cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 211 of 632
CVE-2022-42895P4MEDIUMCVSS 5.1fixed in linux 6.0.7-1 (bookworm)2022
CVE-2022-42895 [MEDIUM] CVE-2022-42895: linux - There is an infoleak vulnerability in the Linux kernel's net/bluetooth/l2cap_cor... There is an infoleak vulnerability in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_parse_conf_req function which can be used to leak kernel pointers remotely. We recommend upgrading past commit https://github.com/torvalds/linux/commit/b1a2cd50c0357f243b7435a732b4e62ba3157a2e https://www.google.com/url Scope: local bookworm: resolved (fixed in 6.0.7-1) bulls
debian
CVE-2024-50102P4LOWCVSS 7.5fixed in linux 6.11.6-1 (forky)2024
CVE-2024-50102 [HIGH] CVE-2024-50102: linux - In the Linux kernel, the following vulnerability has been resolved: x86: fix us... In the Linux kernel, the following vulnerability has been resolved: x86: fix user address masking non-canonical speculation issue It turns out that AMD has a "Meltdown Lite(tm)" issue with non-canonical accesses in kernel space. And so using just the high bit to decide whether an access is in user space or kernel space ends up with the good old "leak speculative data"
debian
CVE-2014-8173P4HIGHCVSS 7.2fixed in linux 3.13.4-1 (bookworm)2014
CVE-2014-8173 [HIGH] CVE-2014-8173: linux - The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.... The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.h in the Linux kernel before 3.13 on NUMA systems does not properly determine whether a Page Middle Directory (PMD) entry is a transparent huge-table entry, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other im
debian
CVE-2025-68816P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-68816 CVE-2025-68816: linux - In the Linux kernel, the following vulnerability has been resolved: net/mlx5: f... In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, Validate format string parameters Add validation for format string parameters in the firmware tracer to prevent potential security vulnerabilities and crashes from malformed format strings received from firmware. The firmware tracer receives format strings from the device firmware and us
debian
CVE-2019-19081P4MEDIUMCVSS 5.9fixed in linux 5.3.7-1 (bookworm)2019
CVE-2019-19081 [MEDIUM] CVE-2019-19081: linux - A memory leak in the nfp_flower_spawn_vnic_reprs() function in drivers/net/ether... A memory leak in the nfp_flower_spawn_vnic_reprs() function in drivers/net/ethernet/netronome/nfp/flower/main.c in the Linux kernel before 5.3.4 allows attackers to cause a denial of service (memory consumption), aka CID-8ce39eb5a67a. Scope: local bookworm: resolved (fixed in 5.3.7-1) bullseye: resolved (fixed in 5.3.7-1) forky: resolved (fixed in 5.3.7-1) sid: reso
debian
CVE-2022-48881P4HIGHCVSS 7.1fixed in linux 6.1.7-1 (bookworm)2022
CVE-2022-48881 [HIGH] CVE-2022-48881: linux - In the Linux kernel, the following vulnerability has been resolved: platform/x8... In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd: Fix refcount leak in amd_pmc_probe pci_get_domain_bus_and_slot() takes reference, the caller should release the reference by calling pci_dev_put() after use. Call pci_dev_put() in the error path to fix this. Scope: local bookworm: resolved (fixed in 6.1.7-1) bullseye: resolved forky:
debian
CVE-2013-1796P4MEDIUMCVSS 6.8fixed in linux 3.2.41-2 (bookworm)2013
CVE-2013-1796 [MEDIUM] CVE-2013-1796: linux - The kvm_set_msr_common function in arch/x86/kvm/x86.c in the Linux kernel throug... The kvm_set_msr_common function in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 does not ensure a required time_page alignment during an MSR_KVM_SYSTEM_TIME operation, which allows guest OS users to cause a denial of service (buffer overflow and host OS memory corruption) or possibly have unspecified other impact via a crafted application. Scope: local bookwor
debian
CVE-2022-3567P4MEDIUMCVSS 4.6fixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-3567 [MEDIUM] CVE-2022-3567: linux - A vulnerability has been found in Linux Kernel and classified as problematic. Th... A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function inet6_stream_ops/inet6_dgram_ops of the component IPv6 Handler. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. VDB-211090 is the identifier assigned to this vulnerability. Scope: local bookworm: resolved
debian
CVE-2014-8159P4MEDIUMCVSS 6.9fixed in linux 3.16.7-ckt9-1 (bookworm)2014
CVE-2014-8159 [MEDIUM] CVE-2014-8159: linux - The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504... The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging pe
debian
CVE-2013-1979P4MEDIUMCVSS 6.9fixed in linux 3.8.11-1 (bookworm)2013
