Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 141 of 632
CVE-2018-6927P4HIGHCVSS 7.8fixed in linux 4.14.17-1 (bookworm)2018
CVE-2018-6927 [HIGH] CVE-2018-6927: linux - The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 ...
The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact by triggering a negative wake or requeue value.
Scope: local
bookworm: resolved (fixed in 4.14.17-1)
bullseye: resolved (fixed in 4.14.17-1)
forky: resolved (fixed in 4.14.17-1)
si
debian
CVE-2017-14497P4HIGHCVSS 7.8fixed in linux 4.12.13-1 (bookworm)2017
CVE-2017-14497 [HIGH] CVE-2017-14497: linux - The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4....
The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of service (buffer overflow, and disk and memory corruption) or possibly have unspecified other impact via crafted system calls.
Scope: local
bookworm: resolved (fixed in 4.12.13-1)
bullseye: resolved (fixed in 4.1
debian
CVE-2015-8830P4HIGHCVSS 7.8fixed in linux 4.1.3-1 (bookworm)2015
CVE-2015-8830 [HIGH] CVE-2015-8830: linux - Integer overflow in the aio_setup_single_vector function in fs/aio.c in the Linu...
Integer overflow in the aio_setup_single_vector function in fs/aio.c in the Linux kernel 4.0 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec. NOTE: this vulnerability exists because of a CVE-2012-6701 regression.
Scope: local
bookworm: resolved (fixed in 4.1.3-1)
bullseye: resolved (fixed in 4.1.3-1)
forky:
debian
CVE-2017-8068P4HIGHCVSS 7.8fixed in linux 4.9.10-1 (bookworm)2017
CVE-2017-8068 [HIGH] CVE-2017-8068: linux - drivers/net/usb/pegasus.c in the Linux kernel 4.9.x before 4.9.11 interacts inco...
drivers/net/usb/pegasus.c in the Linux kernel 4.9.x before 4.9.11 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.
Scope: local
bookworm: resolved (fixed in 4.9.
debian
CVE-2017-8240P4HIGHCVSS 7.8fixed in linux 4.0.2-1 (bookworm)2017
CVE-2017-8240 [HIGH] CVE-2017-8240: linux - In all Android releases from CAF using the Linux kernel, a kernel driver has an ...
In all Android releases from CAF using the Linux kernel, a kernel driver has an off-by-one buffer over-read vulnerability.
Scope: local
bookworm: resolved (fixed in 4.0.2-1)
bullseye: resolved (fixed in 4.0.2-1)
forky: resolved (fixed in 4.0.2-1)
sid: resolved (fixed in 4.0.2-1)
trixie: resolved (fixed in 4.0.2-1)
debian
CVE-2016-5829P4HIGHCVSS 7.8fixed in linux 4.6.3-1 (bookworm)2016
CVE-2016-5829 [HIGH] CVE-2016-5829: linux - Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drive...
Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call.
Scope: local
bookworm: resolved (fixed in 4.6.3-1)
bullseye: resolved (fixed in 4
debian
CVE-2017-5548P4HIGHCVSS 7.8fixed in linux 4.9.6-1 (bookworm)2017
CVE-2017-5548 [HIGH] CVE-2017-5548: linux - drivers/net/ieee802154/atusb.c in the Linux kernel 4.9.x before 4.9.6 interacts ...
drivers/net/ieee802154/atusb.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2017-8070P4HIGHCVSS 7.8fixed in linux 4.9.13-1 (bookworm)2017
CVE-2017-8070 [HIGH] CVE-2017-8070: linux - drivers/net/usb/catc.c in the Linux kernel 4.9.x before 4.9.11 interacts incorre...
drivers/net/usb/catc.c in the Linux kernel 4.9.x before 4.9.11 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.
Scope: local
bookworm: resolved (fixed in 4.9.13-
debian
CVE-2017-5547P4HIGHCVSS 7.8fixed in linux 4.9.6-1 (bookworm)2017
CVE-2017-5547 [HIGH] CVE-2017-5547: linux - drivers/hid/hid-corsair.c in the Linux kernel 4.9.x before 4.9.6 interacts incor...
drivers/hid/hid-corsair.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.
Scope: local
bookworm: resolved (fixed in 4.9.6
debian
CVE-2017-8069P4HIGHCVSS 7.8fixed in linux 4.9.13-1 (bookworm)2017
CVE-2017-8069 [HIGH] CVE-2017-8069: linux - drivers/net/usb/rtl8150.c in the Linux kernel 4.9.x before 4.9.11 interacts inco...
drivers/net/usb/rtl8150.c in the Linux kernel 4.9.x before 4.9.11 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.
