Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 157 of 632
CVE-2016-3070P4HIGHCVSS 7.8fixed in linux 4.4.2-1 (bookworm)2016
CVE-2016-3070 [HIGH] CVE-2016-3070: linux - The trace_writeback_dirty_page implementation in include/trace/events/writeback....
The trace_writeback_dirty_page implementation in include/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate.c, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by triggering a certain page move.
Scope: local
bookworm: resolved (fixed in 4.
debian
CVE-2017-6345P4HIGHCVSS 7.8fixed in linux 4.9.13-1 (bookworm)2017
CVE-2017-6345 [HIGH] CVE-2017-6345: linux - The LLC subsystem in the Linux kernel before 4.9.13 does not ensure that a certa...
The LLC subsystem in the Linux kernel before 4.9.13 does not ensure that a certain destructor exists in required circumstances, which allows local users to cause a denial of service (BUG_ON) or possibly have unspecified other impact via crafted system calls.
Scope: local
bookworm: resolved (fixed in 4.9.13-1)
bullseye: resolved (fixed in 4.9.13-1)
forky: resolved (fixed
debian
CVE-2020-26139P4MEDIUMCVSS 5.3fixed in linux 5.10.46-1 (bookworm)2020
CVE-2020-26139 [MEDIUM] CVE-2020-26139: linux - An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwar...
An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clien
debian
CVE-2017-1000407P4HIGHCVSS 7.4fixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-1000407 [HIGH] CVE-2017-1000407: linux - The Linux Kernel 2.6.32 and later are affected by a denial of service, by floodi...
The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.
Scope: local
bookworm: resolved (fixed in 4.14.7-1)
bullseye: resolved (fixed in 4.14.7-1)
forky: resolved (fixed in 4.14.7-1)
sid: resolved (fixed in 4.14.7-1)
trixie: resolved (fixed in 4.14.7-1)
debian
CVE-2022-40982P4MEDIUMCVSS 6.5fixed in intel-microcode 3.20230808.1~deb12u1 (bookworm)2022
CVE-2022-40982 [MEDIUM] CVE-2022-40982: intel-microcode - Information exposure through microarchitectural state after transient execution ...
Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20230808.1~deb12u1)
bullseye: resolved (fixed in 3.20230808.1~deb11u1)
forky
debian
CVE-2023-39198P4HIGHCVSS 7.5fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-39198 [HIGH] CVE-2023-39198: linux - A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_d...
A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_object_create_with_handle(), but the handle is the only one holding a reference to it. This flaw allows an attacker to guess the returned handle value and trigger a use-after-free issue, potentially leading to a denial of
debian
CVE-2014-9940P4LOWCVSS 7.0fixed in linux 4.0.2-1 (bookworm)2014
CVE-2014-9940 [HIGH] CVE-2014-9940: linux - The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux ke...
The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.
Scope: local
bookworm: resolved (fixed in 4.0.2-1)
bullseye: resolved (fixed in 4.0.2-1)
forky: resolved (fixed in 4.0.2-1)
sid: resolved (fixed in 4.0.2-1)
trixie:
debian
CVE-2023-20593P4MEDIUMCVSS 5.5fixed in amd64-microcode 3.20230719.1~deb12u1 (bookworm)2023
CVE-2023-20593 [MEDIUM] CVE-2023-20593: amd64-microcode - An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may a...
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
Scope: local
bookworm: resolved (fixed in 3.20230719.1~deb12u1)
bullseye: resolved (fixed in 3.20230719.1~deb11u1)
forky: resolved (fixed in 3.20230719.1)
sid: resolved (fixed in 3.20230719.1)
trixie: resolved (fixed
debian
CVE-2013-4299P4MEDIUMCVSS 6.0fixed in linux 3.11.6-2 (bookworm)2013
CVE-2013-4299 [MEDIUM] CVE-2013-4299: linux - Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel t...
Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive information or modify data via a crafted mapping to a snapshot block device.
Scope: local
bookworm: resolved (fixed in 3.11.6-2)
bullseye: resolved (fixed in 3.11.6-2)
forky: resolved (fixed in 3.11.6-2)
sid: resolved (fix
debian
CVE-2021-27364P4HIGHCVSS 7.1fixed in linux 5.10.24-1 (bookworm)2021
CVE-2021-27364 [HIGH] CVE-2021-27364: linux - An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_tr...
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
Scope: local
bookworm: resolved (fixed in 5.10.24-1)
bullseye: resolved (fixed in 5.10.24-1)
forky: resolved (fixed in 5.10.24-1)
sid: resolved (fixed in 5.10.24-1)
trixie: resolved (fix
debian
CVE-2017-16913P4MEDIUMCVSS 5.9fixed in linux 4.14.12-1 (bookworm)2017
CVE-2017-16913 [MEDIUM] CVE-2017-16913: linux - The "stub_recv_cmd_submit()" function (drivers/usb/usbip/stub_rx.c) in the Linux...
