cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 137 of 632
CVE-2023-3106P3MEDIUMCVSS 6.6fixed in linux 4.8.5-1 (bookworm)2023
CVE-2023-3106 [MEDIUM] CVE-2023-3106: linux - A NULL pointer dereference vulnerability was found in netlink_dump. This issue c... A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause a denial of service or possibly another unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully rul
debian
CVE-2019-19071P4HIGHCVSS 7.5fixed in linux 5.4.6-1 (bookworm)2019
CVE-2019-19071 [HIGH] CVE-2019-19071: linux - A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_... A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c. Scope: local bookworm: resolved (fixed in 5.4.6-1) bullseye: resolved (fixed in 5.4.6-1) forky: resolved (fixe
debian
CVE-2021-47267P3MEDIUMCVSS 6.3fixed in linux 5.10.46-1 (bookworm)2021
CVE-2021-47267 [MEDIUM] CVE-2021-47267: linux - In the Linux kernel, the following vulnerability has been resolved: usb: fix va... In the Linux kernel, the following vulnerability has been resolved: usb: fix various gadget panics on 10gbps cabling usb_assign_descriptors() is called with 5 parameters, the last 4 of which are the usb_descriptor_header for: full-speed (USB1.1 - 12Mbps [including USB1.0 low-speed @ 1.5Mbps), high-speed (USB2.0 - 480Mbps), super-speed (USB3.0 - 5Gbps), super-speed-p
debian
CVE-2019-16995P4HIGHCVSS 7.5fixed in linux 4.19.37-1 (bookworm)2019
CVE-2019-16995 [HIGH] CVE-2019-16995: linux - In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in n... In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d. Scope: local bookworm: resolved (fixed in 4.19.37-1) bullseye: resolved (fixed in 4.19.37-1) forky: resolved (fixed in 4.19.37-1) sid: resolved (fixed in 4.19.37-1) trixie: res
debian
CVE-2012-6638P4HIGHCVSS 7.5fixed in linux 3.2.29-1 (bookworm)2012
CVE-2012-6638 [HIGH] CVE-2012-6638: linux - The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel b... The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to cause a denial of service (kernel resource consumption) via a flood of SYN+FIN TCP packets, a different vulnerability than CVE-2012-2663. Scope: local bookworm: resolved (fixed in 3.2.29-1) bullseye: resolved (fixed in 3.2.29-1) forky: resolved (fixed
debian
CVE-2020-26147P4MEDIUMCVSS 5.4fixed in linux 5.10.46-1 (bookworm)2020
CVE-2020-26147 [MEDIUM] CVE-2020-26147: linux - An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 ... An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Scop
debian
CVE-2014-7825P4HIGHCVSS 7.8fixed in linux 3.16.7-ckt2-1 (bookworm)2014
CVE-2014-7825 [HIGH] CVE-2014-7825: linux - kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not proper... kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the perf subsystem, which allows local users to cause a denial of service (out-of-bounds read and OOPS) or bypass the ASLR protection mechanism via a crafted application. Scope: local bookworm: resolved (fixed in 3.16.7-ckt2-1) bullseye: resolv
debian
CVE-2018-6555P4HIGHCVSS 7.8fixed in linux 4.17.3-1 (bookworm)2018
CVE-2018-6555 [HIGH] CVE-2018-6555: linux - The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/... The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (ias_object use-after-free and system crash) or possibly have unspecified other impact via an AF_IRDA socket. Scope: local bookworm: resolved (fixed in 4.17.3-1) bullseye: resolved (fixed in 4.
debian
CVE-2016-4794P4HIGHCVSS 7.8fixed in linux 4.6.2-2 (bookworm)2016
CVE-2016-4794 [HIGH] CVE-2016-4794: linux - Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allo... Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allows local users to cause a denial of service (BUG) or possibly have unspecified other impact via crafted use of the mmap and bpf system calls. Scope: local bookworm: resolved (fixed in 4.6.2-2) bullseye: resolved (fixed in 4.6.2-2) forky: resolved (fixed in 4.6.2-2) sid: resolved (fixed in 4.
