Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 17 of 632
CVE-2023-5717P3HIGHCVSS 7.8fixed in linux 6.1.64-1 (bookworm)2023
CVE-2023-5717 [HIGH] CVE-2023-5717: linux - A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Perf...
A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer. We recommend upgrading
debian
CVE-2020-27815P3HIGHCVSS 7.8fixed in linux 5.10.4-1 (bookworm)2020
CVE-2020-27815 [HIGH] CVE-2020-27815: linux - A flaw was found in the JFS filesystem code in the Linux Kernel which allows a l...
A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Scope: local
bookworm: resolved (fixed in 5.10.4-1
debian
CVE-2021-3612P3HIGHCVSS 7.8fixed in linux 5.10.46-3 (bookworm)2021
CVE-2021-3612 [HIGH] CVE-2021-3612: linux - An out-of-bounds memory write flaw was found in the Linux kernel's joystick devi...
An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availa
debian
CVE-2023-0461P3HIGHCVSS 7.8fixed in linux 6.1.7-1 (bookworm)2023
CVE-2023-0461 [HIGH] CVE-2023-0461: linux - There is a use-after-free vulnerability in the Linux Kernel which can be exploit...
There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To reach the vulnerability kernel configuration flag CONFIG_TLS or CONFIG_XFRM_ESPINTCP has to be configured, but the operation does not require any privilege. There is a use-after-free bug of icsk_ulp_data of a struct inet_connection_sock. When CONF
debian
CVE-2021-3489P3HIGHCVSS 7.8fixed in linux 5.10.38-1 (bookworm)2021
CVE-2021-3489 [HIGH] CVE-2021-3489: linux - The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not chec...
The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This issue was fixed via commit 4b81ccebaeee ("bpf, ringbuf: Deny reserve of buffers larger than ringbuf") (v5.13-rc4)
debian
CVE-2026-23111P3HIGHCVSS 7.8fixed in linux 6.1.164-1 (bookworm)2026
CVE-2026-23111 [HIGH] CVE-2026-23111: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-catchall counterpart nft_mapelem_activate() and compared to what is logically required. nft_map_catchall_activate() is called from the
debian
CVE-2018-1000028P3HIGHCVSS 7.4fixed in linux 4.14.17-1 (bookworm)2018
CVE-2018-1000028 [HIGH] CVE-2018-1000028: linux - Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4....
Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading or writing files they should not be able to via NFS. This attack appear to be exploitable via NFS server must export a filesystem with the "rootsquash" options enabled.
debian
CVE-2021-3483P3HIGHCVSS 7.8fixed in linux 5.10.28-1 (bookworm)2021
CVE-2021-3483 [HIGH] CVE-2021-3483: linux - A flaw was found in the Nosy driver in the Linux kernel. This issue allows a dev...
A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. Versions before kernel 5.12-rc6 are affected
Scope: local
bookwor
debian
CVE-2021-47259P3HIGHCVSS 7.5fixed in linux 5.10.46-1 (bookworm)2021
CVE-2021-47259 [HIGH] CVE-2021-47259: linux - In the Linux kernel, the following vulnerability has been resolved: NFS: Fix us...
In the Linux kernel, the following vulnerability has been resolved: NFS: Fix use-after-free in nfs4_init_client() KASAN reports a use-after-free when attempting to mount two different exports through two different NICs that belong to the same server. Olga was able to hit this with kernels starting somewhere between 5.7 and 5.10, but I traced the patch that introduced
debian
CVE-2021-3715P3HIGHCVSS 7.8fixed in linux 5.5.17-1 (bookworm)2021
CVE-2021-3715 [HIGH] CVE-2021-3715: linux - A flaw was found in the "Routing decision" classifier in the Linux kernel's Traf...
A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity,
debian
CVE-2023-6817P3HIGHCVSS 7.8fixed in linux 6.1.69-1 (bookworm)2023
CVE-2023-6817 [HIGH] CVE-2023-6817: linux - A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables compon...
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The function nft_pipapo_walk did not skip inactive elements during set walk which could lead double deactivations of PIPAPO (Pile Packet Policies) elements, leading to use-after-free. We recommend upgrading past commit 317eb96850956
debian
CVE-2023-1118P3HIGHCVSS 7.8fixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-1118 [HIGH] CVE-2023-1118: linux - A flaw use after free in the Linux kernel integrated infrared receiver/transceiv...
