cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 167 of 632
CVE-2015-5366P4HIGHCVSS 7.8fixed in linux 4.0.7-1 (bookworm)2015
CVE-2015-5366 [HIGH] CVE-2015-5366: linux - The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4... The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 provide inappropriate -EAGAIN return values, which allows remote attackers to cause a denial of service (EPOLLET epoll application read outage) via an incorrect checksum in a UDP packet, a different vulnerability than CVE-2015-5364. Scope: local bookworm: resolved (fixed in 4.0.7-1) bul
debian
CVE-2018-14625P4MEDIUMCVSS 5.3fixed in linux 4.19.9-1 (bookworm)2018
CVE-2018-14625 [MEDIUM] CVE-2018-14625: linux - A flaw was found in the Linux Kernel where an attacker may be able to have an un... A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients. Scope: loca
debian
CVE-2022-21166P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20220510.1 (bookworm)2022
CVE-2022-21166 [MEDIUM] CVE-2022-21166: intel-microcode - Incomplete cleanup in specific special register write operations for some Intel(... Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. Scope: local bookworm: resolved (fixed in 3.20220510.1) bullseye: resolved (fixed in 3.20220510.1~deb11u1) forky: resolved (fixed in 3.20220510.1) sid: resolved (fixed i
debian
CVE-2019-19046P4LOWCVSS 6.5fixed in linux 5.4.19-1 (bookworm)2019
CVE-2019-19046 [MEDIUM] CVE-2019-19046: linux - A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_ms... A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering ida_simple_get() failure, aka CID-4aa7afb0ee20. NOTE: third parties dispute the relevance of this because an attacker cannot realistically control this failure a
debian
CVE-2015-8963P4HIGHCVSS 7.0fixed in linux 4.4.2-1 (bookworm)2015
CVE-2015-8963 [HIGH] CVE-2015-8963: linux - Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows loc... Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect handling of an swevent data structure during a CPU unplug operation. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: resolved (fixed in 4.4.2-1) forky: resolved (fixed in 4.4.2-1) s
debian
CVE-2013-4587P4HIGHCVSS 7.2fixed in linux 3.12.5-1 (bookworm)2013
CVE-2013-4587 [HIGH] CVE-2013-4587: linux - Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.... Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value. Scope: local bookworm: resolved (fixed in 3.12.5-1) bullseye: resolved (fixed in 3.12.5-1) forky: resolved (fixed in 3.12.5-1) sid: resolved (fixed in 3.12.5-1) trixie: resol
debian
CVE-2015-8955P4HIGHCVSS 7.3fixed in linux 4.1.3-1 (bookworm)2015
CVE-2015-8955 [HIGH] CVE-2015-8955: linux - arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms... arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via vectors involving events that are mishandled during a span of multiple HW PMUs. Scope: local bookworm: resolved (fixed in 4.1.3-1) bullseye: resolved (fixed in 4.1.3-1) forky: resolved (fixe
debian
CVE-2014-4667P4MEDIUMCVSS 5.0fixed in linux 3.14.9-1 (bookworm)2014
CVE-2014-4667 [MEDIUM] CVE-2014-4667: linux - The sctp_association_free function in net/sctp/associola.c in the Linux kernel b... The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet. Scope: local bookworm: resolved (fixed in 3.14.9-1) bullseye: resolved (fixed in 3.14.9-1) forky: resolved (fixed in 3.14.9-1
debian
CVE-2013-4300P4HIGHCVSS 7.2fixed in linux 3.11.5-1 (bookworm)2013
CVE-2013-4300 [HIGH] CVE-2013-4300: linux - The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 p... The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows local users to gain privileges via PID spoofing. Scope: local bookworm: resolved (fixed in 3.11.5-1) bullseye: resolved (fixed in 3.11.5-1) forky: resolved (fixed in 3.11.5-1) sid: resolved (fixed in 3.11.5-1) trixie: resolve
debian
CVE-2020-8428P4HIGHCVSS 7.1fixed in linux 5.4.19-1 (bookworm)2020
CVE-2020-8428 [HIGH] CVE-2020-8428: linux - fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-f... fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9. One attack vector may be an open system call for a UNIX domain socket, if the socket is being moved to a new parent directory and its old paren
debian
CVE-2021-3739P4HIGHCVSS 7.1fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-3739 [HIGH] CVE-2021-3739: linux - A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/... A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. The highest threat from this vulnerability is to system availability. Scope: local bookworm: resolved (fixed in 5
