Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 204 of 632
CVE-2019-19076P4MEDIUMCVSS 5.9fixed in linux 5.3.7-1 (bookworm)2019
CVE-2019-19076 [MEDIUM] CVE-2019-19076: linux - A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/etherne...
A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux kernel before 5.3.6 allows attackers to cause a denial of service (memory consumption), aka CID-78beef629fd9. NOTE: This has been argued as not a valid vulnerability. The upstream commit 78beef629fd9 was reverted
Scope: local
bookworm: resolved (fix
debian
CVE-2022-50026P4HIGHCVSS 7.1fixed in linux 5.19.6-1 (bookworm)2022
CVE-2022-50026 [HIGH] CVE-2022-50026: linux - In the Linux kernel, the following vulnerability has been resolved: habanalabs/...
In the Linux kernel, the following vulnerability has been resolved: habanalabs/gaudi: fix shift out of bounds When validating NIC queues, queue offset calculation must be performed only for NIC queues.
Scope: local
bookworm: resolved (fixed in 5.19.6-1)
bullseye: open
forky: resolved (fixed in 5.19.6-1)
sid: resolved (fixed in 5.19.6-1)
trixie: resolved (fixed in 5.19
debian
CVE-2012-2137P4MEDIUMCVSS 6.9fixed in linux 3.2.20-1 (bookworm)2012
CVE-2012-2137 [MEDIUM] CVE-2012-2137: linux - Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel ...
Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to Message Signaled Interrupts (MSI), irq routing entries, and an incorrect check by the setup_routing_entry function before invoking the kvm_set_irq function.
Scop
debian
CVE-2014-7841P4MEDIUMCVSS 5.0fixed in linux 3.16.7-ckt2-1 (bookworm)2014
CVE-2014-7841 [MEDIUM] CVE-2014-7841: linux - The sctp_process_param function in net/sctp/sm_make_chunk.c in the SCTP implemen...
The sctp_process_param function in net/sctp/sm_make_chunk.c in the SCTP implementation in the Linux kernel before 3.17.4, when ASCONF is used, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via a malformed INIT chunk.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt2-1)
bullseye: resolved (fixed in 3.16.7-ckt2-1)
f
debian
CVE-2014-2309P4MEDIUMCVSS 6.1fixed in linux 3.13.6-1 (bookworm)2014
CVE-2014-2309 [MEDIUM] CVE-2014-2309: linux - The ip6_route_add function in net/ipv6/route.c in the Linux kernel through 3.13....
The ip6_route_add function in net/ipv6/route.c in the Linux kernel through 3.13.6 does not properly count the addition of routes, which allows remote attackers to cause a denial of service (memory consumption) via a flood of ICMPv6 Router Advertisement packets.
Scope: local
bookworm: resolved (fixed in 3.13.6-1)
bullseye: resolved (fixed in 3.13.6-1)
forky: resolved (
debian
CVE-2019-19080P4MEDIUMCVSS 5.9fixed in linux 5.3.7-1 (bookworm)2019
CVE-2019-19080 [MEDIUM] CVE-2019-19080: linux - Four memory leaks in the nfp_flower_spawn_phy_reprs() function in drivers/net/et...
Four memory leaks in the nfp_flower_spawn_phy_reprs() function in drivers/net/ethernet/netronome/nfp/flower/main.c in the Linux kernel before 5.3.4 allow attackers to cause a denial of service (memory consumption), aka CID-8572cea1461a.
Scope: local
bookworm: resolved (fixed in 5.3.7-1)
bullseye: resolved (fixed in 5.3.7-1)
forky: resolved (fixed in 5.3.7-1)
sid: re
debian
CVE-2019-15090P4MEDIUMCVSS 6.7fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-15090 [MEDIUM] CVE-2019-15090: linux - An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel befo...
An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in 5.2.6-1)
trixie: resolved (fixed in 5.2.6-1)
debian
CVE-2023-39192P4MEDIUMCVSS 6.7fixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-39192 [MEDIUM] CVE-2023-39192: linux - A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 modu...
A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate the fields in the xt_u32 structure. This flaw allows a local privileged attacker to trigger an out-of-bounds read by setting the size fields with a value beyond the array boundaries, leading to a crash or information disclosure.
Scope: local
bookworm: resolved (fixed
debian
CVE-2022-2785P4MEDIUMCVSS 6.7fixed in linux 5.19.6-1 (bookworm)2022
CVE-2022-2785 [MEDIUM] CVE-2022-2785: linux - There exists an arbitrary memory read within the Linux Kernel BPF - Constants pr...