A flaw use after free in the Linux kernel integrated infrared receiver/transceiver driver was found in the way user detaching rc device. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
Scope: local
bookworm: resolved (fixed in 6.1.20-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.20-
debian
CVE-2023-3611P3HIGHCVSS 7.8fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-3611 [HIGH] CVE-2023-3611: linux - An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq co...
An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. The qfq_change_agg() function in net/sched/sch_qfq.c allows an out-of-bounds write because lmax is updated according to packet sizes without bounds checks. We recommend upgrading past commit 3e337087c3b5805fe0b8a46ba622a962880b5
debian
CVE-2023-3610P3HIGHCVSS 7.8fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-3610 [HIGH] CVE-2023-3610: linux - A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables compon...
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Flaw in the error handling of bound chains causes a use-after-free in the abort path of NFT_MSG_NEWRULE. The vulnerability requires CAP_NET_ADMIN to be triggered. We recommend upgrading past commit 4bedf9eee016286c835e3d8fa981ddece5
debian
CVE-2022-48980P3HIGHCVSS 7.8fixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-48980 [HIGH] CVE-2022-48980: linux - In the Linux kernel, the following vulnerability has been resolved: net: dsa: s...
In the Linux kernel, the following vulnerability has been resolved: net: dsa: sja1105: avoid out of bounds access in sja1105_init_l2_policing() The SJA1105 family has 45 L2 policing table entries (SJA1105_MAX_L2_POLICING_COUNT) and SJA1110 has 110 (SJA1110_MAX_L2_POLICING_COUNT). Keeping the table structure but accounting for the difference in port count (5 in SJA1105
debian
CVE-2025-38585P3HIGHCVSS 7.8fixed in linux 6.16.3-1 (forky)2025
CVE-2025-38585 [HIGH] CVE-2025-38585: linux - In the Linux kernel, the following vulnerability has been resolved: staging: me...
In the Linux kernel, the following vulnerability has been resolved: staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int() When gmin_get_config_var() calls efi.get_variable() and the EFI variable is larger than the expected buffer size, two behaviors combine to create a stack buffer overflow: 1. gmin_get_config_var() does not return the proper error
debian
CVE-2026-23092P3LOWCVSS 7.8fixed in linux 6.18.8-1 (forky)2026
CVE-2026-23092 [HIGH] CVE-2026-23092: linux - In the Linux kernel, the following vulnerability has been resolved: iio: dac: a...
In the Linux kernel, the following vulnerability has been resolved: iio: dac: ad3552r-hs: fix out-of-bound write in ad3552r_hs_write_data_source When simple_write_to_buffer() succeeds, it returns the number of bytes actually copied to the buffer. The code incorrectly uses 'count' as the index for null termination instead of the actual bytes copied. If count exceeds th
debian
CVE-2021-47378P3CRITICALCVSS 9.8fixed in linux 5.14.9-1 (bookworm)2021
CVE-2021-47378 [CRITICAL] CVE-2021-47378: linux - In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: ...
In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: destroy cm id before destroy qp to avoid use after free We should always destroy cm_id before destroy qp to avoid to get cma event after qp was destroyed, which may lead to use after free. In RDMA connection establishment error flow, don't destroy qp in cm event handler.Just report cm_e
debian
CVE-2025-39967P3HIGHCVSS 7.8fixed in linux 6.1.158-1 (bookworm)2025
CVE-2025-39967 [HIGH] CVE-2025-39967: linux - In the Linux kernel, the following vulnerability has been resolved: fbcon: fix ...
In the Linux kernel, the following vulnerability has been resolved: fbcon: fix integer overflow in fbcon_do_set_font Fix integer overflow vulnerabilities in fbcon_do_set_font() where font size calculations could overflow when handling user-controlled font parameters. The vulnerabilities occur when: 1. CALC_FONTSZ(h, pitch, charcount) performs h * pith * charcount mult
debian
CVE-2025-71089P3HIGHCVSS 7.8fixed in linux 6.1.164-1 (bookworm)2025
CVE-2025-71089 [HIGH] CVE-2025-71089: linux - In the Linux kernel, the following vulnerability has been resolved: iommu: disa...
In the Linux kernel, the following vulnerability has been resolved: iommu: disable SVA when CONFIG_X86 is set Patch series "Fix stale IOTLB entries for kernel address space", v7. This proposes a fix for a security vulnerability related to IOMMU Shared Virtual Addressing (SVA). In an SVA context, an IOMMU can cache kernel page table entries. When a kernel page table pa
debian