debian
CVE-2023-26607P4HIGHCVSS 7.1fixed in linux 4.19.37-1 (bookworm)2023
CVE-2023-26607 [HIGH] CVE-2023-26607: linux - In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in f... In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c. Scope: local bookworm: resolved (fixed in 4.19.37-1) bullseye: resolved (fixed in 4.19.37-1) forky: resolved (fixed in 4.19.37-1) sid: resolved (fixed in 4.19.37-1) trixie: resolved (fixed in 4.19.37-1)
debian
CVE-2018-18021P4HIGHCVSS 7.1fixed in linux 4.18.10-2 (bookworm)2018
CVE-2018-18021 [HIGH] CVE-2018-18021: linux - arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 pl... arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers who can create virtual machines. An attacker can arbitrarily redirect the hypervisor flow of control (with full register control). An attacker can also cause a denial of service (hypervisor panic) via an illegal e
debian
CVE-2021-32078P4LOWCVSS 7.1fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-32078 [HIGH] CVE-2021-32078: linux - An Out-of-Bounds Read was discovered in arch/arm/mach-footbridge/personal-pci.c ... An Out-of-Bounds Read was discovered in arch/arm/mach-footbridge/personal-pci.c in the Linux kernel through 5.12.11 because of the lack of a check for a value that shouldn't be negative, e.g., access to element -2 of an array, aka CID-298a58e165e4. Scope: local bookworm: resolved (fixed in 5.14.6-1) bullseye: open forky: resolved (fixed in 5.14.6-1) sid: resolved (fix
debian
CVE-2020-36386P4HIGHCVSS 7.1fixed in linux 5.7.17-1 (bookworm)2020
CVE-2020-36386 [HIGH] CVE-2020-36386: linux - An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_even... An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci_extended_inquiry_result_evt, aka CID-51c19bf3d5cf. Scope: local bookworm: resolved (fixed in 5.7.17-1) bullseye: resolved (fixed in 5.7.17-1) forky: resolved (fixed in 5.7.17-1) sid: resolved (fixed in 5.7.17-1) trixie: resolved (fixed in 5.7.17-1)
debian
CVE-2021-32399P4HIGHCVSS 7.0fixed in linux 5.10.38-1 (bookworm)2021
CVE-2021-32399 [HIGH] CVE-2021-32399: linux - net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condit... net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller. Scope: local bookworm: resolved (fixed in 5.10.38-1) bullseye: resolved (fixed in 5.10.38-1) forky: resolved (fixed in 5.10.38-1) sid: resolved (fixed in 5.10.38-1) trixie: resolved (fixed in 5.10.38-1)
debian
CVE-2013-4125P4MEDIUMCVSS 5.4fixed in linux 3.10.5-1 (bookworm)2013
CVE-2013-4125 [MEDIUM] CVE-2013-4125: linux - The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in the Lin... The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in the Linux kernel through 3.10.1 does not properly handle Router Advertisement (RA) messages in certain circumstances involving three routes that initially qualified for membership in an ECMP route set until a change occurred for one of the first two routes, which allows remote attackers to cause
debian
CVE-2026-31407P4UNKNOWNfixed in linux 6.19.10-1 (forky)2026
CVE-2026-31407 CVE-2026-31407: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ... In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: add missing netlink policy validations Hyunwoo Kim reports out-of-bounds access in sctp and ctnetlink. These attributes are used by the kernel without any validation. Extend the netlink policies accordingly. Quoting the reporter: nlattr_to_sctp() assigns the user-supplied CTA_PROTOINFO_
debian
CVE-2026-23454P4UNKNOWNfixed in linux 6.19.10-1 (forky)2026
CVE-2026-23454 CVE-2026-23454: linux - In the Linux kernel, the following vulnerability has been resolved: net: mana: ... In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown A potential race condition exists in mana_hwc_destroy_channel() where hwc->caller_ctx is freed before the HWC's Completion Queue (CQ) and Event Queue (EQ) are destroyed. This allows an in-flight CQ interrupt handler to derefer
debian
CVE-2026-31395P4LOWfixed in linux 6.19.10-1 (forky)2026
CVE-2026-31395 [LOW] CVE-2026-31395: linux - In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fi... In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler The ASYNC_EVENT_CMPL_EVENT_ID_DBG_BUF_PRODUCER handler in bnxt_async_event_process() uses a firmware-supplied 'type' field directly as an index into bp->bs_trace[] without bounds validation. The 'type' field is a 16-bit value extracted fro
debian
Debian Linux vulnerabilities | cvebase