Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 156 of 632
CVE-2020-0030P4HIGHCVSS 7.0fixed in linux 4.15.11-1 (bookworm)2020
CVE-2020-0030 [HIGH] CVE-2020-0030: linux - In binder_thread_release of binder.c, there is a possible use after free due to ...
In binder_thread_release of binder.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-145286050References: Upstream kernel
Scope: local
bookworm: resolved (fixed
debian
CVE-2015-9016P4HIGHCVSS 7.0fixed in linux 4.2.3-1 (bookworm)2015
CVE-2015-9016 [HIGH] CVE-2015-9016: linux - In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use ...
In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use after free due to a race condition when a request has been previously freed by blk_mq_complete_request. This could lead to local escalation of privilege. Product: Android. Versions: Android kernel. Android ID: A-63083046.
Scope: local
bookworm: resolved (fixed in 4.2.3-1)
bullseye: resolved
debian
CVE-2025-71203P4LOWCVSS 7.0fixed in linux 6.18.10-1 (forky)2025
CVE-2025-71203 [HIGH] CVE-2025-71203: linux - In the Linux kernel, the following vulnerability has been resolved: riscv: Sani...
In the Linux kernel, the following vulnerability has been resolved: riscv: Sanitize syscall table indexing under speculation The syscall number is a user-controlled value used to index into the syscall table. Use array_index_nospec() to clamp this value after the bounds check to prevent speculative out-of-bounds access and subsequent data leakage via cache side channe
debian
CVE-2026-23175P4LOWCVSS 7.0fixed in linux 6.18.10-1 (forky)2026
CVE-2026-23175 [HIGH] CVE-2026-23175: linux - In the Linux kernel, the following vulnerability has been resolved: net: cpsw: ...
In the Linux kernel, the following vulnerability has been resolved: net: cpsw: Execute ndo_set_rx_mode callback in a work queue Commit 1767bb2d47b7 ("ipv6: mcast: Don't hold RTNL for IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP.") removed the RTNL lock for IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP operations. However, this change triggered the following call trace on my Be
debian
CVE-2025-39759P4HIGHCVSS 7.0fixed in linux 6.1.153-1 (bookworm)2025
CVE-2025-39759 [HIGH] CVE-2025-39759: linux - In the Linux kernel, the following vulnerability has been resolved: btrfs: qgro...
In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix race between quota disable and quota rescan ioctl There's a race between a task disabling quotas and another running the rescan ioctl that can result in a use-after-free of qgroup records from the fs_info->qgroup_tree rbtree. This happens as follows: 1) Task A enters btrfs_ioctl_quo
debian
CVE-2021-20292P4MEDIUMCVSS 6.7fixed in linux 5.7.17-1 (bookworm)2021
CVE-2021-20292 [MEDIUM] CVE-2021-20292: linux - There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/g...
There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouveau_sgdma_create_ttm in Nouveau DRM subsystem. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker with a local account with a root privilege, can leverage this vulnerabil
debian
CVE-2025-71221P4HIGHCVSS 7.0fixed in linux 6.18.10-1 (forky)2025
CVE-2025-71221 [HIGH] CVE-2025-71221: linux - In the Linux kernel, the following vulnerability has been resolved: dmaengine: ...
In the Linux kernel, the following vulnerability has been resolved: dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() Add proper locking in mmp_pdma_residue() to prevent use-after-free when accessing descriptor list and descriptor contents. The race occurs when multiple threads call tx_status() while the tasklet on another CPU is freeing completed descript
debian
CVE-2021-42327P4MEDIUMCVSS 6.7fixed in linux 5.14.16-1 (bookworm)2021
CVE-2021-42327 [MEDIUM] CVE-2021-42327: linux - dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugf...
dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can write a string to the AMD GPU display drivers debug filesystem. There are no checks on size within parse_write_buffer_into_params when it uses the size of copy_from_user to copy a userspace
debian
CVE-2023-21400P4MEDIUMCVSS 6.7fixed in linux 5.18.2-1 (bookworm)2023
CVE-2023-21400 [MEDIUM] CVE-2023-21400: linux - In multiple functions of io_uring.c, there is a possible kernel memory corrupti...
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.
Scope: local
bookworm: resolved (fixed in 5.18.2-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved
debian
CVE-2024-35976P4MEDIUMCVSS 6.7fixed in linux 6.1.90-1 (bookworm)2024
CVE-2024-35976 [MEDIUM] CVE-2024-35976: linux - In the Linux kernel, the following vulnerability has been resolved: xsk: valida...
