Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 178 of 632
CVE-2018-17972P4MEDIUMCVSS 5.5fixed in linux 4.18.20-1 (bookworm)2018
CVE-2018-17972 [MEDIUM] CVE-2018-17972: linux - An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the ...
An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does not ensure that only root may inspect the kernel stack of an arbitrary task, allowing a local attacker to exploit racy stack unwinding and leak kernel task stack contents.
Scope: local
bookworm: resolved (fixed in 4.18.20-1)
bullseye: resolved (fixed
debian
CVE-2019-11135P4MEDIUMCVSS 6.5fixed in intel-microcode 3.20191112.1 (bookworm)2019
CVE-2019-11135 [MEDIUM] CVE-2019-11135: intel-microcode - TSX Asynchronous Abort condition on some CPUs utilizing speculative execution ma...
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
Scope: local
bookworm: resolved (fixed in 3.20191112.1)
bullseye: resolved (fixed in 3.20191112.1)
forky: resolved (fixed in 3.20191112.1)
sid: resolved (fixed in 3.
debian
CVE-2017-16914P4MEDIUMCVSS 5.9fixed in linux 4.14.12-1 (bookworm)2017
CVE-2017-16914 [MEDIUM] CVE-2017-16914: linux - The "stub_send_ret_submit()" function (drivers/usb/usbip/stub_tx.c) in the Linux...
The "stub_send_ret_submit()" function (drivers/usb/usbip/stub_tx.c) in the Linux Kernel before version 4.14.8, 4.9.71, 4.1.49, and 4.4.107 allows attackers to cause a denial of service (NULL pointer dereference) via a specially crafted USB over IP packet.
Scope: local
bookworm: resolved (fixed in 4.14.12-1)
bullseye: resolved (fixed in 4.14.12-1)
forky: resolved (fi
debian
CVE-2017-16912P4MEDIUMCVSS 5.9fixed in linux 4.14.12-1 (bookworm)2017
CVE-2017-16912 [MEDIUM] CVE-2017-16912: linux - The "get_pipe()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel befo...
The "get_pipe()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 allows attackers to cause a denial of service (out-of-bounds read) via a specially crafted USB over IP packet.
Scope: local
bookworm: resolved (fixed in 4.14.12-1)
bullseye: resolved (fixed in 4.14.12-1)
forky: resolved (fixed in 4.14.12-1)
sid: res
debian
CVE-2013-0913P4HIGHCVSS 7.2fixed in linux 3.2.41-2 (bookworm)2013
CVE-2013-0913 [HIGH] CVE-2013-0913: linux - Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 drive...
Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted appli
debian
CVE-2020-24490P4MEDIUMCVSS 6.5fixed in linux 5.7.17-1 (bookworm)2020
CVE-2020-24490 [MEDIUM] CVE-2020-24490: linux - Improper buffer restrictions in BlueZ may allow an unauthenticated user to poten...
Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access. This affects all Linux kernel versions that support BlueZ.
Scope: local
bookworm: resolved (fixed in 5.7.17-1)
bullseye: resolved (fixed in 5.7.17-1)
forky: resolved (fixed in 5.7.17-1)
sid: resolved (fixed in 5.7.17-1)
trixie: resolve
debian
CVE-2015-0274P4HIGHCVSS 7.2fixed in linux 3.11.5-1 (bookworm)2015
CVE-2015-0274 [HIGH] CVE-2015-0274: linux - The XFS implementation in the Linux kernel before 3.15 improperly uses an old si...
The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges by leveraging XFS filesystem access.
Scope: local
bookworm: resolved (fixed in 3.11.5-1)
bullseye: resolved (fixed in 3.11
debian
CVE-2013-2206P4MEDIUMCVSS 5.4fixed in linux 3.9.4-1 (bookworm)2013
CVE-2013-2206 [MEDIUM] CVE-2013-2206: linux - The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP imp...
The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via cr
debian
CVE-2025-21946P4HIGHCVSS 7.1fixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-21946 [HIGH] CVE-2025-21946: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds in parse_sec_desc() If osidoffset, gsidoffset and dacloffset could be greater than smb_ntsd struct size. If it is smaller, It could cause slab-out-of-bounds. And when validating sid, It need to check it included subauth array size.
Scope: local
bookworm: resolved (fixed in 6.1
debian
CVE-2017-2584P4HIGHCVSS 7.1fixed in linux 4.9.6-1 (bookworm)2017
CVE-2017-2584 [HIGH] CVE-2017-2584: linux - arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3 allows local users to o...
arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free) via a crafted application that leverages instruction emulation for fxrstor, fxsave, sgdt, and sidt.
Scope: local
bookworm: resolved (fixed in 4.9.6-1)
bullseye: resolved (fixed in 4.9.6-1)
forky: res
debian
CVE-2025-40088P4UNKNOWNfixed in linux 6.1.158-1 (bookworm)2025
CVE-2025-40088 CVE-2025-40088: linux - In the Linux kernel, the following vulnerability has been resolved: hfsplus: fi...
