Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 142 of 632
CVE-2018-10938P4LOWCVSS 5.9fixed in linux 4.13.4-1 (bookworm)2018
CVE-2018-10938 [MEDIUM] CVE-2018-10938: linux - A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc...
A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a denial-of-service. A certain non-default configuration of LSM (Linux Security Module) and NetLabel should be set
debian
CVE-2022-48778P4HIGHCVSS 7.8fixed in linux 5.16.11-1 (bookworm)2022
CVE-2022-48778 [HIGH] CVE-2022-48778: linux - In the Linux kernel, the following vulnerability has been resolved: mtd: rawnan...
In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: gpmi: don't leak PM reference in error path If gpmi_nfc_apply_timings() fails, the PM runtime usage counter must be dropped.
Scope: local
bookworm: resolved (fixed in 5.16.11-1)
bullseye: resolved (fixed in 5.10.103-1)
forky: resolved (fixed in 5.16.11-1)
sid: resolved (fixed in 5.16.11-
debian
CVE-2023-4244P4HIGHCVSS 7.8fixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-4244 [HIGH] CVE-2023-4244: linux - A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables compon...
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set element garbage collection, it is possible to underflow the reference counter causing a use-after-free vulnerability. We recommend upgrading pas
debian
CVE-2023-1295P4HIGHCVSS 7.8fixed in linux 5.14.6-1 (bookworm)2023
CVE-2023-1295 [HIGH] CVE-2023-1295: linux - A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CL...
A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1
debian
CVE-2024-36955P4HIGHCVSS 7.7fixed in linux 6.1.94-1 (bookworm)2024
CVE-2024-36955 [HIGH] CVE-2024-36955: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: ...
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: intel-sdw-acpi: fix usage of device_get_named_child_node() The documentation for device_get_named_child_node() mentions this important point: " The caller is responsible for calling fwnode_handle_put() on the returned fwnode pointer. " Add fwnode_handle_put() to avoid a leaked reference.
Sc
debian
CVE-2023-52883P4LOWCVSS 7.5fixed in linux 6.5.10-1 (forky)2023
CVE-2023-52883 [HIGH] CVE-2023-52883: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu:...
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix possible null pointer dereference abo->tbo.resource may be NULL in amdgpu_vm_bo_update.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.5.10-1)
sid: resolved (fixed in 6.5.10-1)
trixie: resolved (fixed in 6.5.10-1)
debian
CVE-2021-26708P4HIGHCVSS 7.0fixed in linux 5.10.13-1 (bookworm)2021
CVE-2021-26708 [HIGH] CVE-2021-26708: linux - A local privilege escalation was discovered in the Linux kernel before 5.10.13. ...
A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits that added VSOCK multi-transport support.
Scope: local
bookworm: resolved (fixed in 5.10.13-1)
bullseye: resolved (
debian
CVE-2020-12654P4HIGHCVSS 7.1fixed in linux 5.5.13-1 (bookworm)2020
CVE-2020-12654 [HIGH] CVE-2020-12654: linux - An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in...
An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wmm.c allows a remote AP to trigger a heap-based buffer overflow because of an incorrect memcpy, aka CID-3a9b153c5591.
Scope: local
bookworm: resolved (fixed in 5.5.13-1)
bullseye: resolved (fixed in 5.5.13-1)
forky: resolved (fixed in 5.5.13-1)
sid: r
debian
CVE-2016-3841P4HIGHCVSS 7.3fixed in linux 4.3.3-1 (bookworm)2016
CVE-2016-3841 [HIGH] CVE-2016-3841: linux - The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which a...
The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
Scope: local
bookworm: resolved (fixed in 4.3.3-1)
bullseye: resolved (fixed in 4.3.3-1)
forky: resolved (fixed in 4.3.3-1)
sid: resolved (fixed in 4.3.3-1)
debian
CVE-2019-18683P3HIGHCVSS 7.0fixed in linux 5.3.15-1 (bookworm)2019
CVE-2019-18683 [HIGH] CVE-2019-18683: linux - An issue was discovered in drivers/media/platform/vivid in the Linux kernel thro...
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this driver (part of the V4L2 subsystem). These issues a
debian
CVE-2023-2002P4MEDIUMCVSS 6.8fixed in linux 6.1.27-1 (bookworm)2023
CVE-2023-2002 [MEDIUM] CVE-2023-2002: linux - A vulnerability was found in the HCI sockets implementation due to a missing cap...
