Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 212 of 632
CVE-2020-29568P4MEDIUMCVSS 6.5fixed in linux 5.9.15-1 (bookworm)2020
CVE-2020-29568 [MEDIUM] CVE-2020-29568: linux - An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD...
An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they will get queued. As the queue is unbounded, a guest may be able to trigger an OOM in the backend. All systems with a FreeBSD, Linux, or NetBSD (any v
debian
CVE-2020-8834P4MEDIUMCVSS 6.5fixed in linux 4.18.6-1 (bookworm)2020
CVE-2020-8834 [MEDIUM] CVE-2020-8834: linux - KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOS...
KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of this, an attacker with the ability run code in kernel space of a guest VM can cause the host kernel to panic. There were two commits that, according to the reporter, introd
debian
CVE-2021-28711P4MEDIUMCVSS 6.5fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-28711 [MEDIUM] CVE-2021-28711: linux - Rogue backends can cause DoS of guests via high frequency events T[his CNA infor...
Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically referred to as "driver domains". Running PV backends in driver domains has one primary sec
debian
CVE-2021-28712P4MEDIUMCVSS 6.5fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-28712 [MEDIUM] CVE-2021-28712: linux - Rogue backends can cause DoS of guests via high frequency events T[his CNA infor...
Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically referred to as "driver domains". Running PV backends in driver domains has one primary sec
debian
CVE-2021-28713P4MEDIUMCVSS 6.5fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-28713 [MEDIUM] CVE-2021-28713: linux - Rogue backends can cause DoS of guests via high frequency events T[his CNA infor...
Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically referred to as "driver domains". Running PV backends in driver domains has one primary sec
debian
CVE-2022-48711P4HIGHCVSS 8.8fixed in linux 5.16.10-1 (bookworm)2022
CVE-2022-48711 [HIGH] CVE-2022-48711: linux - In the Linux kernel, the following vulnerability has been resolved: tipc: impro...
In the Linux kernel, the following vulnerability has been resolved: tipc: improve size validations for received domain records The function tipc_mon_rcv() allows a node to receive and process domain_record structs from peer nodes to track their views of the network topology. This patch verifies that the number of members in a received domain record does not exceed the
debian
CVE-2024-36968P4MEDIUMCVSS 6.5fixed in linux 6.8.11-1 (forky)2024
CVE-2024-36968 [MEDIUM] CVE-2024-36968: linux - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ...
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init() l2cap_le_flowctl_init() can cause both div-by-zero and an integer overflow since hdev->le_mtu may not fall in the valid range. Move MTU from hci_dev to hci_conn to validate MTU and stop the connection process earlier if MTU is invalid. Als
debian
CVE-2018-14609P4MEDIUMCVSS 5.5fixed in linux 4.18.8-1 (bookworm)2018
CVE-2018-14609 [MEDIUM] CVE-2018-14609: linux - An issue was discovered in the Linux kernel through 4.17.10. There is an invalid...
An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in __del_reloc_root() in fs/btrfs/relocation.c when mounting a crafted btrfs image, related to removing reloc rb_trees when reloc control has not been initialized.
Scope: local
bookworm: resolved (fixed in 4.18.8-1)
bullseye: resolved (fixed in 4.18.8-1)
forky: resol
debian
CVE-2018-13096P4MEDIUMCVSS 5.5fixed in linux 4.19.9-1 (bookworm)2018
CVE-2018-13096 [MEDIUM] CVE-2018-13096: linux - An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.14. A d...
An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.14. A denial of service (out-of-bounds memory access and BUG) can occur upon encountering an abnormal bitmap size when mounting a crafted f2fs image.
Scope: local
bookworm: resolved (fixed in 4.19.9-1)
bullseye: resolved (fixed in 4.19.9-1)
forky: resolved (fixed in 4.19.9-1)
sid: resolved (fix
debian
CVE-2018-14611P4MEDIUMCVSS 5.5fixed in linux 4.19.9-1 (bookworm)2018
CVE-2018-14611 [MEDIUM] CVE-2018-14611: linux - An issue was discovered in the Linux kernel through 4.17.10. There is a use-afte...
An issue was discovered in the Linux kernel through 4.17.10. There is a use-after-free in try_merge_free_space() when mounting a crafted btrfs image, because of a lack of chunk type flag checks in btrfs_check_chunk_valid in fs/btrfs/volumes.c.
