Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 203 of 632
CVE-2020-11668P4HIGHCVSS 7.1fixed in linux 5.5.17-1 (bookworm)2020
CVE-2020-11668 [HIGH] CVE-2020-11668: linux - In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the...
In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.
Scope: local
bookworm: resolved (fixed in 5.5.17-1)
bullseye: resolved (fixed in 5.5.17-1)
forky: resolved (fixed in 5.5.17-1)
sid: resolved (fixed in 5.5.17-1)
trixie: resolved (fixed in 5.5.17-1)
debian
CVE-2023-54057P4UNKNOWNfixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-54057 CVE-2023-54057: linux - In the Linux kernel, the following vulnerability has been resolved: iommu/amd: ...
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Add a length limitation for the ivrs_acpihid command-line parameter The 'acpiid' buffer in the parse_ivrs_acpihid function may overflow, because the string specifier in the format string sscanf() has no width limitation. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) w
debian
CVE-2023-53717P4UNKNOWNfixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-53717 CVE-2023-53717: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k...
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: Fix potential stack-out-of-bounds write in ath9k_wmi_rsp_callback() Fix a stack-out-of-bounds write that occurs in a WMI response callback function that is called after a timeout occurs in ath9k_wmi_cmd(). The callback writes to wmi->cmd_rsp_buf, a stack-allocated buffer that could no longer be
debian
CVE-2023-54182P4UNKNOWNfixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-54182 CVE-2023-54182: linux - In the Linux kernel, the following vulnerability has been resolved: f2fs: fix t...
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to check readonly condition correctly With below case, it can mount multi-device image w/ rw option, however one of secondary device is set as ro, later update will cause panic, so let's introduce f2fs_dev_is_readonly(), and check multi-devices rw status in f2fs_remount() w/ it in order to avoid su
debian
CVE-2025-40242P4UNKNOWNfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40242 CVE-2025-40242: linux - In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix u...
In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix unlikely race in gdlm_put_lock In gdlm_put_lock(), there is a small window of time in which the DFL_UNMOUNT flag has been set but the lockspace hasn't been released, yet. In that window, dlm may still call gdlm_ast() and gdlm_bast(). To prevent it from dereferencing freed glock objects, only free t
debian
CVE-2022-50701P4UNKNOWNfixed in linux 6.1.20-1 (bookworm)2022
CVE-2022-50701 CVE-2022-50701: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:...
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921s: fix slab-out-of-bounds access in sdio host SDIO may need addtional 511 bytes to align bus operation. If the tailroom of this skb is not big enough, we would access invalid memory region. For low level operation, increase skb size to keep valid memory access in SDIO host. Error message: [
debian
CVE-2026-23315P4UNKNOWNfixed in linux 6.19.8-1 (forky)2026
CVE-2026-23315 CVE-2026-23315: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:...
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() Check frame length before accessing the mgmt fields in mt76_connac2_mac_write_txwi_80211 in order to avoid a possible oob access. [fix check to also cover mgmt->u.action.u.addba_req.capab, correct Fixes tag]
Scope: local
bookworm: ope
debian
CVE-2025-68313P4LOWfixed in linux 6.17.8-1 (forky)2025
CVE-2025-68313 [LOW] CVE-2025-68313: linux - In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD...
In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Add RDSEED fix for Zen5 There's an issue with RDSEED's 16-bit and 32-bit register output variants on Zen5 which return a random value of 0 "at a rate inconsistent with randomness while incorrectly signaling success (CF=1)". Search the web for AMD-SB-7055 for more detail. Add a fix glue whi
debian
CVE-2026-23388P4UNKNOWNfixed in linux 6.19.8-1 (forky)2026
CVE-2026-23388 CVE-2026-23388: linux - In the Linux kernel, the following vulnerability has been resolved: Squashfs: c...
In the Linux kernel, the following vulnerability has been resolved: Squashfs: check metadata block offset is within range Syzkaller reports a "general protection fault in squashfs_copy_data" This is ultimately caused by a corrupted index look-up table, which produces a negative metadata block offset. This is subsequently passed to squashfs_copy_data (via squashfs_read_metada
debian
CVE-2017-13305P4HIGHCVSS 7.1fixed in linux 4.12.6-1 (bookworm)2017
CVE-2017-13305 [HIGH] CVE-2017-13305: linux - A information disclosure vulnerability in the Upstream kernel encrypted-keys. Pr...
A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.
Scope: local
bookworm: resolved (fixed in 4.12.6-1)
bullseye: resolved (fixed in 4.12.6-1)
forky: resolved (fixed in 4.12.6-1)
sid: resolved (fixed in 4.12.6-1)
trixie: resolved (fixed in 4.12.6-1)
debian
CVE-2021-47327P4HIGHCVSS 7.1fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-47327 [HIGH] CVE-2021-47327: linux - In the Linux kernel, the following vulnerability has been resolved: iommu/arm-s...
In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu: Fix arm_smmu_device refcount leak when arm_smmu_rpm_get fails arm_smmu_rpm_get() invokes pm_runtime_get_sync(), which increases the refcount of the "smmu" even though the return value is less than 0. The reference counting issue happens in some error handling paths of arm_smmu_rpm_get(
debian
CVE-2023-52640P4HIGHCVSS 7.1fixed in linux 6.1.82-1 (bookworm)2023
CVE-2023-52640 [HIGH] CVE-2023-52640: linux - In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: F...
