cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 168 of 632
CVE-2020-24394P4HIGHCVSS 7.1fixed in linux 5.7.6-1 (bookworm)2020
CVE-2020-24394 [HIGH] CVE-2020-24394: linux - In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set inco... In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered. Scope: local bookworm: resolved (fixed in 5.7.6-1) bullseye: resolved (fixed in 5.7.6-1) forky: resolved (fixed in 5.7.6-1) sid:
debian
CVE-2020-29370P4HIGHCVSS 7.0fixed in linux 5.5.13-1 (bookworm)2020
CVE-2020-29370 [HIGH] CVE-2020-29370: linux - An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kerne... An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment, aka CID-fd4d9c7d0c71. Scope: local bookworm: resolved (fixed in 5.5.13-1) bullseye: resolved (fixed in 5.5.13-1) forky: resolved (fixed in 5.5.13-1) sid: resolved (fixed in 5.5.13-1) trixie: resolved (fixed in 5.5.13-1)
debian
CVE-2022-33742P4HIGHCVSS 7.1fixed in linux 5.18.14-1 (bookworm)2022
CVE-2022-33742 [HIGH] CVE-2022-33742: linux - Linux disk/nic frontends data leaks T[his CNA information record relates to mult... Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sh
debian
CVE-2022-26365P4HIGHCVSS 7.1fixed in linux 5.18.14-1 (bookworm)2022
CVE-2022-26365 [HIGH] CVE-2022-26365: linux - Linux disk/nic frontends data leaks T[his CNA information record relates to mult... Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sh
debian
CVE-2022-33741P4HIGHCVSS 7.1fixed in linux 5.18.14-1 (bookworm)2022
CVE-2022-33741 [HIGH] CVE-2022-33741: linux - Linux disk/nic frontends data leaks T[his CNA information record relates to mult... Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sh
debian
CVE-2022-33740P4HIGHCVSS 7.1fixed in linux 5.18.14-1 (bookworm)2022
CVE-2022-33740 [HIGH] CVE-2022-33740: linux - Linux disk/nic frontends data leaks T[his CNA information record relates to mult... Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sh
debian
CVE-2024-26630P4LOWCVSS 7.1fixed in linux 6.7.9-1 (forky)2024
CVE-2024-26630 [HIGH] CVE-2024-26630: linux - In the Linux kernel, the following vulnerability has been resolved: mm: cachest... In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix folio read-after-free in cache walk In cachestat, we access the folio from the page cache's xarray to compute its page offset, and check for its dirty and writeback flags. However, we do not hold a reference to the folio before performing these actions, which means the folio can con
debian
CVE-2024-46743P4HIGHCVSS 7.1fixed in linux 6.1.112-1 (bookworm)2024
CVE-2024-46743 [HIGH] CVE-2024-46743: linux - In the Linux kernel, the following vulnerability has been resolved: of/irq: Pre... In the Linux kernel, the following vulnerability has been resolved: of/irq: Prevent device address out-of-bounds read in interrupt map walk When of_irq_parse_raw() is invoked with a device address smaller than the interrupt parent node (from #address-cells property), KASAN detects the following out-of-bounds read when populating the initial match table (dyndbg="func o
debian
CVE-2022-49444P4HIGHCVSS 7.1fixed in linux 5.18.5-1 (bookworm)2022
CVE-2022-49444 [HIGH] CVE-2022-49444: linux - In the Linux kernel, the following vulnerability has been resolved: module: fix... In the Linux kernel, the following vulnerability has been resolved: module: fix [e_shstrndx].sh_size=0 OOB access It is trivial to craft a module to trigger OOB access in this line: if (info->secstrings[strhdr->sh_size - 1] != '\0') { BUG: unable to handle page fault for address: ffffc90000aa0fff PGD 100000067 P4D 100000067 PUD 100066067 PMD 10436f067 PTE 0 Oops: 0000
debian
CVE-2022-49560P4HIGHCVSS 7.1fixed in linux 5.18.2-1 (bookworm)2022
CVE-2022-49560 [HIGH] CVE-2022-49560: linux - In the Linux kernel, the following vulnerability has been resolved: exfat: chec... In the Linux kernel, the following vulnerability has been resolved: exfat: check if cluster num is valid Syzbot reported slab-out-of-bounds read in exfat_clear_bitmap. This was triggered by reproducer calling truncute with size 0, which causes the following trace: BUG: KASAN: slab-out-of-bounds in exfat_clear_bitmap+0x147/0x490 fs/exfat/balloc.c:174 Read of size 8 at
debian
CVE-2024-47723P4HIGHCVSS 7.1fixed in linux 6.1.115-1 (bookworm)2024
CVE-2024-47723 [HIGH] CVE-2024-47723: linux - In the Linux kernel, the following vulnerability has been resolved: jfs: fix ou... In the Linux kernel, the following vulnerability has been resolved: jfs: fix out-of-bounds in dbNextAG() and diAlloc() In dbNextAG() , there is no check for the case where bmp->db_numag is greater or same than MAXAG due to a polluted image, which causes an out-of-bounds. Therefore, a bounds check should be added in dbMount(). And in dbNextAG(), a check for the case wh
debian
CVE-2024-38538P4HIGHCVSS 7.1fixed in linux 6.1.94-1 (bookworm)2024