Scope: local
bookworm: resolved (fixed in 4.9.
debian
CVE-2012-6704P4HIGHCVSS 7.8fixed in linux 3.8.11-1 (bookworm)2012
CVE-2012-6704 [HIGH] CVE-2012-6704: linux - The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5 m...
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability for a crafted setsockopt system call with the (1) SO_SNDBUF or
debian
CVE-2017-2647P4HIGHCVSS 7.8fixed in linux 4.0.2-1 (bookworm)2017
CVE-2017-2647 [HIGH] CVE-2017-2647: linux - The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain pr...
The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyring.c.
Scope: local
bookworm: resolved (fixed in 4.0.2-1)
bullseye: resolved (fixed in 4.0.2-
debian
CVE-2017-8072P4HIGHCVSS 7.8fixed in linux 4.9.10-1 (bookworm)2017
CVE-2017-8072 [HIGH] CVE-2017-8072: linux - The cp2112_gpio_direction_input function in drivers/hid/hid-cp2112.c in the Linu...
The cp2112_gpio_direction_input function in drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 does not have the expected EIO error status for a zero-length report, which allows local users to have an unspecified impact via unknown vectors.
Scope: local
bookworm: resolved (fixed in 4.9.10-1)
bullseye: resolved (fixed in 4.9.10-1)
forky: resolved (fixed in 4
debian
CVE-2017-8067P4HIGHCVSS 7.8fixed in linux 4.9.25-1 (bookworm)2017
CVE-2017-8067 [HIGH] CVE-2017-8067: linux - drivers/char/virtio_console.c in the Linux kernel 4.9.x and 4.10.x before 4.10.1...
drivers/char/virtio_console.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.
Scope: local
bookworm: resolve
debian
CVE-2017-7487P4HIGHCVSS 7.8fixed in linux 4.9.30-1 (bookworm)2017
CVE-2017-7487 [HIGH] CVE-2017-7487: linux - The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1...
The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a failed SIOCGIFADDR ioctl call for an IPX interface.
Scope: local
bookworm: resolved (fixed in 4.9.30-1)
bullseye: resolved (fixed in 4.9.30-1)
debian
CVE-2023-6932P4HIGHCVSS 7.8fixed in linux 6.1.66-1 (bookworm)2023
CVE-2023-6932 [HIGH] CVE-2023-6932: linux - A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be...
A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread. We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.
Scope: local
bookworm: reso
debian
CVE-2018-5344P4HIGHCVSS 7.8fixed in linux 4.14.17-1 (bookworm)2018
CVE-2018-5344 [HIGH] CVE-2018-5344: linux - In the Linux kernel through 4.14.13, drivers/block/loop.c mishandles lo_release ...
In the Linux kernel through 4.14.13, drivers/block/loop.c mishandles lo_release serialization, which allows attackers to cause a denial of service (__lock_acquire use-after-free) or possibly have unspecified other impact.
Scope: local
bookworm: resolved (fixed in 4.14.17-1)
bullseye: resolved (fixed in 4.14.17-1)
forky: resolved (fixed in 4.14.17-1)
sid: resolved (fixed
debian
CVE-2017-8064P4HIGHCVSS 7.8fixed in linux 4.9.25-1 (bookworm)2017
CVE-2017-8064 [HIGH] CVE-2017-8064: linux - drivers/media/usb/dvb-usb-v2/dvb_usb_core.c in the Linux kernel 4.9.x and 4.10.x...
drivers/media/usb/dvb-usb-v2/dvb_usb_core.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.
Scope: local
boo
debian
CVE-2025-21702P4HIGHCVSS 7.8fixed in linux 6.1.133-1 (bookworm)2025
CVE-2025-21702 [HIGH] CVE-2025-21702: linux - In the Linux kernel, the following vulnerability has been resolved: pfifo_tail_...
In the Linux kernel, the following vulnerability has been resolved: pfifo_tail_enqueue: Drop new packet when sch->limit == 0 Expected behaviour: In case we reach scheduler's limit, pfifo_tail_enqueue() will drop a packet in scheduler's queue and decrease scheduler's qlen by one. Then, pfifo_tail_enqueue() enqueue new packet and increase scheduler's qlen by one. Finall
debian
CVE-2018-1066P4MEDIUMCVSS 6.5fixed in linux 4.11.6-1 (bookworm)2018
CVE-2018-1066 [MEDIUM] CVE-2018-1066: linux - The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference...
The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker controlling a CIFS server to kernel panic a client that has this server mounted, because an empty TargetInfo field in an NTLMSSP setup negotiation response is mishandled during session recovery.
Scope: local
bookworm: res
debian