Scope: local
bookworm: resolved (fixed in 4.19.9-1)
bullseye: resolved (fixed in 4.19.9-1)
forky: resolved (fixed in 4.19.9-
debian
CVE-2026-23230P4HIGHCVSS 8.8fixed in linux 6.1.164-1 (bookworm)2026
CVE-2026-23230 [HIGH] CVE-2026-23230: linux - In the Linux kernel, the following vulnerability has been resolved: smb: client...
In the Linux kernel, the following vulnerability has been resolved: smb: client: split cached_fid bitfields to avoid shared-byte RMW races is_open, has_lease and on_list are stored in the same bitfield byte in struct cached_fid but are updated in different code paths that may run concurrently. Bitfield assignments generate byte read–modify–write operations (e.g. `orb
debian
CVE-2015-8215P4MEDIUMCVSS 5.0fixed in linux 4.0.2-1 (bookworm)2015
CVE-2015-8215 [MEDIUM] CVE-2015-8215: linux - net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0 does not va...
net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0 does not validate attempted changes to the MTU value, which allows context-dependent attackers to cause a denial of service (packet loss) via a value that is (1) smaller than the minimum compliant value or (2) larger than the MTU of an interface, as demonstrated by a Router Advertisement (RA) message
debian
CVE-2016-4482P4MEDIUMCVSS 6.2fixed in linux 4.5.5-1 (bookworm)2016
CVE-2016-4482 [MEDIUM] CVE-2016-4482: linux - The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel th...
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.
Scope: local
bookworm: resolved (fixed in 4.5.5-1)
bullseye: resolved (fixed in 4.5.5-1)
forky: resolved
debian
CVE-2024-42161P4MEDIUMCVSS 6.3fixed in linux 6.1.98-1 (bookworm)2024
CVE-2024-42161 [MEDIUM] CVE-2024-42161: linux - In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid ...
In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid uninitialized value in BPF_CORE_READ_BITFIELD [Changes from V1: - Use a default branch in the switch statement to initialize `val'.] GCC warns that `val' may be used uninitialized in the BPF_CRE_READ_BITFIELD macro, defined in bpf_core_read.h as: [...] unsigned long long val; \ [...] \ sw
debian
CVE-2016-8658P4MEDIUMCVSS 6.1fixed in linux 4.7.5-1 (bookworm)2016
CVE-2016-8658 [MEDIUM] CVE-2016-8658: linux - Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/n...
Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.7.5 allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a long SSID Information Element in a command to a Netlink socket.
Scope: local
bookworm: resolved
debian
CVE-2019-19813P4MEDIUMCVSS 5.5fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-19813 [MEDIUM] CVE-2019-19813: linux - In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performin...
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner in kernel/locking/mutex.c, __btrfs_qgroup_free_meta in fs/btrfs/qgroup.c, and btrfs_insert_delayed_items in fs/btrfs/
debian
CVE-2019-19767P4MEDIUMCVSS 5.5fixed in linux 5.3.15-1 (bookworm)2019
CVE-2019-19767 [MEDIUM] CVE-2019-19767: linux - The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrate...
The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry, related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
Scope: local
bookworm: resolved (fixed in 5.3.15-1)
bullseye: resolved (fixed in 5.3.15-1)
forky: resolved (fixed in 5.3.15-1)
sid: reso
debian
CVE-2024-39490P4MEDIUMCVSS 6.2fixed in linux 6.1.94-1 (bookworm)2024
CVE-2024-39490 [MEDIUM] CVE-2024-39490: linux - In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: f...
In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix missing sk_buff release in seg6_input_core The seg6_input() function is responsible for adding the SRH into a packet, delegating the operation to the seg6_input_core(). This function uses the skb_cow_head() to ensure that there is sufficient headroom in the sk_buff for accommodating th
debian
CVE-2020-27171P4MEDIUMCVSS 6.0fixed in linux 5.10.24-1 (bookworm)2020
CVE-2020-27171 [MEDIUM] CVE-2020-27171: linux - An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c...
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-10d2bb2e6b1d.
Scope: local
bookworm: resol
debian
CVE-2020-25211P4MEDIUMCVSS 6.0fixed in linux 5.8.14-1 (bookworm)2020
CVE-2020-25211 [MEDIUM] CVE-2020-25211: linux - In the Linux kernel through 5.8.7, local attackers able to inject conntrack netl...
In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netlink.c, aka CID-1cc5ef91d2ff.
Scope: local
bookworm: resolved (fixed in 5.8.14-1)
bullseye: resolved (fixed in
debian