cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 208 of 632
CVE-2023-0459P4MEDIUMCVSS 6.5fixed in linux 6.1.15-1 (bookworm)2023
CVE-2023-0459 [MEDIUM] CVE-2023-0459: linux - Copy_from_user on 64-bit versions of the Linux kernel does not implement the __u... Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to bypass the "access_ok" check and pass a kernel pointer to copy_from_user(). This would allow an attacker to leak information. We recommend upgrading beyond commit 74e19ef0ff8061ef55957c3abd71614ef0f42f47 Scope: local bookworm: resolved (fixed in 6.1.1
debian
CVE-2013-1798P4MEDIUMCVSS 6.2fixed in linux 3.2.41-2 (bookworm)2013
CVE-2013-1798 [MEDIUM] CVE-2013-1798: linux - The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel throu... The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel through 3.8.4 does not properly handle a certain combination of invalid IOAPIC_REG_SELECT and IOAPIC_REG_WINDOW operations, which allows guest OS users to obtain sensitive information from host OS memory or cause a denial of service (host OS OOPS) via a crafted application. Scope: local bookwor
debian
CVE-2020-26541P4MEDIUMCVSS 6.5fixed in linux 5.14.6-1 (bookworm)2020
CVE-2020-26541 [MEDIUM] CVE-2020-26541: linux - The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbid... The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c. Scope: local bookworm: resolved (fixed in 5.14.6-1) bullseye: resolved (fixed in 5.10.70-1) forky: resolved (fixed in 5.14.6-1) sid: resolved (fixed in 5.14.6-1) trixie: reso
debian
CVE-2018-15572P4MEDIUMCVSS 6.5fixed in linux 4.17.15-1 (bookworm)2018
CVE-2018-15572 [MEDIUM] CVE-2018-15572: linux - The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the L... The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4.18.1 does not always fill RSB upon a context switch, which makes it easier for attackers to conduct userspace-userspace spectreRSB attacks. Scope: local bookworm: resolved (fixed in 4.17.15-1) bullseye: resolved (fixed in 4.17.15-1) forky: resolved (fixed in 4.17.15-
debian
CVE-2022-0001P4MEDIUMCVSS 6.5fixed in linux 5.16.12-1 (bookworm)2022
CVE-2022-0001 [MEDIUM] CVE-2022-0001: linux - Non-transparent sharing of branch predictor selectors between contexts in some I... Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. Scope: local bookworm: resolved (fixed in 5.16.12-1) bullseye: resolved (fixed in 5.10.103-1) forky: resolved (fixed in 5.16.12-1) sid: resolved (fixed in 5.16.12-1) trixie: resol
debian
CVE-2023-52819P4MEDIUMCVSS 6.6fixed in linux 6.1.64-1 (bookworm)2023
CVE-2023-52819 [MEDIUM] CVE-2023-52819: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fi... In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix UBSAN array-index-out-of-bounds for Polaris and Tonga For pptable structs that use flexible array sizes, use flexible arrays. Scope: local bookworm: resolved (fixed in 6.1.64-1) bullseye: resolved (fixed in 5.10.205-1) forky: resolved (fixed in 6.6.8-1) sid: resolved (fixed in 6.6.8-1)
debian
CVE-2022-0002P4MEDIUMCVSS 6.5fixed in linux 5.16.12-1 (bookworm)2022
CVE-2022-0002 [MEDIUM] CVE-2022-0002: linux - Non-transparent sharing of branch predictor within a context in some Intel(R) Pr... Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. Scope: local bookworm: resolved (fixed in 5.16.12-1) bullseye: resolved (fixed in 5.10.103-1) forky: resolved (fixed in 5.16.12-1) sid: resolved (fixed in 5.16.12-1) trixie: resolved (fixed
debian
CVE-2021-28688P4MEDIUMCVSS 6.5fixed in linux 5.10.28-1 (bookworm)2021
CVE-2021-28688 [MEDIUM] CVE-2021-28688: linux - The fix for XSA-365 includes initialization of pointers such that subsequent cle... The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went too far and may under certain conditions also overwrite pointers which are in need of cleaning up. The lack of cleanup would result in leaking persistent grants. The leak in turn would prevent fully cleaning u
debian
CVE-2024-53135P4MEDIUMCVSS 6.5fixed in linux 6.1.119-1 (bookworm)2024
CVE-2024-53135 [MEDIUM] CVE-2024-53135: linux - In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: B... In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN Hide KVM's pt_mode module param behind CONFIG_BROKEN, i.e. disable support for virtualizing Intel PT via guest/host mode unless BROKEN=y. There are myriad bugs in the implementation, some of which are fatal to the guest, a
debian
CVE-2015-5156P4MEDIUMCVSS 6.1fixed in linux 4.1.5-1 (bookworm)2015
CVE-2015-5156 [MEDIUM] CVE-2015-5156: linux - The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel befor... The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via a crafted sequence of fragmented packets. Scope: local bookworm: resolved (fixed in 4.1.5-1) bullseye: resolve
