cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 175 of 632
CVE-2023-53254P4HIGHCVSS 7.1fixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-53254 [HIGH] CVE-2023-53254: linux - In the Linux kernel, the following vulnerability has been resolved: cacheinfo: ... In the Linux kernel, the following vulnerability has been resolved: cacheinfo: Fix shared_cpu_map to handle shared caches at different levels The cacheinfo sets up the shared_cpu_map by checking whether the caches with the same index are shared between CPUs. However, this will trigger slab-out-of-bounds access if the CPUs do not have the same cache hierarchy. Another
debian
CVE-2023-53575P4LOWCVSS 7.1fixed in linux 6.4.11-1 (forky)2023
CVE-2023-53575 [HIGH] CVE-2023-53575: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwi... In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix potential array out of bounds access Account for IWL_SEC_WEP_KEY_OFFSET when needed while verifying key_len size in iwl_mvm_sec_key_add(). Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 6.4.11-1) sid: resolved (fixed in 6.4.11-1) trixie: resolved (
debian
CVE-2017-17053P4HIGHCVSS 7.0fixed in linux 4.12.12-1 (bookworm)2017
CVE-2017-17053 [HIGH] CVE-2017-17053: linux - The init_new_context function in arch/x86/include/asm/mmu_context.h in the Linux... The init_new_context function in arch/x86/include/asm/mmu_context.h in the Linux kernel before 4.12.10 does not correctly handle errors from LDT table allocation when forking a new process, allowing a local attacker to achieve a use-after-free or possibly have unspecified other impact by running a specially crafted program. This vulnerability only affected kernels bui
debian
CVE-2026-23204P4HIGHCVSS 7.1fixed in linux 6.18.10-1 (forky)2026
CVE-2026-23204 [HIGH] CVE-2026-23204: linux - In the Linux kernel, the following vulnerability has been resolved: net/sched: ... In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_u32: use skb_header_pointer_careful() skb_header_pointer() does not fully validate negative @offset values. Use skb_header_pointer_careful() instead. GangMin Kim provided a report and a repro fooling u32_classify(): BUG: KASAN: slab-out-of-bounds in u32_classify+0x1180/0x11b0 net/sched/
debian
CVE-2016-10906P4HIGHCVSS 7.0fixed in linux 4.5.1-1 (bookworm)2016
CVE-2016-10906 [HIGH] CVE-2016-10906: linux - An issue was discovered in drivers/net/ethernet/arc/emac_main.c in the Linux ker... An issue was discovered in drivers/net/ethernet/arc/emac_main.c in the Linux kernel before 4.5. A use-after-free is caused by a race condition between the functions arc_emac_tx and arc_emac_tx_clean. Scope: local bookworm: resolved (fixed in 4.5.1-1) bullseye: resolved (fixed in 4.5.1-1) forky: resolved (fixed in 4.5.1-1) sid: resolved (fixed in 4.5.1-1) trixie: resol
debian
CVE-2025-71231P4LOWCVSS 7.1fixed in linux 6.18.12-1 (forky)2025
CVE-2025-71231 [HIGH] CVE-2025-71231: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: iaa... In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - Fix out-of-bounds index in find_empty_iaa_compression_mode The local variable 'i' is initialized with -EINVAL, but the for loop immediately overwrites it and -EINVAL is never returned. If no empty compression mode can be found, the function would return the out-of-bounds index IAA_COMP_M
debian
CVE-2019-11486P4HIGHCVSS 7.0fixed in linux 4.19.37-1 (bookworm)2019
CVE-2019-11486 [HIGH] CVE-2019-11486: linux - The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux k... The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions. Scope: local bookworm: resolved (fixed in 4.19.37-1) bullseye: resolved (fixed in 4.19.37-1) forky: resolved (fixed in 4.19.37-1) sid: resolved (fixed in 4.19.37-1) trixie: resolved (fixed in 4.19.37-1)
debian
CVE-2025-37776P4HIGHCVSS 7.0fixed in linux 6.12.25-1 (forky)2025
CVE-2025-37776 [HIGH] CVE-2025-37776: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ... In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_break_all_levII_oplock() There is a room in smb_break_all_levII_oplock that can cause racy issues when unlocking in the middle of the loop. This patch use read lock to protect whole loop. Scope: local bookworm: open bullseye: resolved forky: resolved (fixed in 6.12.25-
debian
CVE-2021-40490P4HIGHCVSS 7.0fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-40490 [HIGH] CVE-2021-40490: linux - A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.... A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13. Scope: local bookworm: resolved (fixed in 5.14.6-1) bullseye: resolved (fixed in 5.10.46-5) forky: resolved (fixed in 5.14.6-1) sid: resolved (fixed in 5.14.6-1) trixie: resolved (fixed in 5.14.6-1)
debian
CVE-2024-41040P4HIGHCVSS 7.0fixed in linux 6.1.106-1 (bookworm)2024
CVE-2024-41040 [HIGH] CVE-2024-41040: linux - In the Linux kernel, the following vulnerability has been resolved: net/sched: ... In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix UAF when resolving a clash KASAN reports the following UAF: BUG: KASAN: slab-use-after-free in tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct] Read of size 1 at addr ffff888c07603600 by task handler130/6469 Call Trace: dump_stack_lvl+0x48/0x70 print_address_description.constprop.0+0
debian
CVE-2024-50286P4HIGHCVSS 7.0fixed in linux 6.1.119-1 (bookworm)2024