The "stub_recv_cmd_submit()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 when handling CMD_SUBMIT packets allows attackers to cause a denial of service (arbitrary memory allocation) via a specially crafted USB over IP packet.
Scope: local
bookworm: resolved (fixed in 4.14.12-1)
bullseye: resolved (fixed in 4.
debian
CVE-2012-2136P4HIGHCVSS 7.2fixed in linux 3.2.20-1 (bookworm)2012
CVE-2012-2136 [HIGH] CVE-2012-2136: linux - The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before ...
The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly gain privileges by leveraging access to a TUN/TAP device.
Scope: local
bookworm: resolved (fixed in 3.2.20-1)
bullseye: res
debian
CVE-2024-36916P4HIGHCVSS 7.1fixed in linux 6.1.94-1 (bookworm)2024
CVE-2024-36916 [HIGH] CVE-2024-36916: linux - In the Linux kernel, the following vulnerability has been resolved: blk-iocost:...
In the Linux kernel, the following vulnerability has been resolved: blk-iocost: avoid out of bounds shift UBSAN catches undefined behavior in blk-iocost, where sometimes iocg->delay is shifted right by a number that is too large, resulting in undefined behavior on some architectures. [ 186.556576] ------------[ cut here ]------------ UBSAN: shift-out-of-bounds in bloc
debian
CVE-2025-37879P4HIGHCVSS 7.1fixed in linux 6.1.137-1 (bookworm)2025
CVE-2025-37879 [HIGH] CVE-2025-37879: linux - In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix...
In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix improper handling of bogus negative read/write replies In p9_client_write() and p9_client_read_once(), if the server incorrectly replies with success but a negative write/read count then we would consider written (negative) 3)
Scope: local
bookworm: resolved (fixed in 6.1.137-1)
bullseye:
debian
CVE-2016-10318P4MEDIUMCVSS 6.5fixed in linux 4.7.4-1 (bookworm)2016
CVE-2016-10318 [MEDIUM] CVE-2016-10318: linux - A missing authorization check in the fscrypt_process_policy function in fs/crypt...
A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel before 4.7.4 allows a user to assign an encryption policy to a directory owned by a different user, potentially creating a denial of service.
Scope: local
bookworm: resolved (fixed in 4.7.4-1)
bullseye: res
debian
CVE-2025-22038P4HIGHCVSS 7.1fixed in linux 6.1.135-1 (bookworm)2025
CVE-2025-22038 [HIGH] CVE-2025-22038: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: vali...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate zero num_subauth before sub_auth is accessed Access psid->sub_auth[psid->num_subauth - 1] without checking if num_subauth is non-zero leads to an out-of-bounds read. This patch adds a validation step to ensure num_subauth != 0 before sub_auth is accessed.
Scope: local
bookworm: resolve
debian
CVE-2018-1000004P4MEDIUMCVSS 5.9fixed in linux 4.14.17-1 (bookworm)2018
CVE-2018-1000004 [MEDIUM] CVE-2018-1000004: linux - In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race conditi...
In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race condition vulnerability exists in the sound system, this can lead to a deadlock and denial of service condition.
Scope: local
bookworm: resolved (fixed in 4.14.17-1)
bullseye: resolved (fixed in 4.14.17-1)
forky: resolved (fixed in 4.14.17-1)
sid: resolved (fixed in 4.14.17-1)
trixie: resol
debian
CVE-2023-6606P4HIGHCVSS 7.1fixed in linux 6.1.76-1 (bookworm)2023
CVE-2023-6606 [HIGH] CVE-2023-6606: linux - An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/ne...
An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.
Scope: local
bookworm: resolved (fixed in 6.1.76-1)
bullseye: resolved (fixed in 5.10.209-1)
forky: resolved (fixed in 6.6.9-1)
sid: resolved (fixed in 6.6.9-1)
trixi
debian
CVE-2023-6610P4HIGHCVSS 7.1fixed in linux 6.1.76-1 (bookworm)2023
CVE-2023-6610 [HIGH] CVE-2023-6610: linux - An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/clie...
An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.
Scope: local
bookworm: resolved (fixed in 6.1.76-1)
bullseye: open
forky: resolved (fixed in 6.6.13-1)
sid: resolved (fixed in 6.6.13-1)
trixie: resolved (fixed
debian
CVE-2021-47097P4HIGHCVSS 7.1fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-47097 [HIGH] CVE-2021-47097: linux - In the Linux kernel, the following vulnerability has been resolved: Input: elan...
In the Linux kernel, the following vulnerability has been resolved: Input: elantech - fix stack out of bound access in elantech_change_report_id() The array param[] in elantech_change_report_id() must be at least 3 bytes, because elantech_read_reg_params() is calling ps2_command() with PSMOUSE_CMD_GETINFO, that is going to access 3 bytes from param[], but it's defined
debian