cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 145 of 632
CVE-2019-12881P4HIGHCVSS 7.8fixed in linux 4.18.6-1 (bookworm)2019
CVE-2019-12881 [HIGH] CVE-2019-12881: linux - i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Lin... i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) or possibly have unspecified other impact via crafted ioctl calls to /dev/dri/card0. Scope: local bookworm: resolved (fixed in 4.18.6-1) bullseye: resolved (fixed in 4.18.6
debian
CVE-2021-47295P4HIGHCVSS 7.5fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-47295 [HIGH] CVE-2021-47295: linux - In the Linux kernel, the following vulnerability has been resolved: net: sched:... In the Linux kernel, the following vulnerability has been resolved: net: sched: fix memory leak in tcindex_partial_destroy_work Syzbot reported memory leak in tcindex_set_parms(). The problem was in non-freed perfect hash in tcindex_partial_destroy_work(). In tcindex_set_parms() new tcindex_data is allocated and some fields from old one are copied to new one, but not
debian
CVE-2016-4951P4HIGHCVSS 7.8fixed in linux 4.5.5-1 (bookworm)2016
CVE-2016-4951 [HIGH] CVE-2016-4951: linux - The tipc_nl_publ_dump function in net/tipc/socket.c in the Linux kernel through ... The tipc_nl_publ_dump function in net/tipc/socket.c in the Linux kernel through 4.6 does not verify socket existence, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a dumpit operation. Scope: local bookworm: resolved (fixed in 4.5.5-1) bullseye: resolved (fixed in 4.5.5-1) f
debian
CVE-2016-10153P4HIGHCVSS 7.8fixed in linux 4.9.6-1 (bookworm)2016
CVE-2016-10153 [HIGH] CVE-2016-10153: linux - The crypto scatterlist API in the Linux kernel 4.9.x before 4.9.6 interacts inco... The crypto scatterlist API in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging reliance on earlier net/ceph/crypto.c code. Scope: local bookworm: resolved (fixed in 4.9.6-1) bullse
debian
CVE-2017-8066P4HIGHCVSS 7.8fixed in linux 4.9.16-1 (bookworm)2017
CVE-2017-8066 [HIGH] CVE-2017-8066: linux - drivers/net/can/usb/gs_usb.c in the Linux kernel 4.9.x and 4.10.x before 4.10.2 ... drivers/net/can/usb/gs_usb.c in the Linux kernel 4.9.x and 4.10.x before 4.10.2 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist. Scope: local bookworm: resolved
debian
CVE-2017-8061P4HIGHCVSS 7.8fixed in linux 4.9.25-1 (bookworm)2017
CVE-2017-8061 [HIGH] CVE-2017-8061: linux - drivers/media/usb/dvb-usb/dvb-usb-firmware.c in the Linux kernel 4.9.x and 4.10.... drivers/media/usb/dvb-usb/dvb-usb-firmware.c in the Linux kernel 4.9.x and 4.10.x before 4.10.7 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist. Scope: local boo
debian
CVE-2017-5576P4HIGHCVSS 7.8fixed in linux 4.9.6-1 (bookworm)2017
CVE-2017-5576 [HIGH] CVE-2017-5576: linux - Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in... Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted size value in a VC4_SUBMIT_CL ioctl call. Scope: local bookworm: resolved (fixed in 4.9.6-1) bullseye: resolved (fixed in 4.9.6-1
debian
CVE-2017-9074P4HIGHCVSS 7.8fixed in linux 4.9.30-1 (bookworm)2017
CVE-2017-9074 [HIGH] CVE-2017-9074: linux - The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does no... The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact via crafted socket and send system calls. Scope: local bookworm: resolved (fixed in 4.9.30-
debian
CVE-2017-17855P4HIGHCVSS 7.8fixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-17855 [HIGH] CVE-2017-17855: linux - kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to c... kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging improper use of pointers in place of scalars. Scope: local bookworm: resolved (fixed in 4.14.7-1) bullseye: resolved (fixed in 4.14.7-1) forky: resolved (fixed in 4.14.7-1) sid: resolved (f
debian
CVE-2017-15951P4HIGHCVSS 7.8fixed in linux 4.13.10-1 (bookworm)2017
CVE-2017-15951 [HIGH] CVE-2017-15951: linux - The KEYS subsystem in the Linux kernel before 4.13.10 does not correctly synchro... The KEYS subsystem in the Linux kernel before 4.13.10 does not correctly synchronize the actions of updating versus finding a key in the "negative" state to avoid a race condition, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls. Scope: local bookworm: resolved (fixed in 4.13.10-1) bullseye: reso
debian
CVE-2017-8062P4HIGHCVSS 7.8fixed in linux 4.9.16-1 (bookworm)2017