CVE-2024-50286 [HIGH] CVE-2024-50286: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ... In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-use-after-free in ksmbd_smb2_session_create There is a race condition between ksmbd_smb2_session_create and ksmbd_expire_session. This patch add missing sessions_table_lock while adding/deleting session from global session table. Scope: local bookworm: resolved (fixed in 6.1.119-1) bul
debian
CVE-2024-41049P4HIGHCVSS 7.0fixed in linux 6.1.106-1 (bookworm)2024
CVE-2024-41049 [HIGH] CVE-2024-41049: linux - In the Linux kernel, the following vulnerability has been resolved: filelock: f... In the Linux kernel, the following vulnerability has been resolved: filelock: fix potential use-after-free in posix_lock_inode Light Hsieh reported a KASAN UAF warning in trace_posix_lock_inode(). The request pointer had been changed earlier to point to a lock entry that was added to the inode's list. However, before the tracepoint could fire, another task raced in an
debian
CVE-2024-26654P4HIGHCVSS 7.0fixed in linux 6.1.85-1 (bookworm)2024
CVE-2024-26654 [HIGH] CVE-2024-26654: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: sh: a... In the Linux kernel, the following vulnerability has been resolved: ALSA: sh: aica: reorder cleanup operations to avoid UAF bugs The dreamcastcard->timer could schedule the spu_dma_work and the spu_dma_work could also arm the dreamcastcard->timer. When the snd_pcm_substream is closing, the aica_channel will be deallocated. But it could still be dereferenced in the wor
debian
CVE-2023-4389P4HIGHCVSS 7.0fixed in linux 5.17.6-1 (bookworm)2023
CVE-2023-4389 [HIGH] CVE-2023-4389: linux - A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesy... A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double decrement of the reference count. This issue may allow a local attacker with user privilege to crash the system or may lead to leaked internal kernel information. Scope: local bookworm: resolved (fixed in 5.17.6-1) bullseye: resolved (fixed in 5.10.11
debian
CVE-2022-45919P4HIGHCVSS 7.0fixed in linux 6.1.37-1 (bookworm)2022
CVE-2022-45919 [HIGH] CVE-2022-45919: linux - An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb... An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb-core/dvb_ca_en50221.c, a use-after-free can occur is there is a disconnect after an open, because of the lack of a wait_event. Scope: local bookworm: resolved (fixed in 6.1.37-1) bullseye: resolved (fixed in 5.10.191-1) forky: resolved (fixed in 6.3.7-1) sid: resolved (fixed in 6.3.7-1) t
debian
CVE-2022-48872P4HIGHCVSS 7.0fixed in linux 6.1.8-1 (bookworm)2022
CVE-2022-48872 [HIGH] CVE-2022-48872: linux - In the Linux kernel, the following vulnerability has been resolved: misc: fastr... In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix use-after-free race condition for maps It is possible that in between calling fastrpc_map_get() until map->fl->lock is taken in fastrpc_free_map(), another thread can call fastrpc_map_lookup() and get a reference to a map that is about to be deleted. Rewrite fastrpc_map_get() to onl
debian
CVE-2024-50275P4HIGHCVSS 7.0fixed in linux 6.1.123-1 (bookworm)2024
CVE-2024-50275 [HIGH] CVE-2024-50275: linux - In the Linux kernel, the following vulnerability has been resolved: arm64/sve: ... In the Linux kernel, the following vulnerability has been resolved: arm64/sve: Discard stale CPU state when handling SVE traps The logic for handling SVE traps manipulates saved FPSIMD/SVE state incorrectly, and a race with preemption can result in a task having TIF_SVE set and TIF_FOREIGN_FPSTATE clear even though the live CPU state is stale (e.g. with SVE traps enab
debian
CVE-2024-38561P4HIGHCVSS 7.0fixed in linux 6.1.94-1 (bookworm)2024
CVE-2024-38561 [HIGH] CVE-2024-38561: linux - In the Linux kernel, the following vulnerability has been resolved: kunit: Fix ... In the Linux kernel, the following vulnerability has been resolved: kunit: Fix kthread reference There is a race condition when a kthread finishes after the deadline and before the call to kthread_stop(), which may lead to use after free. Scope: local bookworm: resolved (fixed in 6.1.94-1) bullseye: resolved forky: resolved (fixed in 6.8.12-1) sid: resolved (fixed in
debian
CVE-2024-43883P4HIGHCVSS 7.0fixed in linux 6.1.106-1 (bookworm)2024
CVE-2024-43883 [HIGH] CVE-2024-43883: linux - In the Linux kernel, the following vulnerability has been resolved: usb: vhci-h... In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places the driver carries stale pointers to references that can still be used. Make sure that does not happen. This strictly speaking closes ZDI-CAN-22273, though there may be similar races in the driver. Scope: local book
debian
CVE-2021-47088P4HIGHCVSS 7.0fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-47088 [HIGH] CVE-2021-47088: linux - In the Linux kernel, the following vulnerability has been resolved: mm/damon/db... In the Linux kernel, the following vulnerability has been resolved: mm/damon/dbgfs: protect targets destructions with kdamond_lock DAMON debugfs interface iterates current monitoring targets in 'dbgfs_target_ids_read()' while holding the corresponding 'kdamond_lock'. However, it also destructs the monitoring targets in 'dbgfs_before_terminate()' without holding the lo
debian
Debian Linux vulnerabilities | cvebase