Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 164 of 632
CVE-2025-71201P4LOWCVSS 7.1fixed in linux 6.18.8-1 (forky)2025
CVE-2025-71201 [HIGH] CVE-2025-71201: linux - In the Linux kernel, the following vulnerability has been resolved: netfs: Fix ...
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early read unlock of page with EOF in middle The read result collection for buffered reads seems to run ahead of the completion of subrequests under some circumstances, as can be seen in the following log snippet: 9p_client_res: client 18446612686390831168 response P9_TREAD tag 0 err 0 ...
debian
CVE-2022-23040P4HIGHCVSS 7.0fixed in linux 5.16.14-1 (bookworm)2022
CVE-2022-23040 [HIGH] CVE-2022-23040: linux - Linux PV device frontends vulnerable to attacks by backends T[his CNA informatio...
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential da
debian
CVE-2022-23038P4HIGHCVSS 7.0fixed in linux 5.16.14-1 (bookworm)2022
CVE-2022-23038 [HIGH] CVE-2022-23038: linux - Linux PV device frontends vulnerable to attacks by backends T[his CNA informatio...
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential da
debian
CVE-2022-23041P4HIGHCVSS 7.0fixed in linux 5.16.14-1 (bookworm)2022
CVE-2022-23041 [HIGH] CVE-2022-23041: linux - Linux PV device frontends vulnerable to attacks by backends T[his CNA informatio...
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential da
debian
CVE-2022-23036P4HIGHCVSS 7.0fixed in linux 5.16.14-1 (bookworm)2022
CVE-2022-23036 [HIGH] CVE-2022-23036: linux - Linux PV device frontends vulnerable to attacks by backends T[his CNA informatio...
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential da
debian
CVE-2022-23039P4HIGHCVSS 7.0fixed in linux 5.16.14-1 (bookworm)2022
CVE-2022-23039 [HIGH] CVE-2022-23039: linux - Linux PV device frontends vulnerable to attacks by backends T[his CNA informatio...
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential da
debian
CVE-2020-29368P4HIGHCVSS 7.0fixed in linux 5.7.6-1 (bookworm)2020
CVE-2020-29368 [HIGH] CVE-2020-29368: linux - An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux ker...
An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1.
Scope: local
bookworm: resolved (fixed in 5.7.6-1)
bullseye: resolved (fixed in 5.7.6-1)
forky: resolved (fixed in 5.7.6-1)
sid: r
debian
CVE-2022-23037P4HIGHCVSS 7.0fixed in linux 5.16.14-1 (bookworm)2022
CVE-2022-23037 [HIGH] CVE-2022-23037: linux - Linux PV device frontends vulnerable to attacks by backends T[his CNA informatio...
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential da
debian
CVE-2020-10711P4MEDIUMCVSS 5.9fixed in linux 5.6.14-1 (bookworm)2020
CVE-2020-10711 [MEDIUM] CVE-2020-10711: linux - A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsyste...
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO restricted bitmap tag in the 'cipso_v4_parsetag_rbm' rout
debian
CVE-2023-1077P4HIGHCVSS 7.0fixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-1077 [HIGH] CVE-2023-1077: linux - In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not...
In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the list head,which would then be used as a type confused sched_rt_entity,causing memory corruption.
Scope: local
bookworm: resolved (fi
debian
CVE-2024-27397P4HIGHCVSS 7.0fixed in linux 6.1.99-1 (bookworm)2024
CVE-2024-27397 [HIGH] CVE-2024-27397: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use timestamp to check for set element timeout Add a timestamp field at the beginning of the transaction, store it in the nftables per-netns area. Update set backend .insert, .deactivate and sync gc path to use the timestamp, this avoids that an element expires while control plan
debian
CVE-2024-46858P4HIGHCVSS 7.0fixed in linux 6.1.112-1 (bookworm)2024
CVE-2024-46858 [HIGH] CVE-2024-46858: linux - In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ...
