Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 13 of 632
CVE-2022-42719P3HIGHCVSS 8.8fixed in linux 6.0.2-1 (bookworm)2022
CVE-2022-42719 [HIGH] CVE-2022-42719: linux - A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the...
A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.
Scope: local
bookworm: resolved (fixed in 6.0.2-1)
bullseye: resolved (fixed in 5.10.149-1)
forky: resolved (fixed in 6.0.2-1)
sid: reso
debian
CVE-2023-52798P3HIGHCVSS 8.8fixed in linux 6.1.64-1 (bookworm)2023
CVE-2023-52798 [HIGH] CVE-2023-52798: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath11...
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix dfs radar event locking The ath11k active pdevs are protected by RCU but the DFS radar event handling code calling ath11k_mac_get_ar_by_pdev_id() was not marked as a read-side critical section. Mark the code in question as an RCU read-side critical section to avoid any potential use-
debian
CVE-2015-1421P3CRITICALCVSS 10.0fixed in linux 3.16.7-ckt4-3 (bookworm)2015
CVE-2015-1421 [CRITICAL] CVE-2015-1421: linux - Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/assoc...
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2024-43847P3LOWCVSS 8.8fixed in linux 6.10.3-1 (forky)2024
CVE-2024-43847 [HIGH] CVE-2024-43847: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath12...
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix invalid memory access while processing fragmented packets The monitor ring and the reo reinject ring share the same ring mask index. When the driver receives an interrupt for the reo reinject ring, the monitor ring is also processed, leading to invalid memory access. Since monitor su
debian
CVE-2012-6712P3CRITICALCVSS 9.8fixed in linux 3.8.11-1 (bookworm)2012
CVE-2012-6712 [CRITICAL] CVE-2012-6712: linux - In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless...
In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause at least memory corruption.
Scope: local
bookworm: resolved (fixed in 3.8.11-1)
bullseye: resolved (fixed in 3.8.11-1)
forky: resolved (fixed in 3.8.11-1)
sid: resolved (fixed in 3.8.11-1)
trixie: resolved (fixed in 3.8.11-1)
debian
CVE-2013-2850P3HIGHCVSS 7.9fixed in linux 3.9.4-1 (bookworm)2013
CVE-2013-2850 [HIGH] CVE-2013-2850: linux - Heap-based buffer overflow in the iscsi_add_notunderstood_response function in d...
Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory corruption and OOPS) or possibly execute arbitrary code via a long key that is not properly handled during construction o
debian
CVE-2025-21759P3HIGHCVSS 7.8fixed in linux 6.12.16-1 (forky)2025
CVE-2025-21759 [HIGH] CVE-2025-21759: linux - In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast...
In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: extend RCU protection in igmp6_send() igmp6_send() can be called without RTNL or RCU being held. Extend RCU protection so that we can safely fetch the net pointer and avoid a potential UAF. Note that we no longer can use sock_alloc_send_skb() because ipv6.igmp_sk uses GFP_KERNEL allocatio
debian
CVE-2023-4147P3HIGHCVSS 7.8fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-4147 [HIGH] CVE-2023-4147: linux - A use-after-free flaw was found in the Linux kernel’s Netfilter functionality wh...
A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system.
Scope: local
bookworm: resolved (fixed in 6.1.52-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.4.11-1)
sid: resolved (fixed in 6.4.11-1)
trix
debian
CVE-2023-38427P3CRITICALCVSS 9.8fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-38427 [CRITICAL] CVE-2023-38427: linux - An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu....
An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts.
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved
forky: resolved (fixed in 6.3.11-1)
sid: resolved (fixed in 6.3.11-1)
trixie: resolved (fixed in 6.3.11-1)
debian
CVE-2022-48716P3CRITICALCVSS 9.8fixed in linux 5.16.10-1 (bookworm)2022
CVE-2022-48716 [CRITICAL] CVE-2022-48716: linux - In the Linux kernel, the following vulnerability has been resolved: ASoC: codec...
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd938x: fix incorrect used of portid Mixer controls have the channel id in mixer->reg, which is not same as port id. port id should be derived from chan_info array. So fix this. Without this, its possible that we could corrupt struct wcd938x_sdw_priv by accessing port_map array out
debian
CVE-2026-23112P3CRITICALCVSS 9.8fixed in linux 6.1.164-1 (bookworm)2026
CVE-2026-23112 [CRITICAL] CVE-2026-23112: linux - In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: ...
