cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 209 of 632
CVE-2024-44947P4MEDIUMCVSS 5.5fixed in linux 6.1.112-1 (bookworm)2024
CVE-2024-44947 [MEDIUM] CVE-2024-44947: linux - In the Linux kernel, the following vulnerability has been resolved: fuse: Initi... In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before setting uptodate fuse_notify_store(), unlike fuse_do_readpage(), does not enable page zeroing (because it can be used to change partial page contents). So fuse_notify_store() must be more careful to fully initialize page contents (including parts of t
debian
CVE-2022-3435P4MEDIUMCVSS 4.3fixed in linux 6.0.12-1 (bookworm)2022
CVE-2022-3435 [MEDIUM] CVE-2022-3435: linux - A vulnerability classified as problematic has been found in Linux Kernel. This a... A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-210357 was assigned to
debian
CVE-2019-15902P4MEDIUMCVSS 5.6fixed in linux 5.2.17-1 (bookworm)2019
CVE-2019-15902 [MEDIUM] CVE-2019-15902: linux - A backporting error was discovered in the Linux stable/longterm kernel 4.4.x thr... A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate. This occurred be
debian
CVE-2019-5489P4MEDIUMCVSS 5.5fixed in linux 4.19.37-4 (bookworm)2019
CVE-2019-5489 [MEDIUM] CVE-2019-5489: linux - The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13... The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this affects the output of the fincore program.) Limited remote exploitation may be possible, as demonstrated by latency differ
debian
CVE-2020-24586P4LOWCVSS 3.5fixed in firmware-nonfree 20210818-1 (bookworm)2020
CVE-2020-24586 [LOW] CVE-2020-24586: firmware-nonfree - The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) ... The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitra
debian
CVE-2022-23960P4MEDIUMCVSS 5.6fixed in linux 5.16.14-1 (bookworm)2022
CVE-2022-23960 [MEDIUM] CVE-2022-23960: linux - Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly re... Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information. Scope: local bookworm: resolved (fixed in 5.
debian
CVE-2024-36357P4MEDIUMCVSS 5.6fixed in amd64-microcode 3.20251202.1 (forky)2024
CVE-2024-36357 [MEDIUM] CVE-2024-36357: amd64-microcode - A transient execution vulnerability in some AMD processors may allow an attacker... A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 3.20251202.1) sid: resolved (fixed in 3.20251202.1) trixie: open
debian
CVE-2021-47384P4MEDIUMCVSS 5.3fixed in linux 5.14.12-1 (bookworm)2021
CVE-2021-47384 [MEDIUM] CVE-2021-47384: linux - In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83... In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field If driver read tmp value sufficient for (tmp & 0x08) && (!(tmp & 0x80)) && ((tmp & 0x7) == ((tmp >> 4) & 0x7)) from device then Null pointer dereference occurs. (It is possible if tmp = 0b0xyz1xyz, where same litera
debian
CVE-2014-3690P4MEDIUMCVSS 5.5fixed in linux 3.16.7-1 (bookworm)2014
CVE-2014-3690 [MEDIUM] CVE-2014-3690: linux - arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Int... arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm access, as demonstrated by PR_SET_TSC prctl calls withi
debian
CVE-2018-18710P4MEDIUMCVSS 5.5fixed in linux 4.18.20-1 (bookworm)2018
CVE-2018-18710 [MEDIUM] CVE-2018-18710: linux - An issue was discovered in the Linux kernel through 4.19. An information leak in... An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. This is similar to CVE-2018-10940 and CVE-2018-16658. Scope: local bookworm: resolved (fixed in 4.18.20-1) bu
debian
CVE-2023-4130P4MEDIUMCVSS 5.5fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-4130 [MEDIUM] CVE-2023-4130: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ... In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix wrong next length validation of ea buffer in smb2_set_ea() There are multiple smb2_ea_info buffers in FILE_FULL_EA_INFORMATION request from client. ksmbd find next smb2_ea_info using ->NextEntryOffset of current smb2_ea_info. ksmbd need to validate buffer length Before accessing the next ea
debian
CVE-2020-10766P4MEDIUMCVSS 5.5fixed in linux 5.7.6-1 (bookworm)2020