In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: Fix uaf in __timer_delete_sync There are two paths to access mptcp_pm_del_add_timer, result in a race condition: CPU1 CPU2 ==== ==== net_rx_action napi_poll netlink_sendmsg __napi_poll netlink_unicast process_backlog netlink_unicast_kernel __netif_receive_skb genl_rcv __netif_receive_skb_on
debian
CVE-2022-23042P4HIGHCVSS 7.0fixed in linux 5.16.14-1 (bookworm)2022
CVE-2022-23042 [HIGH] CVE-2022-23042: linux - Linux PV device frontends vulnerable to attacks by backends T[his CNA informatio...
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential da
debian
CVE-2014-3183P4MEDIUMCVSS 6.9fixed in linux 3.16.2-2 (bookworm)2014
CVE-2014-3183 [MEDIUM] CVE-2014-3183: linux - Heap-based buffer overflow in the logi_dj_ll_raw_request function in drivers/hid...
Heap-based buffer overflow in the logi_dj_ll_raw_request function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that specifies a large report size for an LED report.
Scope: local
bookworm: resolved (fixed in 3.1
debian
CVE-2024-26730P4LOWCVSS 7.0fixed in linux 6.7.7-1 (forky)2024
CVE-2024-26730 [HIGH] CVE-2024-26730: linux - In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct...
In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775) Fix access to temperature configuration registers The number of temperature configuration registers does not always match the total number of temperature registers. This can result in access errors reported if KASAN is enabled. BUG: KASAN: global-out-of-bounds in nct6775_probe+0x5654/
debian
CVE-2024-26939P4HIGHCVSS 7.0fixed in linux 6.1.90-1 (bookworm)2024
CVE-2024-26939 [HIGH] CVE-2024-26939: linux - In the Linux kernel, the following vulnerability has been resolved: drm/i915/vm...
In the Linux kernel, the following vulnerability has been resolved: drm/i915/vma: Fix UAF on destroy against retire race Object debugging tools were sporadically reporting illegal attempts to free a still active i915 VMA object when parking a GT believed to be idle. [161.359441] ODEBUG: free active (active state 0) object: ffff88811643b958 object type: i915_active hin
debian
CVE-2024-26872P4HIGHCVSS 7.0fixed in linux 6.1.85-1 (bookworm)2024
CVE-2024-26872 [HIGH] CVE-2024-26872: linux - In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: ...
In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Do not register event handler until srpt device is fully setup Upon rare occasions, KASAN reports a use-after-free Write in srpt_refresh_port(). This seems to be because an event handler is registered before the srpt device is fully setup and a race condition upon error may leave a partiall
debian
CVE-2024-50059P4HIGHCVSS 7.0fixed in linux 6.1.115-1 (bookworm)2024
CVE-2024-50059 [HIGH] CVE-2024-50059: linux - In the Linux kernel, the following vulnerability has been resolved: ntb: ntb_hw...
In the Linux kernel, the following vulnerability has been resolved: ntb: ntb_hw_switchtec: Fix use after free vulnerability in switchtec_ntb_remove due to race condition In the switchtec_ntb_add function, it can call switchtec_ntb_init_sndev function, then &sndev->check_link_status_work is bound with check_link_status_work. switchtec_ntb_link_notification may be calle
debian
CVE-2024-39486P4LOWCVSS 7.0fixed in linux 6.9.8-1 (forky)2024
CVE-2024-39486 [HIGH] CVE-2024-39486: linux - In the Linux kernel, the following vulnerability has been resolved: drm/drm_fil...
In the Linux kernel, the following vulnerability has been resolved: drm/drm_file: Fix pid refcounting race , Maxime Ripard , Thomas Zimmermann filp->pid is supposed to be a refcounted pointer; however, before this patch, drm_file_update_pid() only increments the refcount of a struct pid after storing a pointer to it in filp->pid and dropping the dev->filelist_mutex, m
debian
CVE-2024-27020P4HIGHCVSS 7.0fixed in linux 6.1.90-1 (bookworm)2024
CVE-2024-27020 [HIGH] CVE-2024-27020: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() nft_unregister_expr() can concurrent with __nft_expr_type_get(), and there is not any protection when iterate over nf_tables_expressions list in __nft_expr_type_get(). Therefore, there is potential data-race of nf_tables_expression
debian