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU length or offset exceeds sg_cnt and then use bogus sg->length/offset values, leading to _copy_to_iter() GPF/KASAN. Guard sg_idx, remaining entries, and sg->length/offset bef
debian
CVE-2022-41674P3HIGHCVSS 8.1fixed in linux 6.0.2-1 (bookworm)2022
CVE-2022-41674 [HIGH] CVE-2022-41674: linux - An issue was discovered in the Linux kernel before 5.19.16. Attackers able to in...
An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.
Scope: local
bookworm: resolved (fixed in 6.0.2-1)
bullseye: resolved (fixed in 5.10.149-1)
forky: resolved (fixed in 6.0.2-1)
sid: resolved (fixed in 6.0.2-1)
trixie: resolved
debian
CVE-2023-52735P3CRITICALCVSS 9.1fixed in linux 6.1.15-1 (bookworm)2023
CVE-2023-52735 [CRITICAL] CVE-2023-52735: linux - In the Linux kernel, the following vulnerability has been resolved: bpf, sockma...
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself sock_map proto callbacks should never call themselves by design. Protect against bugs like [1] and break out of the recursive loop to avoid a stack overflow in favor of a resource leak. [1] https://lore.kernel.org/all/000000000000
debian
CVE-2023-38430P3CRITICALCVSS 9.1fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-38430 [CRITICAL] CVE-2023-38430: linux - An issue was discovered in the Linux kernel before 6.3.9. ksmbd does not validat...
An issue was discovered in the Linux kernel before 6.3.9. ksmbd does not validate the SMB request protocol ID, leading to an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved
forky: resolved (fixed in 6.3.11-1)
sid: resolved (fixed in 6.3.11-1)
trixie: resolved (fixed in 6.3.11-1)
debian
CVE-2019-10125P3CRITICALCVSS 9.8fixed in linux 4.19.37-1 (bookworm)2019
CVE-2019-10125 [CRITICAL] CVE-2019-10125: linux - An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5....
An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_wake() if an expected event is triggered immediately (e.g., by the close of a pair of pipes) after the return of vfs_poll(), and this will cause a use-after-free.
Scope: local
bookworm: resolved (fixed in 4.19.37-1)
bullseye: resolved (fixed in 4
debian
CVE-2022-47943P3HIGHCVSS 8.1fixed in linux 5.19.6-1 (bookworm)2022
CVE-2022-47943 [HIGH] CVE-2022-47943: linux - An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5....
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is an out-of-bounds read and OOPS for SMB2_WRITE, when there is a large length in the zero DataOffset case.
Scope: local
bookworm: resolved (fixed in 5.19.6-1)
bullseye: resolved
forky: resolved (fixed in 5.19.6-1)
sid: resolved (fixed in 5.19.6-1)
trixie: resolved (fixed in 5.
debian
CVE-2015-4001P3LOWCVSS 9.0fixed in linux 4.1.3-1 (bookworm)2015
CVE-2015-4001 [CRITICAL] CVE-2015-4001: linux - Integer signedness error in the oz_hcd_get_desc_cnf function in drivers/staging/...
Integer signedness error in the oz_hcd_get_desc_cnf function in drivers/staging/ozwpan/ozhcd.c in the OZWPAN driver in the Linux kernel through 4.0.5 allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted packet.
Scope: local
bookworm: resolved (fixed in 4.1.3-1)
bullseye: resolved (fixed in 4.1.3-1)
fork
debian
CVE-2021-28660P3HIGHCVSS 8.8fixed in linux 5.10.24-1 (bookworm)2021
CVE-2021-28660 [HIGH] CVE-2021-28660: linux - rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux k...
rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work); however, system integrators may have situations in which a drivers/staging issue is relevant t
debian
CVE-2014-2851P4LOWCVSS 6.9PoCfixed in linux 3.14.4-1 (bookworm)2014
CVE-2014-2851 [MEDIUM] CVE-2014-2851: linux - Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux ...
Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that leverages an improperly managed reference counter.
Scope: local
bookworm: resolved (fixed in 3.14.4-1)
bullseye: resolved (fixe
debian
CVE-2023-32252P3HIGHCVSS 7.5fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-32252 [HIGH] CVE-2023-32252: linux - A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB s...
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_LOGOFF commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Scope: local
bookworm: re
debian