Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 195 of 632
CVE-2013-4343P4MEDIUMCVSS 6.9fixed in linux 3.11.5-1 (bookworm)2013
CVE-2013-4343 [MEDIUM] CVE-2013-4343: linux - Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3....
Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_ADMIN capability and providing an invalid tuntap interface name in a TUNSETIFF ioctl call.
Scope: local
bookworm: resolved (fixed in 3.11.5-1)
bullseye: resolved (fixed in 3.11.5-1)
forky: resolved (fixed in 3.11.5-1)
sid
debian
CVE-2012-3552P4MEDIUMCVSS 5.9fixed in linux 3.0-1 (bookworm)2012
CVE-2012-3552 [MEDIUM] CVE-2012-3552: linux - Race condition in the IP implementation in the Linux kernel before 3.0 might all...
Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system crash) by sending packets to an application that sets socket options during the handling of network traffic.
Scope: local
bookworm: resolved (fixed in 3.0-1)
bullseye: resolved (fixed in 3.0-1)
forky: resolved (fi
debian
CVE-2019-19531P4MEDIUMCVSS 6.8fixed in linux 5.2.9-1 (bookworm)2019
CVE-2019-19531 [MEDIUM] CVE-2019-19531: linux - In the Linux kernel before 5.2.9, there is a use-after-free bug that can be caus...
In the Linux kernel before 5.2.9, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/yurex.c driver, aka CID-fc05481b2fca.
Scope: local
bookworm: resolved (fixed in 5.2.9-1)
bullseye: resolved (fixed in 5.2.9-1)
forky: resolved (fixed in 5.2.9-1)
sid: resolved (fixed in 5.2.9-1)
trixie: resolved (fixed in 5.2.9-1)
debian
CVE-2016-0723P4MEDIUMCVSS 6.8fixed in linux 4.3.3-6 (bookworm)2016
CVE-2016-0723 [MEDIUM] CVE-2016-0723: linux - Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux ke...
Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel through 4.4.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free and system crash) by making a TIOCGETD ioctl call during processing of a TIOCSETD ioctl call.
Scope: local
bookworm: resolved (fixed in 4.3.3-6)
bullseye: r
debian
CVE-2024-0340P4MEDIUMCVSS 4.4fixed in linux 6.1.82-1 (bookworm)2024
CVE-2024-0340 [MEDIUM] CVE-2024-0340: linux - A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux...
A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This issue can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net dev
debian
CVE-2024-35843P4MEDIUMCVSS 6.8fixed in linux 6.8.9-1 (forky)2024
CVE-2024-35843 [MEDIUM] CVE-2024-35843: linux - In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d:...
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Use device rbtree in iopf reporting path The existing I/O page fault handler currently locates the PCI device by calling pci_get_domain_bus_and_slot(). This function searches the list of all PCI devices until the desired device is found. To improve lookup efficiency, replace it with devi
debian
CVE-2019-6133P4MEDIUMCVSS 6.7fixed in linux 4.19.16-1 (bookworm)2019
CVE-2019-6133 [MEDIUM] CVE-2019-6133: linux - In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be by...
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.
Scope: local
bookworm: resolved (fixed in 4.19.16-1)
bullseye: resolved (fixed in 4.19.16-1)
forky
debian
CVE-2017-17558P4MEDIUMCVSS 6.6fixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-17558 [MEDIUM] CVE-2017-17558: linux - The usb_destroy_configuration function in drivers/usb/core/config.c in the USB c...
The usb_destroy_configuration function in drivers/usb/core/config.c in the USB core subsystem in the Linux kernel through 4.14.5 does not consider the maximum number of configurations and interfaces before attempting to release resources, which allows local users to cause a denial of service (out-of-bounds write access) or possibly have unspecified other impact via
debian
CVE-2023-0459P4MEDIUMCVSS 6.5fixed in linux 6.1.15-1 (bookworm)2023
CVE-2023-0459 [MEDIUM] CVE-2023-0459: linux - Copy_from_user on 64-bit versions of the Linux kernel does not implement the __u...
Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to bypass the "access_ok" check and pass a kernel pointer to copy_from_user(). This would allow an attacker to leak information. We recommend upgrading beyond commit 74e19ef0ff8061ef55957c3abd71614ef0f42f47
Scope: local
bookworm: resolved (fixed in 6.1.1
debian
CVE-2013-1798P4MEDIUMCVSS 6.2fixed in linux 3.2.41-2 (bookworm)2013
CVE-2013-1798 [MEDIUM] CVE-2013-1798: linux - The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel throu...