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix oob in ntfs_listxattr The length of name cannot exceed the space occupied by ea.
Scope: local
bookworm: resolved (fixed in 6.1.82-1)
bullseye: resolved
forky: resolved (fixed in 6.7.7-1)
sid: resolved (fixed in 6.7.7-1)
trixie: resolved (fixed in 6.7.7-1)
debian
CVE-2021-47624P4HIGHCVSS 7.1fixed in linux 5.16.10-1 (bookworm)2021
CVE-2021-47624 [HIGH] CVE-2021-47624: linux - In the Linux kernel, the following vulnerability has been resolved: net/sunrpc:...
In the Linux kernel, the following vulnerability has been resolved: net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change The refcount leak issues take place in an error handling path. When the 3rd argument buf doesn't match with "offline", "online" or "remove", the function simply returns -EINVAL and forgets to decrease the reference count of a rpc_xpr
debian
CVE-2024-56597P4HIGHCVSS 7.1fixed in linux 6.1.123-1 (bookworm)2024
CVE-2024-56597 [HIGH] CVE-2024-56597: linux - In the Linux kernel, the following vulnerability has been resolved: jfs: fix sh...
In the Linux kernel, the following vulnerability has been resolved: jfs: fix shift-out-of-bounds in dbSplit When dmt_budmin is less than zero, it causes errors in the later stages. Added a check to return an error beforehand in dbAllocCtl itself.
Scope: local
bookworm: resolved (fixed in 6.1.123-1)
bullseye: resolved (fixed in 5.10.234-1)
forky: resolved (fixed in 6.1
debian
CVE-2024-49862P4LOWCVSS 7.1fixed in linux 6.11.2-1 (forky)2024
CVE-2024-49862 [HIGH] CVE-2024-49862: linux - In the Linux kernel, the following vulnerability has been resolved: powercap: i...
In the Linux kernel, the following vulnerability has been resolved: powercap: intel_rapl: Fix off by one in get_rpi() The rp->priv->rpi array is either rpi_msr or rpi_tpmi which have NR_RAPL_PRIMITIVES number of elements. Thus the > needs to be >= to prevent an off by one access.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.11.2-1)
si
debian
CVE-2024-42132P4LOWCVSS 7.1fixed in linux 6.9.9-1 (forky)2024
CVE-2024-42132 [HIGH] CVE-2024-42132: linux - In the Linux kernel, the following vulnerability has been resolved: bluetooth/h...
In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX Syzbot hit warning in hci_conn_del() caused by freeing handle that was not allocated using ida allocator. This is caused by handle bigger than HCI_CONN_HANDLE_MAX passed by hci_le_big_sync_established_evt(), which makes code think
debian
CVE-2024-50247P4HIGHCVSS 7.1fixed in linux 6.1.119-1 (bookworm)2024
CVE-2024-50247 [HIGH] CVE-2024-50247: linux - In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: C...
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Check if more than chunk-size bytes are written A incorrectly formatted chunk may decompress into more than LZNT_CHUNK_SIZE bytes and a index out of bounds will occur in s_max_off.
Scope: local
bookworm: resolved (fixed in 6.1.119-1)
bullseye: resolved
forky: resolved (fixed in 6.11.7-1)
sid
debian
CVE-2023-52697P4LOWCVSS 7.1fixed in linux 6.6.15-1 (forky)2023
CVE-2023-52697 [HIGH] CVE-2023-52697: linux - In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel...
In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw_rt_sdca_jack_common: ctx->headset_codec_dev = NULL sof_sdw_rt_sdca_jack_exit() are used by different codecs, and some of them use the same dai name. For example, rt712 and rt713 both use "rt712-sdca-aif1" and sof_sdw_rt_sdca_jack_exit(). As a result, sof_sdw_rt_sdca_jack_exit() wi
debian
CVE-2025-21815P4LOWCVSS 7.1fixed in linux 6.12.15-1 (forky)2025
CVE-2025-21815 [HIGH] CVE-2025-21815: linux - In the Linux kernel, the following vulnerability has been resolved: mm/compacti...
In the Linux kernel, the following vulnerability has been resolved: mm/compaction: fix UBSAN shift-out-of-bounds warning syzkaller reported a UBSAN shift-out-of-bounds warning of (1UL << order) in isolate_freepages_block(). The bogus compound_order can be any value because it is union with flags. Add back the MAX_PAGE_ORDER check to fix the warning.
Scope: local
bookw
debian
CVE-2023-53085P4LOWCVSS 7.1fixed in linux 6.3.7-1 (forky)2023
CVE-2023-53085 [HIGH] CVE-2023-53085: linux - In the Linux kernel, the following vulnerability has been resolved: drm/edid: f...
In the Linux kernel, the following vulnerability has been resolved: drm/edid: fix info leak when failing to get panel id Make sure to clear the transfer buffer before fetching the EDID to avoid leaking slab data to the logs on errors that leave the buffer unchanged.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fi
debian