CVE-2024-38538 [HIGH] CVE-2024-38538: linux - In the Linux kernel, the following vulnerability has been resolved: net: bridge... In the Linux kernel, the following vulnerability has been resolved: net: bridge: xmit: make sure we have at least eth header len bytes syzbot triggered an uninit value[1] error in bridge device's xmit path by sending a short (less than ETH_HLEN bytes) skb. To fix it check if we can actually pull that amount instead of assuming. Tested with dropwatch: drop at: br_dev_x
debian
CVE-2024-26763P4HIGHCVSS 7.1fixed in linux 6.1.82-1 (bookworm)2024
CVE-2024-26763 [HIGH] CVE-2024-26763: linux - In the Linux kernel, the following vulnerability has been resolved: dm-crypt: d... In the Linux kernel, the following vulnerability has been resolved: dm-crypt: don't modify the data when using authenticated encryption It was said that authenticated encryption could produce invalid tag when the data that is being encrypted is modified [1]. So, fix this problem by copying the data into the clone bio first and then encrypt them inside the clone bio. T
debian
CVE-2022-49145P4HIGHCVSS 7.1fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-49145 [HIGH] CVE-2022-49145: linux - In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC:... In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Avoid out of bounds access when parsing _CPC data If the NumEntries field in the _CPC return package is less than 2, do not attempt to access the "Revision" element of that package, because it may not be present then. BugLink: https://lore.kernel.org/lkml/20220322143534.GC32582@xsang-OptiP
debian
CVE-2022-49368P4HIGHCVSS 7.1fixed in linux 5.18.5-1 (bookworm)2022
CVE-2022-49368 [HIGH] CVE-2022-49368: linux - In the Linux kernel, the following vulnerability has been resolved: net: ethern... In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: out of bounds read in mtk_hwlro_get_fdir_entry() The "fsp->location" variable comes from user via ethtool_get_rxnfc(). Check that it is valid to prevent an out of bounds read. Scope: local bookworm: resolved (fixed in 5.18.5-1) bullseye: resolved (fixed in 5.10.127-1) forky
debian
CVE-2023-52504P4HIGHCVSS 7.1fixed in linux 6.1.64-1 (bookworm)2023
CVE-2023-52504 [HIGH] CVE-2023-52504: linux - In the Linux kernel, the following vulnerability has been resolved: x86/alterna... In the Linux kernel, the following vulnerability has been resolved: x86/alternatives: Disable KASAN in apply_alternatives() Fei has reported that KASAN triggers during apply_alternatives() on a 5-level paging machine: BUG: KASAN: out-of-bounds in rcu_is_watching() Read of size 4 at addr ff110003ee6419a0 by task swapper/0/0 ... __asan_load4() rcu_is_watching() trace_ha
debian
CVE-2022-41858P4HIGHCVSS 7.1fixed in linux 5.17.6-1 (bookworm)2022
CVE-2022-41858 [HIGH] CVE-2022-41858: linux - A flaw was found in the Linux kernel. A NULL pointer dereference may occur while... A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach in sl_tx_timeout in drivers/net/slip/slip.c. This issue could allow an attacker to crash the system or leak internal kernel information. Scope: local bookworm: resolved (fixed in 5.17.6-1) bullseye: resolved (fixed in 5.10.113-1) forky: resolved (fix
debian
CVE-2022-49623P4HIGHCVSS 7.1fixed in linux 5.18.14-1 (bookworm)2022
CVE-2022-49623 [HIGH] CVE-2022-49623: linux - In the Linux kernel, the following vulnerability has been resolved: powerpc/xiv... In the Linux kernel, the following vulnerability has been resolved: powerpc/xive/spapr: correct bitmap allocation size kasan detects access beyond the end of the xibm->bitmap allocation: BUG: KASAN: slab-out-of-bounds in _find_first_zero_bit+0x40/0x140 Read of size 8 at addr c00000001d1d0118 by task swapper/0/1 CPU: 0 PID: 1 Comm: swapper/0 Not tainted 5.19.0-rc2-0000
debian
CVE-2022-49249P4HIGHCVSS 7.1fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-49249 [HIGH] CVE-2022-49249: linux - In the Linux kernel, the following vulnerability has been resolved: ASoC: codec... In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wc938x: fix accessing array out of bounds for enum type Accessing enums using integer would result in array out of bounds access on platforms like aarch64 where sizeof(long) is 8 compared to enum size which is 4 bytes. Fix this by using enumerated items instead of integers. Scope: local
debian
CVE-2024-41059P4HIGHCVSS 7.1fixed in linux 6.1.106-1 (bookworm)2024
CVE-2024-41059 [HIGH] CVE-2024-41059: linux - In the Linux kernel, the following vulnerability has been resolved: hfsplus: fi... In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix uninit-value in copy_name [syzbot reported] BUG: KMSAN: uninit-value in sized_strscpy+0xc4/0x160 sized_strscpy+0xc4/0x160 copy_name+0x2af/0x320 fs/hfsplus/xattr.c:411 hfsplus_listxattr+0x11e9/0x1a50 fs/hfsplus/xattr.c:750 vfs_listxattr fs/xattr.c:493 [inline] listxattr+0x1f3/0x6b0 fs/xatt
debian
Debian Linux vulnerabilities | cvebase