Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 130 of 632
CVE-2018-3646P3MEDIUMCVSS 5.6fixed in intel-microcode 3.20180703.1 (bookworm)2018
CVE-2018-3646 [MEDIUM] CVE-2018-3646: intel-microcode - Systems with microprocessors utilizing speculative execution and address transla...
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.
Scope: local
bookworm: resolved (fixed in 3.20180703.1)
bullseye: resolved (fi
debian
CVE-2019-19064P3LOWCVSS 7.5fixed in linux 5.4.13-1 (bookworm)2019
CVE-2019-19064 [HIGH] CVE-2019-19064: linux - A memory leak in the fsl_lpspi_probe() function in drivers/spi/spi-fsl-lpspi.c i...
A memory leak in the fsl_lpspi_probe() function in drivers/spi/spi-fsl-lpspi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering pm_runtime_get_sync() failures, aka CID-057b8945f78f. NOTE: third parties dispute the relevance of this because an attacker cannot realistically control these failures at prob
debian
CVE-2012-5375P4LOWCVSS 4.0PoCfixed in linux 3.8-1 (bookworm)2012
CVE-2012-5375 [MEDIUM] CVE-2012-5375: linux - The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc...
The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial of service (prevention of file creation) by leveraging the ability to write to a directory important to the victim, and creating a file with a crafted name that is associated with a specific CRC32C hash value.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2019-16413P3HIGHCVSS 7.5fixed in linux 4.19.37-1 (bookworm)2019
CVE-2019-16413 [HIGH] CVE-2019-16413: linux - An issue was discovered in the Linux kernel before 5.0.4. The 9p filesystem did ...
An issue was discovered in the Linux kernel before 5.0.4. The 9p filesystem did not protect i_size_write() properly, which causes an i_size_read() infinite loop and denial of service on SMP systems.
Scope: local
bookworm: resolved (fixed in 4.19.37-1)
bullseye: resolved (fixed in 4.19.37-1)
forky: resolved (fixed in 4.19.37-1)
sid: resolved (fixed in 4.19.37-1)
trixie
debian
CVE-2019-18807P3HIGHCVSS 7.5fixed in linux 5.3.7-1 (bookworm)2019
CVE-2019-18807 [HIGH] CVE-2019-18807: linux - Two memory leaks in the sja1105_static_config_upload() function in drivers/net/d...
Two memory leaks in the sja1105_static_config_upload() function in drivers/net/dsa/sja1105/sja1105_spi.c in the Linux kernel before 5.3.5 allow attackers to cause a denial of service (memory consumption) by triggering static_config_buf_prepare_for_upload() or sja1105_inhibit_tx() failures, aka CID-68501df92d11.
Scope: local
bookworm: resolved (fixed in 5.3.7-1)
bullse
debian
CVE-2016-8636P3HIGHCVSS 7.8fixed in linux 4.9.10-1 (bookworm)2016
CVE-2016-8636 [HIGH] CVE-2016-8636: linux - Integer overflow in the mem_check_range function in drivers/infiniband/sw/rxe/rx...
Integer overflow in the mem_check_range function in drivers/infiniband/sw/rxe/rxe_mr.c in the Linux kernel before 4.9.10 allows local users to cause a denial of service (memory corruption), obtain sensitive information from kernel memory, or possibly have unspecified other impact via a write or read request involving the "RDMA protocol over infiniband" (aka Soft RoCE) t
debian
CVE-2023-6931P3HIGHCVSS 7.8fixed in linux 6.1.69-1 (bookworm)2023
CVE-2023-6931 [HIGH] CVE-2023-6931: linux - A heap out-of-bounds write vulnerability in the Linux kernel's Performance Event...
A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group(). We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.
Scope: local
bookworm: reso
debian
CVE-2018-14734P3HIGHCVSS 7.8fixed in linux 4.17.14-1 (bookworm)2018
CVE-2018-14734 [HIGH] CVE-2018-14734: linux - drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_l...
drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_leave_multicast to access a certain data structure after a cleanup step in ucma_process_join, which allows attackers to cause a denial of service (use-after-free).
Scope: local
bookworm: resolved (fixed in 4.17.14-1)
bullseye: resolved (fixed in 4.17.14-1)
forky: resolved (fixed in 4.17.14-
debian
CVE-2023-4622P3HIGHCVSS 7.8fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-4622 [HIGH] CVE-2023-4622: linux - A use-after-free vulnerability in the Linux kernel's af_unix component can be ex...
A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collecti
debian
CVE-2022-29900P3MEDIUMCVSS 6.5fixed in linux 5.18.14-1 (bookworm)2022
CVE-2022-29900 [MEDIUM] CVE-2022-29900: linux - Mis-trained branch predictions for return instructions may allow arbitrary specu...