CVE-2017-8062 [HIGH] CVE-2017-8062: linux - drivers/media/usb/dvb-usb/dw2102.c in the Linux kernel 4.9.x and 4.10.x before 4... drivers/media/usb/dvb-usb/dw2102.c in the Linux kernel 4.9.x and 4.10.x before 4.10.4 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist. Scope: local bookworm: res
debian
CVE-2017-8063P4HIGHCVSS 7.8fixed in linux 4.9.25-1 (bookworm)2017
CVE-2017-8063 [HIGH] CVE-2017-8063: linux - drivers/media/usb/dvb-usb/cxusb.c in the Linux kernel 4.9.x and 4.10.x before 4.... drivers/media/usb/dvb-usb/cxusb.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist. Scope: local bookworm: resolved (fixed in 4.9.2
debian
CVE-2017-17863P4HIGHCVSS 7.8fixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-17863 [HIGH] CVE-2017-17863: linux - kernel/bpf/verifier.c in the Linux kernel 4.9.x through 4.9.71 does not check th... kernel/bpf/verifier.c in the Linux kernel 4.9.x through 4.9.71 does not check the relationship between pointer values and the BPF stack, which allows local users to cause a denial of service (integer overflow or invalid memory access) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 4.14.7-1) bullseye: resolved (fixed in 4.14.7-1) f
debian
CVE-2017-18075P4HIGHCVSS 7.8fixed in linux 4.14.13-1 (bookworm)2017
CVE-2017-18075 [HIGH] CVE-2017-18075: linux - crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances,... crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AF_ALG-based AEAD interface (CONFIG_CRYPTO_USER_API_AEAD) and pcrypt (CONFIG_CRYPTO_PCRYPT) to cause a denial of service (kfree of an incorrect pointer) or possibly have unspecified other impact by executing a crafted sequence of system calls. Scop
debian
CVE-2017-16996P4HIGHCVSS 7.8fixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-16996 [HIGH] CVE-2017-16996: linux - kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to c... kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging register truncation mishandling. Scope: local bookworm: resolved (fixed in 4.14.7-1) bullseye: resolved (fixed in 4.14.7-1) forky: resolved (fixed in 4.14.7-1) sid: resolved (fixed in 4.14.
debian
CVE-2017-17857P4HIGHCVSS 7.8fixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-17857 [HIGH] CVE-2017-17857: linux - The check_stack_boundary function in kernel/bpf/verifier.c in the Linux kernel t... The check_stack_boundary function in kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging mishandling of invalid variable stack read operations. Scope: local bookworm: resolved (fixed in 4.14.7-1) bullseye: resolved (fixed in 4.14.7-1) forky:
debian
CVE-2017-17856P4HIGHCVSS 7.8fixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-17856 [HIGH] CVE-2017-17856: linux - kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to c... kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the lack of stack-pointer alignment enforcement. Scope: local bookworm: resolved (fixed in 4.14.7-1) bullseye: resolved (fixed in 4.14.7-1) forky: resolved (fixed in 4.14.7-1) sid: resolved
debian
CVE-2017-17853P4HIGHCVSS 7.8fixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-17853 [HIGH] CVE-2017-17853: linux - kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to c... kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect BPF_RSH signed bounds calculations. Scope: local bookworm: resolved (fixed in 4.14.7-1) bullseye: resolved (fixed in 4.14.7-1) forky: resolved (fixed in 4.14.7-1) sid: resolved (f
debian
CVE-2014-9904P4HIGHCVSS 7.8fixed in linux 4.0.2-1 (bookworm)2014
CVE-2014-9904 [HIGH] CVE-2014-9904: linux - The snd_compress_check_input function in sound/core/compress_offload.c in the AL... The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call. Scope: local book
debian
CVE-2016-9084P4HIGHCVSS 7.8fixed in linux 4.8.11-1 (bookworm)2016
CVE-2016-9084 [HIGH] CVE-2016-9084: linux - drivers/vfio/pci/vfio_pci_intrs.c in the Linux kernel through 4.8.11 misuses the... drivers/vfio/pci/vfio_pci_intrs.c in the Linux kernel through 4.8.11 misuses the kzalloc function, which allows local users to cause a denial of service (integer overflow) or have unspecified other impact by leveraging access to a vfio PCI device file. Scope: local bookworm: resolved (fixed in 4.8.11-1) bullseye: resolved (fixed in 4.8.11-1) forky: resolved (fixed in 4.
debian
Debian Linux vulnerabilities | cvebase