There exists an arbitrary memory read within the Linux Kernel BPF - Constants provided to fill pointers in structs passed in to bpf_sys_bpf are not verified and can point anywhere, including memory not owned by BPF. An attacker with CAP_BPF can arbitrarily read memory from anywhere on the system. We recommend upgrading past commit 86f44fcec22c
Scope: local
bookworm: r
debian
CVE-2023-28746P4MEDIUMCVSS 6.5fixed in intel-microcode 3.20240312.1~deb12u1 (bookworm)2023
CVE-2023-28746 [MEDIUM] CVE-2023-28746: intel-microcode - Information exposure through microarchitectural state after transient execution ...
Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20240312.1~deb12u1)
bullseye: resolved (fixed in 3.20240312.1~deb11u1)
forky:
debian
CVE-2024-0607P4MEDIUMCVSS 6.6fixed in linux 6.1.64-1 (bookworm)2024
CVE-2024-0607 [MEDIUM] CVE-2024-0607: linux - A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in...
A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each iteration, 8 bytes are written, but `dst` is an array of u32, so each element only has space for 4 bytes. That means every iteration overwrites part of the previous element cor
debian
CVE-2017-17741P4MEDIUMCVSS 6.5fixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-17741 [MEDIUM] CVE-2017-17741: linux - The KVM implementation in the Linux kernel through 4.14.7 allows attackers to ob...
The KVM implementation in the Linux kernel through 4.14.7 allows attackers to obtain potentially sensitive information from kernel memory, aka a write_mmio stack-based out-of-bounds read, related to arch/x86/kvm/x86.c and include/trace/events/kvm.h.
Scope: local
bookworm: resolved (fixed in 4.14.7-1)
bullseye: resolved (fixed in 4.14.7-1)
forky: resolved (fixed in 4
debian
CVE-2021-28715P4MEDIUMCVSS 6.5fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-28715 [MEDIUM] CVE-2021-28715: linux - Guest can force Linux netback driver to hog large amounts of kernel memory T[his...
Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's netback driver are buffered until the guest is ready to process them. There are some measures taken for avoi
debian
CVE-2021-28714P4MEDIUMCVSS 6.5fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-28714 [MEDIUM] CVE-2021-28714: linux - Guest can force Linux netback driver to hog large amounts of kernel memory T[his...
Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's netback driver are buffered until the guest is ready to process them. There are some measures taken for avoi
debian
CVE-2022-4382P4MEDIUMCVSS 6.4fixed in linux 6.1.8-1 (bookworm)2022
CVE-2022-4382 [MEDIUM] CVE-2022-4382: linux - A use-after-free flaw caused by a race among the superblock operations in the ga...
A use-after-free flaw caused by a race among the superblock operations in the gadgetfs Linux driver was found. It could be triggered by yanking out a device that is running the gadgetfs side.
Scope: local
bookworm: resolved (fixed in 6.1.8-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.8-1)
sid: resolved (fixed in 6.1.8-1)
trixie: resolved (
debian
CVE-2021-37159P4MEDIUMCVSS 6.4fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-37159 [MEDIUM] CVE-2021-37159: linux - hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 ...
hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixi
debian
CVE-2023-52886P4MEDIUMCVSS 6.4fixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-52886 [MEDIUM] CVE-2023-52886: linux - In the Linux kernel, the following vulnerability has been resolved: USB: core: ...
In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descriptor in hub_port_init() Syzbot reported an out-of-bounds read in sysfs.c:read_descriptors(): BUG: KASAN: slab-out-of-bounds in read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883 Read of size 8 at addr ffff88801e78b8c8 by task udevd/5011 CPU:
debian
CVE-2022-44034P4LOWCVSS 6.4fixed in linux 6.4.4-1 (forky)2022
CVE-2022-44034 [MEDIUM] CVE-2022-44034: linux - An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/s...
An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/scr24x_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between scr24x_open() and scr24x_remove().
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 6.4.4-1)
sid:
debian
CVE-2023-40791P4LOWCVSS 6.3fixed in linux 6.4.13-1 (forky)2023
CVE-2023-40791 [MEDIUM] CVE-2023-40791: linux - extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails ...
extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.4.13-1)
sid: resolved (fixed in 6.4.13-1)
trixie: resolved (fixed in 6.4.13-1)
debian
CVE-2019-19529P4MEDIUMCVSS 6.3fixed in linux 5.3.15-1 (bookworm)2019
CVE-2019-19529 [MEDIUM] CVE-2019-19529: linux - In the Linux kernel before 5.3.11, there is a use-after-free bug that can be cau...
In the Linux kernel before 5.3.11, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c driver, aka CID-4d6636498c41.
Scope: local
bookworm: resolved (fixed in 5.3.15-1)
bullseye: resolved (fixed in 5.3.15-1)
forky: resolved (fixed in 5.3.15-1)
sid: resolved (fixed in 5.3.15-1)
trixie: resolved (fixed in 5.
debian