cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 183 of 632
CVE-2025-39905P4LOWCVSS 7.0fixed in linux 6.16.8-1 (forky)2025
CVE-2025-39905 [HIGH] CVE-2025-39905: linux - In the Linux kernel, the following vulnerability has been resolved: net: phylin... In the Linux kernel, the following vulnerability has been resolved: net: phylink: add lock for serializing concurrent pl->phydev writes with resolver Currently phylink_resolve() protects itself against concurrent phylink_bringup_phy() or phylink_disconnect_phy() calls which modify pl->phydev by relying on pl->state_mutex. The problem is that in phylink_resolve(), pl->
debian
CVE-2020-12464P4MEDIUMCVSS 6.7fixed in linux 5.6.14-1 (bookworm)2020
CVE-2020-12464 [MEDIUM] CVE-2020-12464: linux - usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has... usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925. Scope: local bookworm: resolved (fixed in 5.6.14-1) bullseye: resolved (fixed in 5.6.14-1) forky: resolved (fixed in 5.6.14-1) sid: resolved (fixed in 5.6.14-1) trixie: resolved (fixed in 5.6.14-1)
debian
CVE-2024-36013P4MEDIUMCVSS 6.8fixed in linux 6.8.11-1 (forky)2024
CVE-2024-36013 [MEDIUM] CVE-2024-36013: linux - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ... In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() Extend a critical section to prevent chan from early freeing. Also make the l2cap_connect() return type void. Nothing is using the returned value but it is ugly to return a potentially freed pointer. Making it void will help with backports
debian
CVE-2022-49051P4MEDIUMCVSS 6.8fixed in linux 5.17.6-1 (bookworm)2022
CVE-2022-49051 [MEDIUM] CVE-2022-49051: linux - In the Linux kernel, the following vulnerability has been resolved: net: usb: a... In the Linux kernel, the following vulnerability has been resolved: net: usb: aqc111: Fix out-of-bounds accesses in RX fixup aqc111_rx_fixup() contains several out-of-bounds accesses that can be triggered by a malicious (or defective) USB device, in particular: - The metadata array (desc_offset..desc_offset+2*pkt_count) can be out of bounds, causing OOB reads and (o
debian
CVE-2018-9517P4MEDIUMCVSS 6.7fixed in linux 4.14.2-1 (bookworm)2018
CVE-2018-9517 [MEDIUM] CVE-2018-9517: linux - In pppol2tp_connect, there is possible memory corruption due to a use after free... In pppol2tp_connect, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38159931. Scope: local bookworm: resolved (fixed in 4.14.2-1) bullseye: resolved (fixed in
debian
CVE-2021-42739P4MEDIUMCVSS 6.7fixed in linux 5.14.16-1 (bookworm)2021
CVE-2021-42739 [MEDIUM] CVE-2021-42739: linux - The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow... The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking. Scope: local bookworm: resolved (fixed in 5.14.16-1) bullseye: resolved (fixed in 5.10.84-1) forky: resolved (fixed in 5.14.16-1) sid: resolved (fixed
debian
CVE-2021-3543P4LOWCVSS 6.7fixed in linux 5.10.38-1 (bookworm)2021
CVE-2021-3543 [MEDIUM] CVE-2021-3543: linux - A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in... A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges on the system. Scope: local bookworm: resolved (fixed in 5.10.38-1) bullseye: resolved (fixed in 5.10.38-1) forky:
debian
CVE-2020-35499P4MEDIUMCVSS 6.7fixed in linux 5.10.4-1 (bookworm)2020
CVE-2020-35499 [MEDIUM] CVE-2020-35499: linux - A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be se... A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have a sanity check for a socket connection, when using BT_SNDMTU/BT_RCVMTU for SCO sockets. This could allow a local attacker with a special user privilege to crash the system (DOS) or leak kernel internal information. Sco
debian
CVE-2022-3628P4MEDIUMCVSS 6.6fixed in linux 6.0.8-1 (bookworm)2022
CVE-2022-3628 [MEDIUM] CVE-2022-3628: linux - A buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi dri... A buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi driver. This issue occurs when a user connects to a malicious USB device. This can allow a local user to crash the system or escalate their privileges. Scope: local bookworm: resolved (fixed in 6.0.8-1) bullseye: resolved (fixed in 5.10.158-1) forky: resolved (fixed in 6.0.8-1) sid: resolved
debian
CVE-2024-26586P4MEDIUMCVSS 6.7fixed in linux 6.1.82-1 (bookworm)2024