debian
CVE-2016-4565P4HIGHCVSS 7.8fixed in linux 4.5.3-1 (bookworm)2016
CVE-2016-4565 [HIGH] CVE-2016-4565: linux - The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relie... The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface. Scope: local bookworm: resolved (fixed in 4.5.3-1) bullseye: resolved (fixed in 4.5.3-1) forky: resolved (fixed in
debian
CVE-2016-5828P4HIGHCVSS 7.8fixed in linux 4.6.3-1 (bookworm)2016
CVE-2016-5828 [HIGH] CVE-2016-5828: linux - The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel t... The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system
debian
CVE-2017-6347P4HIGHCVSS 7.8fixed in linux 4.9.13-1 (bookworm)2017
CVE-2017-6347 [HIGH] CVE-2017-6347: linux - The ip_cmsg_recv_checksum function in net/ipv4/ip_sockglue.c in the Linux kernel... The ip_cmsg_recv_checksum function in net/ipv4/ip_sockglue.c in the Linux kernel before 4.10.1 has incorrect expectations about skb data layout, which allows local users to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted system calls, as demonstrated by use of the MSG_MORE flag in conjunction with loopback UDP transmiss
debian
CVE-2018-10675P3HIGHCVSS 7.8fixed in linux 4.12.12-1 (bookworm)2018
CVE-2018-10675 [HIGH] CVE-2018-10675: linux - The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.... The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls. Scope: local bookworm: resolved (fixed in 4.12.12-1) bullseye: resolved (fixed in 4.12.12-1) forky: resolved (fixed in 4.12.12-1) sid: resolved (fixed in 4
debian
CVE-2017-7187P4HIGHCVSS 7.8fixed in linux 4.9.18-1 (bookworm)2017
CVE-2017-7187 [HIGH] CVE-2017-7187: linux - The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel through 4.10.4 al... The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel through 4.10.4 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a large command size in an SG_NEXT_CMD_LEN ioctl call, leading to out-of-bounds write access in the sg_write function. Scope: local bookworm: resolved (fixed in 4.9.18-1)
debian
CVE-2022-28893P3HIGHCVSS 7.8fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-28893 [HIGH] CVE-2022-28893: linux - The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free be... The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state. Scope: local bookworm: resolved (fixed in 5.17.3-1) bullseye: resolved (fixed in 5.10.120-1) forky: resolved (fixed in 5.17.3-1) sid: resolved (fixed in 5.17.3-1) trixie: resolved (fixed in 5.17.3-1)
debian
CVE-2016-9083P4HIGHCVSS 7.8fixed in linux 4.8.11-1 (bookworm)2016
CVE-2016-9083 [HIGH] CVE-2016-9083: linux - drivers/vfio/pci/vfio_pci.c in the Linux kernel through 4.8.11 allows local user... drivers/vfio/pci/vfio_pci.c in the Linux kernel through 4.8.11 allows local users to bypass integer overflow checks, and cause a denial of service (memory corruption) or have unspecified other impact, by leveraging access to a vfio PCI device file for a VFIO_DEVICE_SET_IRQS ioctl call, aka a "state machine confusion bug." Scope: local bookworm: resolved (fixed in 4.8.11
debian
CVE-2017-18218P4HIGHCVSS 7.8fixed in linux 4.13.4-1 (bookworm)2017
CVE-2017-18218 [HIGH] CVE-2017-18218: linux - In drivers/net/ethernet/hisilicon/hns/hns_enet.c in the Linux kernel before 4.13... In drivers/net/ethernet/hisilicon/hns/hns_enet.c in the Linux kernel before 4.13, local users can cause a denial of service (use-after-free and BUG) or possibly have unspecified other impact by leveraging differences in skb handling between hns_nic_net_xmit_hw and hns_nic_net_xmit. Scope: local bookworm: resolved (fixed in 4.13.4-1) bullseye: resolved (fixed in 4.13.4
debian
CVE-2016-9806P4HIGHCVSS 7.8fixed in linux 4.6.3-1 (bookworm)2016
CVE-2016-9806 [HIGH] CVE-2016-9806: linux - Race condition in the netlink_dump function in net/netlink/af_netlink.c in the L... Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that makes sendmsg system calls, leading to a free operation associated with a new dump that started earlier than anticipated. Scope: loc
debian
CVE-2016-8399P4HIGHCVSS 7.0fixed in linux 4.8.15-1 (bookworm)2016
CVE-2016-8399 [HIGH] CVE-2016-8399: linux - An elevation of privilege vulnerability in the kernel networking subsystem could... An elevation of privilege vulnerability in the kernel networking subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and current compiler optimizations restrict access to the vulnerable code. Product: Android. Versions:
debian
CVE-2012-6689P3HIGHCVSS 7.8fixed in linux 3.6.4-1 (bookworm)2012
CVE-2012-6689 [HIGH] CVE-2012-6689: linux - The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel bef... The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages. Scope: local bookworm: resolved (fixed in 3.6.4-1) bullseye: resolved (fixed in 3.6.4-1) forky: resolved (fixed in 3.6.4-1) sid: resolved (fixed in 3.6.4-1) tri
debian
Debian Linux vulnerabilities | cvebase