cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 210 of 632
CVE-2021-31829P4MEDIUMCVSS 5.5fixed in linux 5.10.38-1 (bookworm)2021
CVE-2021-31829 [MEDIUM] CVE-2021-31829: linux - kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable sp... kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the BPF stack can contain uninitialized data that might represent sensitive information previ
debian
CVE-2023-0597P4MEDIUMCVSS 5.5fixed in linux 6.3.7-1 (forky)2023
CVE-2023-0597 [MEDIUM] CVE-2023-0597: linux - A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of ... A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location of exception stack(s) or other important data. A local user could use this flaw to get access to some important data with expected location in memory. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 6.
debian
CVE-2023-52738P4MEDIUMCVSS 5.3fixed in linux 6.1.12-1 (bookworm)2023
CVE-2023-52738 [MEDIUM] CVE-2023-52738: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/... In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/fence: Fix oops due to non-matching drm_sched init/fini Currently amdgpu calls drm_sched_fini() from the fence driver sw fini routine - such function is expected to be called only after the respective init function - drm_sched_init() - was executed successfully. Happens that we faced a dr
debian
CVE-2023-53491P4MEDIUMCVSS 5.5fixed in linux 6.4.4-1 (forky)2023
CVE-2023-53491 [MEDIUM] CVE-2023-53491: linux - In the Linux kernel, the following vulnerability has been resolved: start_kerne... In the Linux kernel, the following vulnerability has been resolved: start_kernel: Add __no_stack_protector function attribute Back during the discussion of commit a9a3ed1eff36 ("x86: Fix early boot crash on gcc-10, third try") we discussed the need for a function attribute to control the omission of stack protectors on a per-function basis; at the time Clang had sup
debian
CVE-2021-47064P4MEDIUMCVSS 5.3fixed in linux 5.10.38-1 (bookworm)2021
CVE-2021-47064 [MEDIUM] CVE-2021-47064: linux - In the Linux kernel, the following vulnerability has been resolved: mt76: fix p... In the Linux kernel, the following vulnerability has been resolved: mt76: fix potential DMA mapping leak With buf uninitialized in mt76_dma_tx_queue_skb_raw, its field skip_unmap could potentially inherit a non-zero value from stack garbage. If this happens, it will cause DMA mappings for MCU command frames to not be unmapped after completion Scope: local bookworm:
debian
CVE-2023-3006P4MEDIUMCVSS 5.5fixed in linux 6.0.7-1 (bookworm)2023
CVE-2023-3006 [MEDIUM] CVE-2023-3006: linux - A known cache speculation vulnerability, known as Branch History Injection (BHI)... A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereOne. Spectre-BHB is similar to Spectre v2, except that malicious code uses the shared branch history (stored in the CPU Branch History Buffer, or BHB) to influence mispredicted branches within the victim's hardware context. Once th
debian
CVE-2025-71128P4LOWCVSS 5.5fixed in linux 6.18.5-1 (forky)2025
CVE-2025-71128 [MEDIUM] CVE-2025-71128: linux - In the Linux kernel, the following vulnerability has been resolved: erspan: Ini... In the Linux kernel, the following vulnerability has been resolved: erspan: Initialize options_len before referencing options. The struct ip_tunnel_info has a flexible array member named options that is protected by a counted_by(options_len) attribute. The compiler will use this information to enforce runtime bounds checking deployed by FORTIFY_SOURCE string helpers
debian
CVE-2023-1076P4MEDIUMCVSS 5.5fixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-1076 [MEDIUM] CVE-2023-1076: linux - A flaw was found in the Linux Kernel. The tun/tap sockets have their socket UID ... A flaw was found in the Linux Kernel. The tun/tap sockets have their socket UID hardcoded to 0 due to a type confusion in their initialization function. While it will be often correct, as tuntap devices require CAP_NET_ADMIN, it may not always be the case, e.g., a non-root user only having that capability. This would make tun/tap sockets being incorrectly treated in f
debian
CVE-2021-20320P4MEDIUMCVSS 5.5fixed in linux 5.14.9-1 (bookworm)2021
CVE-2021-20320 [MEDIUM] CVE-2021-20320: linux - A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.... A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem. Scope: local bookworm: resolved (fixed in 5.14.9-1) bullseye: resolved (fixed in 5.10.70-1) forky: resolved (fixed in 5.14.9-1) sid: re
debian
CVE-2024-50110P4MEDIUMCVSS 5.5fixed in linux 6.1.115-1 (bookworm)2024
CVE-2024-50110 [MEDIUM] CVE-2024-50110: linux - In the Linux kernel, the following vulnerability has been resolved: xfrm: fix o... In the Linux kernel, the following vulnerability has been resolved: xfrm: fix one more kernel-infoleak in algo dumping During fuzz testing, the following issue was discovered: BUG: KMSAN: kernel-infoleak in _copy_to_iter+0x598/0x2a30 _copy_to_iter+0x598/0x2a30 __skb_datagram_iter+0x168/0x1060 skb_copy_datagram_iter+0x5b/0x220 netlink_recvmsg+0x362/0x1700 sock_recvms
debian
CVE-2024-44931P4MEDIUMCVSS 5.5fixed in linux 6.1.112-1 (bookworm)2024