CVE-2020-10766 [MEDIUM] CVE-2020-10766: linux - A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation ... A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling allows an attacker with a local account to disable SSBD protection during a context switch when additional speculative execution mitigations are in place. This issue was introduced when the per task/process conditional STIPB switching was added on top
debian
CVE-2023-52699P4MEDIUMCVSS 5.3fixed in linux 6.1.90-1 (bookworm)2023
CVE-2023-52699 [MEDIUM] CVE-2023-52699: linux - In the Linux kernel, the following vulnerability has been resolved: sysv: don't... In the Linux kernel, the following vulnerability has been resolved: sysv: don't call sb_bread() with pointers_lock held syzbot is reporting sleep in atomic context in SysV filesystem [1], for sb_bread() is called with rw_spinlock held. A "write_lock(&pointers_lock) => read_lock(&pointers_lock) deadlock" bug and a "sb_bread() with write_lock(&pointers_lock)" bug were
debian
CVE-2020-10942P4MEDIUMCVSS 5.3fixed in linux 5.5.13-1 (bookworm)2020
CVE-2020-10942 [MEDIUM] CVE-2020-10942: linux - In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks va... In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls. Scope: local bookworm: resolved (fixed in 5.5.13-1) bullseye: resolved (fixed in 5.5.13-1) forky: resolved (fixed in 5.5.13-1) sid: resolved (fixed in 5.5.13-1) trixie
debian
CVE-2020-12912P4LOWCVSS 5.5fixed in linux 5.9.9-1 (bookworm)2020
CVE-2020-12912 [MEDIUM] CVE-2020-12912: linux - A potential vulnerability in the AMD extension to Linux "hwmon" service may allo... A potential vulnerability in the AMD extension to Linux "hwmon" service may allow an attacker to use the Linux-based Running Average Power Limit (RAPL) interface to show various side channel attacks. In line with industry partners, AMD has updated the RAPL interface to require privileged access. Scope: local bookworm: resolved (fixed in 5.9.9-1) bullseye: resolved (
debian
CVE-2022-3523P4MEDIUMCVSS 5.3fixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-3523 [MEDIUM] CVE-2022-3523: linux - A vulnerability was found in Linux Kernel. It has been classified as problematic... A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is an unknown function of the file mm/memory.c of the component Driver Handler. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211020. Scope
debian
CVE-2022-0382P4MEDIUMCVSS 5.5fixed in linux 5.15.15-1 (bookworm)2022
CVE-2022-0382 [MEDIUM] CVE-2022-0382: linux - An information leak flaw was found due to uninitialized memory in the Linux kern... An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way a user sends a TIPC datagram to one or more destinations. This flaw allows a local user to read some kernel memory. This issue is limited to no more than 7 bytes, and the user cannot control what is read. This flaw affects the Linux kernel versions
debian
CVE-2020-10767P4MEDIUMCVSS 5.5fixed in linux 5.7.6-1 (bookworm)2020
CVE-2020-10767 [MEDIUM] CVE-2020-10767: linux - A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the... A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Prediction Barrier). The IBPB mitigation will be disabled when STIBP is not available or when the Enhanced Indirect Branch Restricted Speculation (IBRS) is available. This flaw allows a local attacker to perform a Spectre V2 style attack when this configur
debian
CVE-2025-39770P4MEDIUMCVSS 5.5fixed in linux 6.1.153-1 (bookworm)2025
CVE-2025-39770 [MEDIUM] CVE-2025-39770: linux - In the Linux kernel, the following vulnerability has been resolved: net: gso: F... In the Linux kernel, the following vulnerability has been resolved: net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM When performing Generic Segmentation Offload (GSO) on an IPv6 packet that contains extension headers, the kernel incorrectly requests checksum offload if the egress device only advertises NETIF_F_IPV6_CSUM feature, which has a
debian
CVE-2024-26731P4MEDIUMCVSS 5.3fixed in linux 6.1.82-1 (bookworm)2024
CVE-2024-26731 [MEDIUM] CVE-2024-26731: linux - In the Linux kernel, the following vulnerability has been resolved: bpf, sockma... In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix NULL pointer dereference in sk_psock_verdict_data_ready() syzbot reported the following NULL pointer dereference issue [1]: BUG: kernel NULL pointer dereference, address: 0000000000000000 [...] RIP: 0010:0x0 [...] Call Trace: sk_psock_verdict_data_ready+0x232/0x340 net/core/skmsg.c
debian
Debian Linux vulnerabilities | cvebase