linux kernel before 4.11.3 does not properly validate th... The NFSv4 server in the Linux kernel before 4.11.3 does not properly validate the layout type when processing the NFSv4 pNFS GETDEVICEINFO or LAYOUTGET operand in a UDP packet from a remote attacker. This type value is uninitialized upon encountering certain error conditions. This value is used as an array index for dereferencing, which leads to an OOPS and eventually a
debian
CVE-2019-10220P3HIGHCVSS 8.8fixed in linux 5.3.9-1 (bookworm)2019
CVE-2019-10220 [HIGH] CVE-2019-10220: linux - Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative path... Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists. Scope: local bookworm: resolved (fixed in 5.3.9-1) bullseye: resolved (fixed in 5.3.9-1) forky: resolved (fixed in 5.3.9-1) sid: resolved (fixed in 5.3.9-1) trixie: resolved (fixed in 5.3.9-1)
debian
CVE-2017-7472P4MEDIUMCVSS 5.5PoCfixed in linux 4.9.25-1 (bookworm)2017
CVE-2017-7472 [MEDIUM] CVE-2017-7472: linux - The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to caus... The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEY_REQKEY_DEFL_THREAD_KEYRING keyctl_set_reqkey_keyring calls. Scope: local bookworm: resolved (fixed in 4.9.25-1) bullseye: resolved (fixed in 4.9.25-1) forky: resolved (fixed in 4.9.25-1) sid: resolved (fixed in 4.9.25-1) trixie
debian
CVE-2021-3491P3HIGHCVSS 7.8fixed in linux 5.10.38-1 (bookworm)2021
CVE-2021-3491 [HIGH] CVE-2021-3491: linux - The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be ... The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc//mem. This could be used to create a heap overflow leading to arbitrary code execution in the kernel. It was addressed via commit d1f82808877b ("io_uring: truncate lengths larger th
debian
CVE-2016-6828P4MEDIUMCVSS 5.5PoCfixed in linux 4.7.2-1 (bookworm)2016
CVE-2016-6828 [MEDIUM] CVE-2016-6828: linux - The tcp_check_send_head function in include/net/tcp.h in the Linux kernel before... The tcp_check_send_head function in include/net/tcp.h in the Linux kernel before 4.7.5 does not properly maintain certain SACK state after a failed data copy, which allows local users to cause a denial of service (tcp_xmit_retransmit_queue use-after-free and system crash) via a crafted SACK option. Scope: local bookworm: resolved (fixed in 4.7.2-1) bullseye: resolved
debian
CVE-2022-4379P3HIGHCVSS 7.5fixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-4379 [HIGH] CVE-2022-4379: linux - A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4fil... A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial Scope: local bookworm: resolved (fixed in 6.1.4-1) bullseye: resolved (fixed in 5.10.178-1) forky: resolved (fixed in 6.1.4-1) sid: resolved (fixed in 6.1.4-1) trixie: resolved (fixed in 6.1.4-1)
debian
CVE-2022-27666P3HIGHCVSS 7.8fixed in linux 5.16.18-1 (bookworm)2022
CVE-2022-27666 [HIGH] CVE-2022-27666: linux - A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ip... A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat. Scope: local bookworm: resolved (fixed in 5.16.18-1) bullseye: resolved (fixed in 5.10.113-1) forky: resolved (f
debian
CVE-2023-1194P3HIGHCVSS 7.1fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-1194 [HIGH] CVE-2023-1194: linux - An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KS... An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of `NameOffset` in the `parse_lease_state()` function, the `create_context` object can access invalid memory. Sco
debian
CVE-2024-36896P3CRITICALCVSS 9.1fixed in linux 6.1.94-1 (bookworm)2024
CVE-2024-36896 [CRITICAL] CVE-2024-36896: linux - In the Linux kernel, the following vulnerability has been resolved: USB: core: ... In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix access violation during port device removal Testing with KASAN and syzkaller revealed a bug in port.c:disable_store(): usb_hub_to_struct_hub() can return NULL if the hub that the port belongs to is concurrently removed, but the function does not check for this possibility before der
debian
CVE-2018-1000026P3HIGHCVSS 7.7fixed in linux 4.16.5-1 (bookworm)2018
CVE-2018-1000026 [HIGH] CVE-2018-1000026: linux - Linux Linux kernel version at least v4.8 onwards, probably well before contains ... Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can
debian
Debian Linux vulnerabilities | cvebase