A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication.
Scope: local
bookworm: resolved (fixed in 6.1.27-1)
bullse
debian
CVE-2025-40087P3UNKNOWNfixed in linux 6.1.158-1 (bookworm)2025
CVE-2025-40087 CVE-2025-40087: linux - In the Linux kernel, the following vulnerability has been resolved: NFSD: Defin...
In the Linux kernel, the following vulnerability has been resolved: NFSD: Define a proc_layoutcommit for the FlexFiles layout type Avoid a crash if a pNFS client should happen to send a LAYOUTCOMMIT operation on a FlexFiles layout.
Scope: local
bookworm: resolved (fixed in 6.1.158-1)
bullseye: resolved (fixed in 5.10.247-1)
forky: resolved (fixed in 6.17.6-1)
sid: resolved (
debian
CVE-2025-22039P4HIGHCVSS 7.1fixed in linux 6.12.25-1 (forky)2025
CVE-2025-22039 [HIGH] CVE-2025-22039: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The dacloffset field was originally typed as int and used in an unchecked addition, which could overflow and bypass the existing bounds check in both smb_check_perm_dacl() and smb_inherit_dacl(). This could result in out-of-bounds memory access and a kern
debian
CVE-2025-40285P3UNKNOWNfixed in linux 6.1.159-1 (bookworm)2025
CVE-2025-40285 CVE-2025-40285: linux - In the Linux kernel, the following vulnerability has been resolved: smb/server:...
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess_setup() Reference count of ksmbd_session will leak when session need reconnect. Fix this by adding the missing ksmbd_user_session_put().
Scope: local
bookworm: resolved (fixed in 6.1.159-1)
bullseye: resolved
forky: resolved (fixed in 6.17.9-1)
sid: resolve
debian
CVE-2026-23453P3LOWfixed in linux 6.19.10-1 (forky)2026
CVE-2026-23453 [LOW] CVE-2026-23453: linux - In the Linux kernel, the following vulnerability has been resolved: net: ti: ic...
In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: Fix memory leak in XDP_DROP for non-zero-copy mode Page recycling was removed from the XDP_DROP path in emac_run_xdp() to avoid conflicts with AF_XDP zero-copy mode, which uses xsk_buff_free() instead. However, this causes a memory leak when running XDP programs that drop packets
debian
CVE-2022-29582P4HIGHCVSS 7.0fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-29582 [HIGH] CVE-2022-29582: linux - In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a r...
In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.
Scope: local
bookworm: resolved (fixed in 5.17.3-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: res
debian
CVE-2023-3567P4HIGHCVSS 7.1fixed in linux 6.1.11-1 (bookworm)2023
CVE-2023-3567 [HIGH] CVE-2023-3567: linux - A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_...
A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information.
Scope: local
bookworm: resolved (fixed in 6.1.11-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.11-1)
sid: resolved (fix
debian
CVE-2026-31406P3LOWfixed in linux 6.19.11-1 (sid)2026
CVE-2026-31406 [LOW] CVE-2026-31406: linux - In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix w...
In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini() After cancel_delayed_work_sync() is called from xfrm_nat_keepalive_net_fini(), xfrm_state_fini() flushes remaining states via __xfrm_state_delete(), which calls xfrm_nat_keepalive_state_updated() to re-schedule nat_keepalive_work.
debian
CVE-2025-40067P3LOWfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40067 [LOW] CVE-2025-40067: linux - In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: r...
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject index allocation if $BITMAP is empty but blocks exist Index allocation requires at least one bit in the $BITMAP attribute to track usage of index entries. If the bitmap is empty while index blocks are already present, this reflects on-disk corruption. syzbot triggered this condition us
debian
CVE-2025-40051P3UNKNOWNfixed in linux 6.1.158-1 (bookworm)2025
CVE-2025-40051 CVE-2025-40051: linux - In the Linux kernel, the following vulnerability has been resolved: vhost: vrin...
In the Linux kernel, the following vulnerability has been resolved: vhost: vringh: Modify the return value check The return value of copy_from_iter and copy_to_iter can't be negative, check whether the copied lengths are equal.
Scope: local
bookworm: resolved (fixed in 6.1.158-1)
bullseye: resolved
forky: resolved (fixed in 6.17.6-1)
sid: resolved (fixed in 6.17.6-1)
trixie:
debian