cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 190 of 632
CVE-2022-0487P4LOWCVSS 5.5fixed in linux 5.16.10-1 (bookworm)2022
CVE-2022-0487 [MEDIUM] CVE-2022-0487: linux - A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/me... A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions prior to 5.14 rc1. Scope: local bookworm: resolved (fixed in 5.16.10-1) bullseye: resolved (fixed in 5.10.103
debian
CVE-2013-7470P4MEDIUMCVSS 6.6fixed in linux 3.11.7-1 (bookworm)2013
CVE-2013-7470 [MEDIUM] CVE-2013-7470: linux - cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7,... cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310. Scope: local bookworm: resolved (fixed in 3.11.7-1) bullseye: resolved (fixed in 3.11.7-1) forky: resolved (
debian
CVE-2014-5206P4HIGHCVSS 7.2fixed in linux 3.16.2-1 (bookworm)2014
CVE-2014-5206 [HIGH] CVE-2014-5206: linux - The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 doe... The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the MNT_LOCK_READONLY bit across a remount of a bind mount, which allows local users to bypass an intended read-only restriction and defeat certain sandbox protection mechanisms via a "mount -o remount" command within a user namespace. Scope: local bookworm: resolved (fixed in
debian
CVE-2016-0774P4HIGHCVSS 7.2fixed in linux 3.16.2-2 (bookworm)2016
CVE-2016-0774 [HIGH] CVE-2016-0774: linux - The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain L... The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain Linux kernel backport in the linux package before 3.2.73-2+deb7u3 on Debian wheezy and the kernel package before 3.10.0-229.26.2 on Red Hat Enterprise Linux (RHEL) 7.1 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows
debian
CVE-2025-68254P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-68254 CVE-2025-68254: linux - In the Linux kernel, the following vulnerability has been resolved: staging: rt... In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE parsing The Extended Supported Rates (ESR) IE handling in OnBeacon accessed *(p + 1 + ielen) and *(p + 2 + ielen) without verifying that these offsets lie within the received frame buffer. A malformed beacon with an ESR IE positioned at the end of
debian
CVE-2025-40004P4LOWfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40004 [LOW] CVE-2025-40004: linux - In the Linux kernel, the following vulnerability has been resolved: net/9p: Fix... In the Linux kernel, the following vulnerability has been resolved: net/9p: Fix buffer overflow in USB transport layer A buffer overflow vulnerability exists in the USB 9pfs transport layer where inconsistent size validation between packet header parsing and actual data copying allows a malicious USB host to overflow heap buffers. The issue occurs because: - usb9pfs_rx
debian
CVE-2020-11668P4HIGHCVSS 7.1fixed in linux 5.5.17-1 (bookworm)2020
CVE-2020-11668 [HIGH] CVE-2020-11668: linux - In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the... In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770. Scope: local bookworm: resolved (fixed in 5.5.17-1) bullseye: resolved (fixed in 5.5.17-1) forky: resolved (fixed in 5.5.17-1) sid: resolved (fixed in 5.5.17-1) trixie: resolved (fixed in 5.5.17-1)
debian
CVE-2023-54057P4UNKNOWNfixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-54057 CVE-2023-54057: linux - In the Linux kernel, the following vulnerability has been resolved: iommu/amd: ... In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Add a length limitation for the ivrs_acpihid command-line parameter The 'acpiid' buffer in the parse_ivrs_acpihid function may overflow, because the string specifier in the format string sscanf() has no width limitation. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) w
debian
CVE-2023-53717P4UNKNOWNfixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-53717 CVE-2023-53717: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k... In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: Fix potential stack-out-of-bounds write in ath9k_wmi_rsp_callback() Fix a stack-out-of-bounds write that occurs in a WMI response callback function that is called after a timeout occurs in ath9k_wmi_cmd(). The callback writes to wmi->cmd_rsp_buf, a stack-allocated buffer that could no longer be
debian
CVE-2025-40242P4UNKNOWNfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40242 CVE-2025-40242: linux - In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix u... In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix unlikely race in gdlm_put_lock In gdlm_put_lock(), there is a small window of time in which the DFL_UNMOUNT flag has been set but the lockspace hasn't been released, yet. In that window, dlm may still call gdlm_ast() and gdlm_bast(). To prevent it from dereferencing freed glock objects, only free t
debian
CVE-2026-23315P4UNKNOWNfixed in linux 6.19.8-1 (forky)2026