The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel through 3.8.4 does not properly handle a certain combination of invalid IOAPIC_REG_SELECT and IOAPIC_REG_WINDOW operations, which allows guest OS users to obtain sensitive information from host OS memory or cause a denial of service (host OS OOPS) via a crafted application.
Scope: local
bookwor
debian
CVE-2020-26541P4MEDIUMCVSS 6.5fixed in linux 5.14.6-1 (bookworm)2020
CVE-2020-26541 [MEDIUM] CVE-2020-26541: linux - The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbid...
The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: reso
debian
CVE-2018-15572P4MEDIUMCVSS 6.5fixed in linux 4.17.15-1 (bookworm)2018
CVE-2018-15572 [MEDIUM] CVE-2018-15572: linux - The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the L...
The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4.18.1 does not always fill RSB upon a context switch, which makes it easier for attackers to conduct userspace-userspace spectreRSB attacks.
Scope: local
bookworm: resolved (fixed in 4.17.15-1)
bullseye: resolved (fixed in 4.17.15-1)
forky: resolved (fixed in 4.17.15-
debian
CVE-2022-0001P4MEDIUMCVSS 6.5fixed in linux 5.16.12-1 (bookworm)2022
CVE-2022-0001 [MEDIUM] CVE-2022-0001: linux - Non-transparent sharing of branch predictor selectors between contexts in some I...
Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 5.16.12-1)
bullseye: resolved (fixed in 5.10.103-1)
forky: resolved (fixed in 5.16.12-1)
sid: resolved (fixed in 5.16.12-1)
trixie: resol
debian
CVE-2023-52819P4MEDIUMCVSS 6.6fixed in linux 6.1.64-1 (bookworm)2023
CVE-2023-52819 [MEDIUM] CVE-2023-52819: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fi...
In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix UBSAN array-index-out-of-bounds for Polaris and Tonga For pptable structs that use flexible array sizes, use flexible arrays.
Scope: local
bookworm: resolved (fixed in 6.1.64-1)
bullseye: resolved (fixed in 5.10.205-1)
forky: resolved (fixed in 6.6.8-1)
sid: resolved (fixed in 6.6.8-1)
debian
CVE-2022-0002P4MEDIUMCVSS 6.5fixed in linux 5.16.12-1 (bookworm)2022
CVE-2022-0002 [MEDIUM] CVE-2022-0002: linux - Non-transparent sharing of branch predictor within a context in some Intel(R) Pr...
Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 5.16.12-1)
bullseye: resolved (fixed in 5.10.103-1)
forky: resolved (fixed in 5.16.12-1)
sid: resolved (fixed in 5.16.12-1)
trixie: resolved (fixed
debian
CVE-2021-28688P4MEDIUMCVSS 6.5fixed in linux 5.10.28-1 (bookworm)2021
CVE-2021-28688 [MEDIUM] CVE-2021-28688: linux - The fix for XSA-365 includes initialization of pointers such that subsequent cle...
The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went too far and may under certain conditions also overwrite pointers which are in need of cleaning up. The lack of cleanup would result in leaking persistent grants. The leak in turn would prevent fully cleaning u
debian
CVE-2024-53135P4MEDIUMCVSS 6.5fixed in linux 6.1.119-1 (bookworm)2024
CVE-2024-53135 [MEDIUM] CVE-2024-53135: linux - In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: B...
In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN Hide KVM's pt_mode module param behind CONFIG_BROKEN, i.e. disable support for virtualizing Intel PT via guest/host mode unless BROKEN=y. There are myriad bugs in the implementation, some of which are fatal to the guest, a
debian
CVE-2015-5156P4MEDIUMCVSS 6.1fixed in linux 4.1.5-1 (bookworm)2015
CVE-2015-5156 [MEDIUM] CVE-2015-5156: linux - The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel befor...
The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via a crafted sequence of fragmented packets.
Scope: local
bookworm: resolved (fixed in 4.1.5-1)
bullseye: resolve
debian
CVE-2014-8884P4MEDIUMCVSS 6.1fixed in linux 3.16.7-ckt2-1 (bookworm)2014
CVE-2014-8884 [MEDIUM] CVE-2014-8884: linux - Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd functi...
Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe.c in the Linux kernel before 3.17.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via a large message length in an ioctl call.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt2-1)
bullseye: resolv
debian
CVE-2019-19602P4MEDIUMCVSS 6.1fixed in linux 5.3.15-1 (bookworm)2019
CVE-2019-19602 [MEDIUM] CVE-2019-19602: linux - fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel be...
fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel before 5.4.2, when GCC 9 is used, allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact because of incorrect fpu_fpregs_owner_ctx caching, as demonstrated by mishandling of signal-based non-cooperative preemption in Go
debian