CVE-2013-1979 [MEDIUM] CVE-2013-1979: linux - The scm_set_cred function in include/net/scm.h in the Linux kernel before 3.8.11... The scm_set_cred function in include/net/scm.h in the Linux kernel before 3.8.11 uses incorrect uid and gid values during credentials passing, which allows local users to gain privileges via a crafted application. Scope: local bookworm: resolved (fixed in 3.8.11-1) bullseye: resolved (fixed in 3.8.11-1) forky: resolved (fixed in 3.8.11-1) sid: resolved (fixed in 3.8.1
debian
CVE-2018-20169P4MEDIUMCVSS 6.8fixed in linux 4.19.9-1 (bookworm)2018
CVE-2018-20169 [MEDIUM] CVE-2018-20169: linux - An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mis... An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c. Scope: local bookworm: resolved (fixed in 4.19.9-1) bullseye: resolved (fixed in 4.19.9-1) forky: resolved (fixed in 4.19.9-1) sid: resolved (fixed in 4.19.9-1)
debian
CVE-2015-8816P4MEDIUMCVSS 6.8fixed in linux 4.4.2-1 (bookworm)2015
CVE-2015-8816 [MEDIUM] CVE-2015-8816: linux - The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4... The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device. Scope: local bookworm: resolved (fixed
debian
CVE-2021-38199P4MEDIUMCVSS 6.5fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-38199 [MEDIUM] CVE-2021-38199: linux - fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-s... fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection. Scope: local bookworm: resolved (fixed in 5.14.6-1) bullseye: resolved (fixed in 5.10.46-5) forky: re
debian
CVE-2021-38204P4LOWCVSS 6.8fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-38204 [MEDIUM] CVE-2021-38204: linux - drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physical... drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations. Scope: local bookworm: resolved (fixed in 5.14.6-1) bullseye: resolved (fixed in 5.10.70-1) forky: resolved (fixed in 5.14.6-1) sid: resolved (fixed in
debian
CVE-2022-1789P4MEDIUMCVSS 6.8fixed in linux 5.17.11-1 (bookworm)2022
CVE-2022-1789 [MEDIUM] CVE-2022-1789: linux - With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu... With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 5.17.11-1) bullseye: resolved (fixed in 5.10.120-1) forky: resolved (fixed in 5.17.11-1) sid: resolved (fixed in 5.17.1
debian
CVE-2015-7513P4MEDIUMCVSS 6.5fixed in linux 4.3.3-3 (bookworm)2015
CVE-2015-7513 [MEDIUM] CVE-2015-7513: linux - arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter... arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related to the kvm_vm_ioctl_set_pit and kvm_vm_ioctl_set_pit2 functions. Scope: local bookworm: resolved (fixed in 4.3.3-3) bullseye: resolv
debian
CVE-2017-12190P4MEDIUMCVSS 6.5fixed in linux 4.13.10-1 (bookworm)2017
CVE-2017-12190 [MEDIUM] CVE-2017-12190: linux - The bio_map_user_iov and bio_unmap_user functions in block/bio.c in the Linux ke... The bio_map_user_iov and bio_unmap_user functions in block/bio.c in the Linux kernel before 4.13.8 do unbalanced refcounting when a SCSI I/O vector has small consecutive buffers belonging to the same page. The bio_add_pc_page function merges them into one, but the page reference is never dropped. This causes a memory leak and possible system lockup (exploitable agai
debian
CVE-2021-47230P4MEDIUMCVSS 6.6fixed in linux 5.10.46-1 (bookworm)2021
CVE-2021-47230 [MEDIUM] CVE-2021-47230: linux - In the Linux kernel, the following vulnerability has been resolved: KVM: x86: I... In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Immediately reset the MMU context when the SMM flag is cleared Immediately reset the MMU context when the vCPU's SMM flag is cleared so that the SMM flag in the MMU role is always synchronized with the vCPU's flag. If RSM fails (which isn't correctly emulated), KVM will bail without callin
debian
CVE-2021-28039P4LOWCVSS 6.5fixed in linux 5.10.24-1 (bookworm)2021
CVE-2021-28039 [MEDIUM] CVE-2021-28039: linux - An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with X... An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical addresses when a configuration has CONFIG_XEN_UNPOPULATED_ALLOC but not CONFIG_XEN_BALLOON_MEMORY_HOTPLUG. S
debian
CVE-2019-17351P4MEDIUMCVSS 6.5fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-17351 [MEDIUM] CVE-2019-17351: linux - An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.... An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause a denial of service because of unrestricted resource consumption during the mapping of guest memory, aka CID-6ef36ab967c7. Scope: local bookworm: resolved (fixed in 5.2.6-1) bullseye: resolved (fixed in 5.2.6-1) forky: re
debian
Debian Linux vulnerabilities | cvebase