CVE-2026-23315 CVE-2026-23315: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:... In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() Check frame length before accessing the mgmt fields in mt76_connac2_mac_write_txwi_80211 in order to avoid a possible oob access. [fix check to also cover mgmt->u.action.u.addba_req.capab, correct Fixes tag] Scope: local bookworm: ope
debian
CVE-2025-68313P4LOWfixed in linux 6.17.8-1 (forky)2025
CVE-2025-68313 [LOW] CVE-2025-68313: linux - In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD... In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Add RDSEED fix for Zen5 There's an issue with RDSEED's 16-bit and 32-bit register output variants on Zen5 which return a random value of 0 "at a rate inconsistent with randomness while incorrectly signaling success (CF=1)". Search the web for AMD-SB-7055 for more detail. Add a fix glue whi
debian
CVE-2026-23388P4UNKNOWNfixed in linux 6.19.8-1 (forky)2026
CVE-2026-23388 CVE-2026-23388: linux - In the Linux kernel, the following vulnerability has been resolved: Squashfs: c... In the Linux kernel, the following vulnerability has been resolved: Squashfs: check metadata block offset is within range Syzkaller reports a "general protection fault in squashfs_copy_data" This is ultimately caused by a corrupted index look-up table, which produces a negative metadata block offset. This is subsequently passed to squashfs_copy_data (via squashfs_read_metada
debian
CVE-2017-13305P4HIGHCVSS 7.1fixed in linux 4.12.6-1 (bookworm)2017
CVE-2017-13305 [HIGH] CVE-2017-13305: linux - A information disclosure vulnerability in the Upstream kernel encrypted-keys. Pr... A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974. Scope: local bookworm: resolved (fixed in 4.12.6-1) bullseye: resolved (fixed in 4.12.6-1) forky: resolved (fixed in 4.12.6-1) sid: resolved (fixed in 4.12.6-1) trixie: resolved (fixed in 4.12.6-1)
debian
CVE-2021-47327P4HIGHCVSS 7.1fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-47327 [HIGH] CVE-2021-47327: linux - In the Linux kernel, the following vulnerability has been resolved: iommu/arm-s... In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu: Fix arm_smmu_device refcount leak when arm_smmu_rpm_get fails arm_smmu_rpm_get() invokes pm_runtime_get_sync(), which increases the refcount of the "smmu" even though the return value is less than 0. The reference counting issue happens in some error handling paths of arm_smmu_rpm_get(
debian
CVE-2023-52640P4HIGHCVSS 7.1fixed in linux 6.1.82-1 (bookworm)2023
CVE-2023-52640 [HIGH] CVE-2023-52640: linux - In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: F... In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix oob in ntfs_listxattr The length of name cannot exceed the space occupied by ea. Scope: local bookworm: resolved (fixed in 6.1.82-1) bullseye: resolved forky: resolved (fixed in 6.7.7-1) sid: resolved (fixed in 6.7.7-1) trixie: resolved (fixed in 6.7.7-1)
debian
CVE-2021-47624P4HIGHCVSS 7.1fixed in linux 5.16.10-1 (bookworm)2021
CVE-2021-47624 [HIGH] CVE-2021-47624: linux - In the Linux kernel, the following vulnerability has been resolved: net/sunrpc:... In the Linux kernel, the following vulnerability has been resolved: net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change The refcount leak issues take place in an error handling path. When the 3rd argument buf doesn't match with "offline", "online" or "remove", the function simply returns -EINVAL and forgets to decrease the reference count of a rpc_xpr
debian
CVE-2024-56597P4HIGHCVSS 7.1fixed in linux 6.1.123-1 (bookworm)2024
CVE-2024-56597 [HIGH] CVE-2024-56597: linux - In the Linux kernel, the following vulnerability has been resolved: jfs: fix sh... In the Linux kernel, the following vulnerability has been resolved: jfs: fix shift-out-of-bounds in dbSplit When dmt_budmin is less than zero, it causes errors in the later stages. Added a check to return an error beforehand in dbAllocCtl itself. Scope: local bookworm: resolved (fixed in 6.1.123-1) bullseye: resolved (fixed in 5.10.234-1) forky: resolved (fixed in 6.1
debian
CVE-2023-52479P4HIGHCVSS 7.1fixed in linux 6.1.64-1 (bookworm)2023
CVE-2023-52479 [HIGH] CVE-2023-52479: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ... In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix uaf in smb20_oplock_break_ack drop reference after use opinfo. Scope: local bookworm: resolved (fixed in 6.1.64-1) bullseye: resolved forky: resolved (fixed in 6.5.8-1) sid: resolved (fixed in 6.5.8-1) trixie: resolved (fixed in 6.5.8-1)
debian
CVE-2024-49862P4LOWCVSS 7.1fixed in linux 6.11.2-1 (forky)2024
CVE-2024-49862 [HIGH] CVE-2024-49862: linux - In the Linux kernel, the following vulnerability has been resolved: powercap: i... In the Linux kernel, the following vulnerability has been resolved: powercap: intel_rapl: Fix off by one in get_rpi() The rp->priv->rpi array is either rpi_msr or rpi_tpmi which have NR_RAPL_PRIMITIVES number of elements. Thus the > needs to be >= to prevent an off by one access. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 6.11.2-1) si
debian
Debian Linux vulnerabilities | cvebase