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
Scope: local
bookworm: resolved (fixed in 5.18.14-1)
bullseye: resolved (fixed in 5.10.136-1)
forky: resolved (fixed in 5.18.14-1)
sid: resolved (fixed in 5.18.14-1)
trixie: resolved (fixed in 5.18.14-1)
debian
CVE-2016-4913P3HIGHCVSS 7.8fixed in linux 4.5.4-1 (bookworm)2016
CVE-2016-4913 [HIGH] CVE-2016-4913: linux - The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel befo...
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.
Scope: local
bookworm: resolved (fixed in 4.5.4-1)
bullseye: res
debian
CVE-2016-4805P3HIGHCVSS 7.8fixed in linux 4.5.2-1 (bookworm)2016
CVE-2016-4805 [HIGH] CVE-2016-4805: linux - Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kerne...
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.
Scope: local
bookworm: res
debian
CVE-2015-3288P3HIGHCVSS 7.8fixed in linux 4.2-1 (bookworm)2015
CVE-2015-3288 [HIGH] CVE-2015-3288: linux - mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which a...
mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or cause a denial of service (page tainting) via a crafted application that triggers writing to page zero.
Scope: local
bookworm: resolved (fixed in 4.2-1)
bullseye: resolved (fixed in 4.2-1)
forky: resolved (fixed in 4.2-1)
sid: resolved (fixed in 4.2-1)
debian
CVE-2017-18222P3HIGHCVSS 7.8fixed in linux 4.15.17-1 (bookworm)2017
CVE-2017-18222 [HIGH] CVE-2017-18222: linux - In the Linux kernel before 4.12, Hisilicon Network Subsystem (HNS) does not cons...
In the Linux kernel before 4.12, Hisilicon Network Subsystem (HNS) does not consider the ETH_SS_PRIV_FLAGS case when retrieving sset_count data, which allows local users to cause a denial of service (buffer overflow and memory corruption) or possibly have unspecified other impact, as demonstrated by incompatibility between hns_get_sset_count and ethtool_get_strings.
S
debian
CVE-2017-15115P3HIGHCVSS 7.8fixed in linux 4.13.13-1 (bookworm)2017
CVE-2017-15115 [HIGH] CVE-2017-15115: linux - The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.1...
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls.
Scope: local
bookworm: resolved (fixed in 4.13.13-1)
bullsey
debian
CVE-2022-24958P3HIGHCVSS 7.8fixed in linux 5.16.14-1 (bookworm)2022
CVE-2022-24958 [HIGH] CVE-2022-24958: linux - drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles ...
drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.
Scope: local
bookworm: resolved (fixed in 5.16.14-1)
bullseye: resolved (fixed in 5.10.106-1)
forky: resolved (fixed in 5.16.14-1)
sid: resolved (fixed in 5.16.14-1)
trixie: resolved (fixed in 5.16.14-1)
debian
CVE-2016-9755P3HIGHCVSS 7.8fixed in linux 4.8.15-1 (bookworm)2016
CVE-2016-9755 [HIGH] CVE-2016-9755: linux - The netfilter subsystem in the Linux kernel before 4.9 mishandles IPv6 reassembl...
The netfilter subsystem in the Linux kernel before 4.9 mishandles IPv6 reassembly, which allows local users to cause a denial of service (integer overflow, out-of-bounds write, and GPF) or possibly have unspecified other impact via a crafted application that makes socket, connect, and writev system calls, related to net/ipv6/netfilter/nf_conntrack_reasm.c and net/ipv6/n
debian
CVE-2018-11506P3HIGHCVSS 7.8fixed in linux 4.16.16-1 (bookworm)2018
CVE-2018-11506 [HIGH] CVE-2018-11506: linux - The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through ...
The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sense buffers have different sizes at the CDROM layer and the SCSI layer, as demonstrated by a CDROMREADMODE2 ioctl call.
Scope: local
bookworm: resolved
debian
CVE-2022-48748P3HIGHCVSS 7.5fixed in linux 5.16.7-1 (bookworm)2022
CVE-2022-48748 [HIGH] CVE-2022-48748: linux - In the Linux kernel, the following vulnerability has been resolved: net: bridge...
In the Linux kernel, the following vulnerability has been resolved: net: bridge: vlan: fix memory leak in __allowed_ingress When using per-vlan state, if vlan snooping and stats are disabled, untagged or priority-tagged ingress frame will go to check pvid state. If the port state is forwarding and the pvid state is not learning/forwarding, untagged or priority-tagged
debian
CVE-2016-4440P3HIGHCVSS 7.8fixed in linux 4.5.5-1 (bookworm)2016
CVE-2016-4440 [HIGH] CVE-2016-4440: linux - arch/x86/kvm/vmx.c in the Linux kernel through 4.6.3 mishandles the APICv on/off...
arch/x86/kvm/vmx.c in the Linux kernel through 4.6.3 mishandles the APICv on/off state, which allows guest OS users to obtain direct APIC MSR access on the host OS, and consequently cause a denial of service (host OS crash) or possibly execute arbitrary code on the host OS, via x2APIC mode.
Scope: local
bookworm: resolved (fixed in 4.5.5-1)
bullseye: resolved (fixed in
debian