CVE-2024-44931 [MEDIUM] CVE-2024-44931: linux - In the Linux kernel, the following vulnerability has been resolved: gpio: preve... In the Linux kernel, the following vulnerability has been resolved: gpio: prevent potential speculation leaks in gpio_device_get_desc() Userspace may trigger a speculative read of an address outside the gpio descriptor array. Users can do that by calling gpio_ioctl() with an offset out of range. Offset is copied from user and then used as an array index to get the g
debian
CVE-2024-50039P4MEDIUMCVSS 5.5fixed in linux 6.1.115-1 (bookworm)2024
CVE-2024-50039 [MEDIUM] CVE-2024-50039: linux - In the Linux kernel, the following vulnerability has been resolved: net/sched: ... In the Linux kernel, the following vulnerability has been resolved: net/sched: accept TCA_STAB only for root qdisc Most qdiscs maintain their backlog using qdisc_pkt_len(skb) on the assumption it is invariant between the enqueue() and dequeue() handlers. Unfortunately syzbot can crash a host rather easily using a TBF + SFQ combination, with an STAB on SFQ [1] We can
debian
CVE-2021-46935P4MEDIUMCVSS 5.5fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-46935 [MEDIUM] CVE-2021-46935: linux - In the Linux kernel, the following vulnerability has been resolved: binder: fix... In the Linux kernel, the following vulnerability has been resolved: binder: fix async_free_space accounting for empty parcels In 4.13, commit 74310e06be4d ("android: binder: Move buffer out of area shared with user space") fixed a kernel structure visibility issue. As part of that patch, sizeof(void *) was used as the buffer size for 0-length data payloads so the dr
debian
CVE-2023-1637P4MEDIUMCVSS 5.5fixed in linux 5.17.3-1 (bookworm)2023
CVE-2023-1637 [MEDIUM] CVE-2023-1637: linux - A flaw that boot CPU could be vulnerable for the speculative execution behavior ... A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks in the Linux kernel X86 CPU Power management options functionality was found in the way user resuming CPU from suspend-to-RAM. A local user could use this flaw to potentially get unauthorized access to some memory of the CPU similar to the speculative execution behavior kin
debian
CVE-2025-37814P4LOWCVSS 5.5fixed in linux 6.12.27-1 (forky)2025
CVE-2025-37814 [MEDIUM] CVE-2025-37814: linux - In the Linux kernel, the following vulnerability has been resolved: tty: Requir... In the Linux kernel, the following vulnerability has been resolved: tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT This requirement was overeagerly loosened in commit 2f83e38a095f ("tty: Permit some TIOCL_SETSEL modes without CAP_SYS_ADMIN"), but as it turns out, (1) the logic I implemented there was inconsistent (apologies!), (2) TIOCL_SELMOUSERE
debian
CVE-2024-42317P4MEDIUMCVSS 5.5fixed in linux 6.10.3-1 (forky)2024
CVE-2024-42317 [MEDIUM] CVE-2024-42317: linux - In the Linux kernel, the following vulnerability has been resolved: mm/huge_mem... In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: avoid PMD-size page cache if needed xarray can't support arbitrary page cache size. the largest and supported page cache size is defined as MAX_PAGECACHE_ORDER by commit 099d90642a71 ("mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray"). However, it's possible to have 512MB p
debian
CVE-2025-37987P4LOWCVSS 5.5fixed in linux 6.12.27-1 (forky)2025
CVE-2025-37987 [MEDIUM] CVE-2025-37987: linux - In the Linux kernel, the following vulnerability has been resolved: pds_core: P... In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent possible adminq overflow/stuck condition The pds_core's adminq is protected by the adminq_lock, which prevents more than 1 command to be posted onto it at any one time. This makes it so the client drivers cannot simultaneously post adminq commands. However, the completions happen i
debian
CVE-2024-47689P4LOWCVSS 5.3fixed in linux 6.11.2-1 (forky)2024
CVE-2024-47689 [MEDIUM] CVE-2024-47689: linux - In the Linux kernel, the following vulnerability has been resolved: f2fs: fix t... In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to don't set SB_RDONLY in f2fs_handle_critical_error() syzbot reports a f2fs bug as below: ------------[ cut here ]------------ WARNING: CPU: 1 PID: 58 at kernel/rcu/sync.c:177 rcu_sync_dtor+0xcd/0x180 kernel/rcu/sync.c:177 CPU: 1 UID: 0 PID: 58 Comm: kworker/1:2 Not tainted 6.10.0-syzkall
debian
CVE-2021-47192P4MEDIUMCVSS 5.3fixed in linux 5.15.5-1 (bookworm)2021
CVE-2021-47192 [MEDIUM] CVE-2021-47192: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: core:... In the Linux kernel, the following vulnerability has been resolved: scsi: core: sysfs: Fix hang when device state is set via sysfs This fixes a regression added with: commit f0f82e2476f6 ("scsi: core: Fix capacity set to zero after offlinining device") The problem is that after iSCSI recovery, iscsid will call into the kernel to set the dev's state to running, and w
debian
CVE-2023-32255P4MEDIUMCVSS 5.3fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-32255 [MEDIUM] CVE-2023-32255: linux - A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur ... A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur if a client sends a session setup request with an unknown NTLMSSP message type, potentially leading to resource exhaustion. Scope: local bookworm: resolved (fixed in 6.1.37-1) bullseye: open forky: resolved (fixed in 6.3.7-1) sid: resolved (fixed in 6.3.7-1) trixie: resolved (fixed in 6.
debian
Debian Linux vulnerabilities | cvebase