Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 15 of 632
CVE-2024-0646P3HIGHCVSS 7.0fixed in linux 6.1.69-1 (bookworm)2024
CVE-2024-0646 [HIGH] CVE-2024-0646: linux - An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Lay...
An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Scope: local
bookworm: resolved (fixed in 6.1.69-1)
bullseye: resolved (fixed in 5.10.209-1)
f
debian
CVE-2019-3900P3HIGHCVSS 7.7fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-3900 [HIGH] CVE-2019-3900: linux - An infinite loop issue was found in the vhost_net kernel module in Linux Kernel ...
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario.
Scope: loca
debian
CVE-2021-4154P3HIGHCVSS 8.8fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-4154 [HIGH] CVE-2021-4154: linux - A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v...
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullse
debian
CVE-2019-9506P3HIGHCVSS 8.1fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-9506 [HIGH] CVE-2019-9506: linux - The Bluetooth BR/EDR specification up to and including version 5.1 permits suffi...
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
Scope: local
bookworm: resolved (fixed
debian
CVE-2025-22041P3HIGHCVSS 8.8fixed in linux 6.1.135-1 (bookworm)2025
CVE-2025-22041 [HIGH] CVE-2025-22041: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_sessions_deregister() In multichannel mode, UAF issue can occur in session_deregister when the second channel sets up a session through the connection of the first channel. session that is freed through the global session table can be accessed again through ->session
debian
CVE-2012-3400P3HIGHCVSS 7.6fixed in linux 3.2.23-1 (bookworm)2012
CVE-2012-3400 [HIGH] CVE-2012-3400: linux - Heap-based buffer overflow in the udf_load_logicalvol function in fs/udf/super.c...
Heap-based buffer overflow in the udf_load_logicalvol function in fs/udf/super.c in the Linux kernel before 3.4.5 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted UDF filesystem.
Scope: local
bookworm: resolved (fixed in 3.2.23-1)
bullseye: resolved (fixed in 3.2.23-1)
forky: resolved (fixed in 3
debian
CVE-2023-0179P3HIGHCVSS 7.8fixed in linux 6.1.7-1 (bookworm)2023
CVE-2023-0179 [HIGH] CVE-2023-0179: linux - A buffer overflow vulnerability was found in the Netfilter subsystem in the Linu...
A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 6.1.7-1)
bullseye: resolved (fixed in 5.10.162-1)
forky: resolved (fixed in
debian
CVE-2014-3687P3HIGHCVSS 7.5fixed in linux 3.16.7-1 (bookworm)2014
CVE-2014-3687 [HIGH] CVE-2014-3687: linux - The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP im...
The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.
Scope: local
bookworm: resolved (fixed in 3.16.7-1)
bullseye: resolved (fixed in 3.16.
debian
CVE-2020-25645P3HIGHCVSS 7.5fixed in linux 5.8.14-1 (bookworm)2020
CVE-2020-25645 [HIGH] CVE-2020-25645: linux - A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between...
A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
Scope: loc
debian
CVE-2021-42008P3HIGHCVSS 7.8fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-42008 [HIGH] CVE-2021-42008: linux - The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel bef...
The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
debian
CVE-2023-39191P3LOWCVSS 8.2fixed in linux 6.3.7-1 (forky)2023
CVE-2023-39191 [HIGH] CVE-2023-39191: linux - An improper input validation flaw was found in the eBPF subsystem in the Linux k...
An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code in the context of the kernel.
Scope: local
bookwor
debian
CVE-2023-3390P3HIGHCVSS 7.8fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-3390 [HIGH] CVE-2023-3390: linux - A use-after-free vulnerability was found in the Linux kernel's netfilter subsyst...
A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user access to cause a privilege escalation issue. We recomme
debian
CVE-2023-3389P3HIGHCVSS 7.8fixed in linux 6.0.2-1 (bookworm)2023
CVE-2023-3389 [HIGH] CVE-2023-3389: linux - A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exp...
A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Racing a io_uring cancel poll request with a linked timeout can cause a UAF in a hrtimer. We recommend upgrading past commit ef7dfac51d8ed961b742218f526bd589f3900a59 (4716c73b188566865bdd79c3a6709696a224ac04 for 5.10 stable and 0e388fce7aec40992e
debian
CVE-2023-3090P3HIGHCVSS 7.8fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-3090 [HIGH] CVE-2023-3090: linux - A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driv...
A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled. We recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e
debian
CVE-2017-14489P4MEDIUMCVSS 5.5PoCfixed in linux 4.12.13-1 (bookworm)2017
CVE-2017-14489 [MEDIUM] CVE-2017-14489: linux - The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux ker...
The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of service (panic) by leveraging incorrect length validation.
Scope: local
bookworm: resolved (fixed in 4.12.13-1)
bullseye: resolved (fixed in 4.12.13-1)
forky: resolved (fixed in 4.12.13-1)
sid: resolved (fixed in 4.12.13-1)
trixi
debian
CVE-2023-39179P3HIGHCVSS 7.5fixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-39179 [HIGH] CVE-2023-39179: linux - A flaw was found within the handling of SMB2 read requests in the kernel ksmbd m...
A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnera
debian
CVE-2023-2007P3HIGHCVSS 7.8fixed in linux 6.0.2-1 (bookworm)2023
CVE-2023-2007 [HIGH] CVE-2023-2007: linux - The specific flaw exists within the DPT I2O Controller driver. The issue results...
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.
Scope: local
bookworm: resolved (fixed in 6.0.2-1)
bullseye: resol
debian
CVE-2026-23268P3HIGHCVSS 7.8fixed in linux 6.1.164-1 (bookworm)2026
CVE-2026-23268 [HIGH] CVE-2026-23268: linux - In the Linux kernel, the following vulnerability has been resolved: apparmor: f...
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix unprivileged local user can do privileged policy management An unprivileged local user can load, replace, and remove profiles by opening the apparmorfs interfaces, via a confused deputy attack, by passing the opened fd to a privileged process, and getting the privileged process to write
debian
CVE-2024-38612P3CRITICALCVSS 9.8fixed in linux 6.1.94-1 (bookworm)2024
CVE-2024-38612 [CRITICAL] CVE-2024-38612: linux - In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: f...
In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defined. In that case if seg6_hmac_init() fails, the genl_unregister_family() isn't called. This issue exist since commit 46738b1317e1 ("ipv6: sr: add option to control lwtun
debian
CVE-2026-22998P3HIGHCVSS 7.5fixed in linux 6.1.162-1 (bookworm)2026
CVE-2026-22998 [HIGH] CVE-2026-22998: linux - In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: f...
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec Commit efa56305908b ("nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length") added ttag bounds checking and data_offset validation in nvmet_tcp_handle_h2c_data_pdu(), but it did not validate whether the command's d
debian