debian
CVE-2014-8884P4MEDIUMCVSS 6.1fixed in linux 3.16.7-ckt2-1 (bookworm)2014
CVE-2014-8884 [MEDIUM] CVE-2014-8884: linux - Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd functi... Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe.c in the Linux kernel before 3.17.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via a large message length in an ioctl call. Scope: local bookworm: resolved (fixed in 3.16.7-ckt2-1) bullseye: resolv
debian
CVE-2019-19602P4MEDIUMCVSS 6.1fixed in linux 5.3.15-1 (bookworm)2019
CVE-2019-19602 [MEDIUM] CVE-2019-19602: linux - fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel be... fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel before 5.4.2, when GCC 9 is used, allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact because of incorrect fpu_fpregs_owner_ctx caching, as demonstrated by mishandling of signal-based non-cooperative preemption in Go
debian
CVE-2019-19927P4MEDIUMCVSS 6.0fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-19927 [MEDIUM] CVE-2019-19927: linux - In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubun... In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some operations can lead to slab-out-of-bounds read access in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c. This is related to the vmwgfx or ttm module. Scope: local bookworm: resolved (fixed in 5.2.6-1) bullseye:
debian
CVE-2021-47375P4MEDIUMCVSS 6.2fixed in linux 5.14.9-1 (bookworm)2021
CVE-2021-47375 [MEDIUM] CVE-2021-47375: linux - In the Linux kernel, the following vulnerability has been resolved: blktrace: F... In the Linux kernel, the following vulnerability has been resolved: blktrace: Fix uaf in blk_trace access after removing by sysfs There is an use-after-free problem triggered by following process: P1(sda) P2(sdb) echo 0 > /sys/block/sdb/trace/enable blk_trace_remove_queue synchronize_rcu blk_trace_free relay_close rcu_read_lock __blk_add_trace trace_note_tsk (Iterat
debian
CVE-2023-52497P4MEDIUMCVSS 6.1fixed in linux 6.1.76-1 (bookworm)2023
CVE-2023-52497 [MEDIUM] CVE-2023-52497: linux - In the Linux kernel, the following vulnerability has been resolved: erofs: fix ... In the Linux kernel, the following vulnerability has been resolved: erofs: fix lz4 inplace decompression Currently EROFS can map another compressed buffer for inplace decompression, that was used to handle the cases that some pages of compressed data are actually not in-place I/O. However, like most simple LZ77 algorithms, LZ4 expects the compressed data is arranged
debian
CVE-2018-12127P4MEDIUMCVSS 5.6fixed in intel-microcode 3.20190514.1 (bookworm)2018
CVE-2018-12127 [MEDIUM] CVE-2018-12127: intel-microcode - Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microproc... Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-inform
debian
CVE-2018-12126P4MEDIUMCVSS 5.6fixed in intel-microcode 3.20190514.1 (bookworm)2018
CVE-2018-12126 [MEDIUM] CVE-2018-12126: intel-microcode - Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some mic... Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-
debian
CVE-2013-2851P4LOWCVSS 6.0fixed in linux 3.9.8-1 (bookworm)2013
CVE-2013-2851 [MEDIUM] CVE-2013-2851: linux - Format string vulnerability in the register_disk function in block/genhd.c in th... Format string vulnerability in the register_disk function in block/genhd.c in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and writing format string specifiers to /sys/module/md_mod/parameters/new_array in order to create a crafted /dev/md device name. Scope: local bookworm: resolved (fixed in 3.9.8-1) bullseye: resolv
debian
CVE-2023-32253P4MEDIUMCVSS 5.9fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-32253 [MEDIUM] CVE-2023-32253: linux - A flaw was found in the Linux kernel's ksmbd component. A deadlock is triggered ... A flaw was found in the Linux kernel's ksmbd component. A deadlock is triggered by sending multiple concurrent session setup requests, possibly leading to a denial of service. Scope: local bookworm: resolved (fixed in 6.1.37-1) bullseye: open forky: resolved (fixed in 6.3.7-1) sid: resolved (fixed in 6.3.7-1) trixie: resolved (fixed in 6.3.7-1)
debian
CVE-2020-28588P4MEDIUMCVSS 5.5fixed in linux 5.9.15-1 (bookworm)2020
CVE-2020-28588 [MEDIUM] CVE-2020-28588: linux - An information disclosure vulnerability exists in the /proc/pid/syscall function... An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in v5.10-rc4, so it’s likely that all versions in between are affected. An attacker can read /proc/pid/syscall
debian
Debian Linux vulnerabilities | cvebase