In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp() The hfsplus_strcasecmp() logic can trigger the issue: [ 117.317703][ T9855] ================================================================== [ 117.318353][ T9855] BUG: KASAN: slab-out-of-bounds in hfsplus_strcasecmp+0x1bc/0x490 [ 117.318991][ T98
debian
CVE-2026-23318P4UNKNOWNfixed in linux 6.19.8-1 (forky)2026
CVE-2026-23318 CVE-2026-23318: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-a...
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Use correct version for UAC3 header validation The entry of the validators table for UAC3 AC header descriptor is defined with the wrong protocol version UAC_VERSION_2, while it should have been UAC_VERSION_3. This results in the validator never matching for actual UAC3 devices (protocol ==
debian
CVE-2025-68785P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-68785 CVE-2025-68785: linux - In the Linux kernel, the following vulnerability has been resolved: net: openvs...
In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix middle attribute validation in push_nsh() action The push_nsh() action structure looks like this: OVS_ACTION_ATTR_PUSH_NSH(OVS_KEY_ATTR_NSH(OVS_NSH_KEY_ATTR_BASE,...)) The outermost OVS_ACTION_ATTR_PUSH_NSH attribute is OK'ed by the nla_for_each_nested() inside __ovs_nla_copy_actions().
debian
CVE-2026-23327P4UNKNOWNfixed in linux 6.19.8-1 (forky)2026
CVE-2026-23327 CVE-2026-23327: linux - In the Linux kernel, the following vulnerability has been resolved: cxl/mbox: v...
In the Linux kernel, the following vulnerability has been resolved: cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() cxl_payload_from_user_allowed() casts and dereferences the input payload without first verifying its size. When a raw mailbox command is sent with an undersized payload (ie: 1 byte for CXL_MBOX_OP_CLEAR_LOG, which ex
debian
CVE-2016-3713P4HIGHCVSS 7.1fixed in linux 4.5.4-1 (bookworm)2016
CVE-2016-3713 [HIGH] CVE-2016-3713: linux - The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4....
The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write to the kvm_arch_vcpu data structure, and consequently obtain sensitive information or cause a denial of service (system crash), via a crafted ioctl call.
Scope: local
bookworm: resolved (fixed in 4.5.4-1)
bullseye: resolved
debian
CVE-2019-19769P4MEDIUMCVSS 6.7fixed in linux 5.5.13-1 (bookworm)2019
CVE-2019-19769 [MEDIUM] CVE-2019-19769: linux - In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_l...
In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h).
Scope: local
bookworm: resolved (fixed in 5.5.13-1)
bullseye: resolved (fixed in 5.5.13-1)
forky: resolved (fixed in 5.5.13-1)
sid: resolved (fixed in 5.5.13-1)
trixie: resolved (fixed in 5.5.13-1)
debian
CVE-2019-3459P4MEDIUMCVSS 6.5fixed in linux 4.19.37-1 (bookworm)2019
CVE-2019-3459 [MEDIUM] CVE-2019-3459: linux - A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in...
A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.
Scope: local
bookworm: resolved (fixed in 4.19.37-1)
bullseye: resolved (fixed in 4.19.37-1)
forky: resolved (fixed in 4.19.37-1)
sid: resolved (fixed in 4.19.37-1)
trixie: resolved (fixed in 4.19.37-1)
debian
CVE-2022-1671P4HIGHCVSS 7.1fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-1671 [HIGH] CVE-2022-1671: linux - A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/serve...
A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw allows a local attacker to crash the system or leak internal kernel information.
Scope: local
bookworm: resolved (fixed in 5.17.3-1)
bullseye: resolved
forky: resolved (fixed in 5.17.3-1)
sid: resolved (fixed in 5.17.3-1)
trixie: resolved (fixed in 5.17
debian
CVE-2024-27029P4LOWCVSS 7.1fixed in linux 6.7.12-1 (forky)2024
CVE-2024-27029 [HIGH] CVE-2024-27029: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu:...
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix mmhub client id out-of-bounds access Properly handle cid 0x140.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.7.12-1)
sid: resolved (fixed in 6.7.12-1)
trixie: resolved (fixed in 6.7.12-1)
debian
CVE-2021-46952P4HIGHCVSS 7.1fixed in linux 5.10.38-1 (bookworm)2021
CVE-2021-46952 [HIGH] CVE-2021-46952: linux - In the Linux kernel, the following vulnerability has been resolved: NFS: fs_con...
In the Linux kernel, the following vulnerability has been resolved: NFS: fs_context: validate UDP retrans to prevent shift out-of-bounds Fix shift out-of-bounds in xprt_calc_majortimeo(). This is caused by a garbage timeout (retrans) mount option being passed to nfs mount, in this case from syzkaller. If the protocol is XPRT_TRANSPORT_UDP, then 'retrans' is a shift va
debian