CVE-2024-26586 [MEDIUM] CVE-2024-26586: linux - In the Linux kernel, the following vulnerability has been resolved: mlxsw: spec... In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix stack corruption When tc filters are first added to a net device, the corresponding local port gets bound to an ACL group in the device. The group contains a list of ACLs. In turn, each ACL points to a different TCAM region where the filters are stored. During forwardin
debian
CVE-2023-2513P4MEDIUMCVSS 6.7fixed in linux 5.19.6-1 (bookworm)2023
CVE-2023-2513 [MEDIUM] CVE-2023-2513: linux - A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem i... A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes. This flaw could allow a privileged local user to cause a system crash or other undefined behaviors. Scope: local bookworm: resolved (fixed in 5.19.6-1) bullseye: resolved (fixed in 5.10.140-1) forky: resolved (fixed in 5.19
debian
CVE-2020-0431P4MEDIUMCVSS 6.7fixed in linux 5.4.13-1 (bookworm)2020
CVE-2020-0431 [MEDIUM] CVE-2020-0431: linux - In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a m... In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-144161459 Scope: local bookworm: resolved (fixed in 5.4.13-1) bullseye
debian
CVE-2019-9456P4MEDIUMCVSS 6.7fixed in linux 4.15.11-1 (bookworm)2019
CVE-2019-9456 [MEDIUM] CVE-2019-9456: linux - In the Android kernel in Pixel C USB monitor driver there is a possible OOB writ... In the Android kernel in Pixel C USB monitor driver there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Scope: local bookworm: resolved (fixed in 4.15.11-1) bullseye: resolved (fixed in 4.15.11-1) forky: resolved (fixed in
debian
CVE-2019-9454P4MEDIUMCVSS 6.7fixed in linux 4.14.17-1 (bookworm)2019
CVE-2019-9454 [MEDIUM] CVE-2019-9454: linux - In the Android kernel in i2c driver there is a possible out of bounds write due ... In the Android kernel in i2c driver there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Scope: local bookworm: resolved (fixed in 4.14.17-1) bullseye: resolved (fixed in 4.14.17-1) forky: resolved (fixed in 4.14.17-1)
debian
CVE-2020-0429P4MEDIUMCVSS 6.7fixed in linux 4.14.2-1 (bookworm)2020
CVE-2020-0429 [MEDIUM] CVE-2020-0429: linux - In l2tp_session_delete and related functions of l2tp_core.c, there is possible m... In l2tp_session_delete and related functions of l2tp_core.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-152735806 Scope: local bookworm: resolved (fixed in 4.14
debian
CVE-2021-0342P4MEDIUMCVSS 6.7fixed in linux 5.7.6-1 (bookworm)2021
CVE-2021-0342 [MEDIUM] CVE-2021-0342: linux - In tun_get_user of tun.c, there is possible memory corruption due to a use after... In tun_get_user of tun.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges required. User interaction is not required for exploitation. Product: Android; Versions: Android kernel; Android ID: A-146554327. Scope: local bookworm: resolved (fixed in 5.7.6-1) bullseye: resolved (
debian
CVE-2021-0941P4MEDIUMCVSS 6.7fixed in linux 5.10.28-1 (bookworm)2021
CVE-2021-0941 [MEDIUM] CVE-2021-0941: linux - In bpf_skb_change_head of filter.c, there is a possible out of bounds read due t... In bpf_skb_change_head of filter.c, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154177719References: Upstream kernel Scope: local bookworm: resolved (fixed in
debian
CVE-2021-39656P4MEDIUMCVSS 6.7fixed in linux 5.10.24-1 (bookworm)2021
CVE-2021-39656 [MEDIUM] CVE-2021-39656: linux - In __configfs_open_file of file.c, there is a possible use-after-free due to imp... In __configfs_open_file of file.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174049066References: Upstream kernel Scope: local bookworm: resolve
debian
CVE-2022-3643P4MEDIUMCVSS 6.5fixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-3643 [MEDIUM] CVE-2022-3643: linux - Guests can trigger NIC interface reset/abort/crash via netback It is possible fo... Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appears to be an (unwritten?) assumption in the rest of the Linux network stack that packet protocol headers are all contained within the linear section of the SK
debian
CVE-2023-30772P4LOWCVSS 6.4fixed in linux 6.1.25-1 (bookworm)2023
CVE-2023-30772 [MEDIUM] CVE-2023-30772: linux - The Linux kernel before 6.2.9 has a race condition and resultant use-after-free ... The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/power/supply/da9150-charger.c if a physically proximate attacker unplugs a device. Scope: local bookworm: resolved (fixed in 6.1.25-1) bullseye: resolved (fixed in 5.10.178-1) forky: resolved (fixed in 6.1.25-1) sid: resolved (fixed in 6.1.25-1) trixie: resolved (fixed in 6.1.
debian
Debian Linux vulnerabilities | cvebase