In the Linux kernel, the following vulnerability has been resolved: xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING syzbot reported an illegal copy in xsk_setsockopt() [1] Make sure to validate setsockopt() @optlen parameter. [1] BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include/linux/sockptr.h:49 [inline] BUG: KASAN: slab-out-of-bounds
debian
CVE-2013-0160P4LOWCVSS 2.1PoCfixed in linux 3.8.12-1 (bookworm)2013
CVE-2013-0160 [LOW] CVE-2013-0160: linux - The Linux kernel through 3.7.9 allows local users to obtain sensitive informatio...
The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device.
Scope: local
bookworm: resolved (fixed in 3.8.12-1)
bullseye: resolved (fixed in 3.8.12-1)
forky: resolved (fixed in 3.8.12-1)
sid: resolved (fixed in 3.8.12-1)
trixie: resolved (fixed in 3.8.12-1)
debian
CVE-2021-34981P4MEDIUMCVSS 6.7fixed in linux 5.10.46-1 (bookworm)2021
CVE-2021-34981 [MEDIUM] CVE-2021-34981: linux - Linux Kernel Bluetooth CMTP Module Double Free Privilege Escalation Vulnerabilit...
Linux Kernel Bluetooth CMTP Module Double Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the CMTP m
debian
CVE-2014-6418P4HIGHCVSS 7.1fixed in linux 3.16.3-1 (bookworm)2014
CVE-2014-6418 [HIGH] CVE-2014-6418: linux - net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not p...
net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor.
Scope: local
bookworm: resolved (fixed in 3.16.3-1)
bullseye: resolved (fixed in 3.16.3-1
debian
CVE-2024-41012P4MEDIUMCVSS 6.3fixed in linux 6.1.106-1 (bookworm)2024
CVE-2024-41012 [MEDIUM] CVE-2024-41012: linux - In the Linux kernel, the following vulnerability has been resolved: filelock: R...
In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close race is detected When fcntl_setlk() races with close(), it removes the created lock with do_lock_file_wait(). However, LSMs can allow the first do_lock_file_wait() that created the lock while denying the second do_lock_file_wait() that tries to remove
debian
CVE-2023-4273P4MEDIUMCVSS 6.0fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-4273 [MEDIUM] CVE-2023-4273: linux - A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exis...
A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a single long file name. Since the file name characters are copied into a stack variable, a lo
debian
CVE-2021-47544P4MEDIUMCVSS 5.9fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-47544 [MEDIUM] CVE-2021-47544: linux - In the Linux kernel, the following vulnerability has been resolved: tcp: fix pa...
In the Linux kernel, the following vulnerability has been resolved: tcp: fix page frag corruption on page fault Steffen reported a TCP stream corruption for HTTP requests served by the apache web-server using a cifs mount-point and memory mapping the relevant file. The root cause is quite similar to the one addressed by commit 20eb4f29b602 ("net: fix sk_page_frag()
debian
CVE-2020-36516P4MEDIUMCVSS 5.9fixed in linux 5.16.7-1 (bookworm)2020
CVE-2020-36516 [MEDIUM] CVE-2020-36516: linux - An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assi...
An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session.
Scope: local
bookworm: resolved (fixed in 5.16.7-1)
bullseye: resolved (fixed in 5.10.103-1)
forky: resolved (fixed in 5.16.7-1)
sid:
debian
CVE-2025-38562P4MEDIUMCVSS 5.5fixed in linux 6.1.148-1 (bookworm)2025
CVE-2025-38562 [MEDIUM] CVE-2025-38562: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference error in generate_encryptionkey If client send two session setups with krb5 authenticate to ksmbd, null pointer dereference error in generate_encryptionkey could happen. sess->Preauth_HashValue is set to NULL if session is valid. So this patch skip generate encryp
debian
CVE-2018-1000204P4MEDIUMCVSS 5.3fixed in linux 4.16.12-1 (bookworm)2018
CVE-2018-1000204 [MEDIUM] CVE-2018-1000204: linux - Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0...
Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV and an empty 6-byte cmdp. This may lead to copying up to 1000 kernel heap pages to the userspace. This has been fixed upstream in https://github.com/torvalds/linux/commit/a45b599ad808c3c982fdcdc12b0b8611c2f92824 already. The problem has limited
debian
CVE-2022-3564P4MEDIUMCVSS 5.5fixed in linux 6.0.8-1 (bookworm)2022
CVE-2022-3564 [MEDIUM] CVE-2022-3564: linux - A vulnerability classified as critical was found in Linux Kernel. Affected by th...
A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211087.
Scope: loc
debian