cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 213 of 632
CVE-2019-3837P4MEDIUMCVSS 6.1fixed in linux 3.13.4-1 (bookworm)2019
CVE-2019-3837 [MEDIUM] CVE-2019-3837: linux - It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as ship... It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unprivileged multi-threaded userspace application calling recvmsg() for the same network socket in parallel executed on ioatdma-enabled hardware with net_dma enabled can leak the memory, crash the host leading to a denial-of-service or cause a random me
debian
CVE-2016-7915P4MEDIUMCVSS 5.5fixed in linux 4.6.1-1 (bookworm)2016
CVE-2016-7915 [MEDIUM] CVE-2016-7915: linux - The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel befor... The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) by connecting a device, as demonstrated by a Logitech DJ receiver. Scope: local bookworm: resolved (fixed in 4.6.1-1) bullseye: resolved (fixed i
debian
CVE-2022-1508P4MEDIUMCVSS 6.1fixed in linux 5.15.3-1 (bookworm)2022
CVE-2022-1508 [MEDIUM] CVE-2022-1508: linux - An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in th... An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This flaw allows a local user to read some memory out of bounds. Scope: local bookworm: resolved (fixed in 5.15.3-1) bullseye: resolved (fixed in 5.10.120-1) forky: resolved (fixed in 5.15.3-1) sid: resolved (fixed
debian
CVE-2020-28097P4MEDIUMCVSS 5.9fixed in linux 5.8.10-1 (bookworm)2020
CVE-2020-28097 [MEDIUM] CVE-2020-28097: linux - The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrol... The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out-of-bounds read, aka CID-973c096f6a85. Scope: local bookworm: resolved (fixed in 5.8.10-1) bullseye: resolved (fixed in 5.8.10-1) forky: resolved (fixed in 5.8.10-1) sid: resolved (fixed in 5.8.10-1) trixie: resolved (fixed in 5.8.10-1)
debian
CVE-2024-26894P4MEDIUMCVSS 6.0fixed in linux 6.1.85-1 (bookworm)2024
CVE-2024-26894 [MEDIUM] CVE-2024-26894: linux - In the Linux kernel, the following vulnerability has been resolved: ACPI: proce... In the Linux kernel, the following vulnerability has been resolved: ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit() After unregistering the CPU idle device, the memory associated with it is not freed, leading to a memory leak: unreferenced object 0xffff896282f6c000 (size 1024): comm "swapper/0", pid 1, jiffies 4294893170 hex dump (first 32 bytes
debian
CVE-2020-8649P4MEDIUMCVSS 5.9fixed in linux 5.5.13-1 (bookworm)2020
CVE-2020-8649 [MEDIUM] CVE-2020-8649: linux - There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the... There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c. Scope: local bookworm: resolved (fixed in 5.5.13-1) bullseye: resolved (fixed in 5.5.13-1) forky: resolved (fixed in 5.5.13-1) sid: resolved (fixed in 5.5.13-1) trixie: resolved (fixed in 5.5.13-1)
debian
CVE-2019-14615P4MEDIUMCVSS 5.5fixed in linux 5.4.13-1 (bookworm)2019
CVE-2019-14615 [MEDIUM] CVE-2019-14615: linux - Insufficient control flow in certain data structures for some Intel(R) Processor... Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access. Scope: local bookworm: resolved (fixed in 5.4.13-1) bullseye: resolved (fixed in 5.4.13-1) forky: resolved (fixed in 5.4.13-1) sid: resolved (fixed in 5.4.1
debian
CVE-2021-0129P4MEDIUMCVSS 5.7fixed in bluez 5.55-3.1 (bookworm)2021
CVE-2021-0129 [MEDIUM] CVE-2021-0129: bluez - Improper access control in BlueZ may allow an authenticated user to potentially ... Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access. Scope: local bookworm: resolved (fixed in 5.55-3.1) bullseye: resolved (fixed in 5.55-3.1) forky: resolved (fixed in 5.55-3.1) sid: resolved (fixed in 5.55-3.1) trixie: resolved (fixed in 5.55-3.1)
debian
CVE-2022-25375P4MEDIUMCVSS 5.5fixed in linux 5.16.10-1 (bookworm)2022
CVE-2022-25375 [MEDIUM] CVE-2022-25375: linux - An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kern... An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory. Scope: local bookworm: resolved (fixed in 5.16.10-1) bullseye: resolved (fixed in 5.10.92-2) forky: resolved (fixed in 5.16.10
debian
CVE-2023-1206P4MEDIUMCVSS 5.7fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-1206 [MEDIUM] CVE-2023-1206: linux - A hash collision flaw was found in the IPv6 connection lookup table in the Linux... A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that accepts IPV6 connections up to 95%. Scope: local bookworm: resolved (fixed in 6.1.52-1) bulls
debian
CVE-2018-3665P4MEDIUMCVSS 5.6fixed in linux 4.6.1-1 (bookworm)2018
CVE-2018-3665 [MEDIUM] CVE-2018-3665: linux - System software utilizing Lazy FP state restore technique on systems using Intel... System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel. Scope: local bookworm: resolved (fixed in 4.6.1-1) bullseye: resolved (fixed in 4.6.1-1) forky: resolved (fixed in 4.6.1-1) sid: resolved (fixe
debian
CVE-2019-7308P4MEDIUMCVSS 5.6fixed in linux 4.19.20-1 (bookworm)2019
CVE-2019-7308 [MEDIUM] CVE-2019-7308: linux - kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out... kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks. Scope: local bookworm: resolved (fixed in 4.19.20-1) bullseye: resolved (fixed in 4.19.20-1) forky: resolved (fi
debian
CVE-2017-1000380P4MEDIUMCVSS 5.5fixed in linux 4.11.6-1 (bookworm)2017
CVE-2017-1000380 [MEDIUM] CVE-2017-1000380: linux - sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data rac... sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time. Scope: local bookworm: resolved (fixed in 4.11.6-1) bullseye: r
debian
CVE-2025-39889P4HIGHCVSS 8.1fixed in linux 6.1.135-1 (bookworm)2025
CVE-2025-39889 [HIGH] CVE-2025-39889: linux - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ... In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on incoming connection This is required for passing GAP/SEC/SEM/BI-04-C PTS test case: Security Mode 4 Level 4, Responder - Invalid Encryption Key Size - 128 bit This tests the security key with size from 1 to 15 bytes while the Security Mode 4 Level 4 reque
debian
CVE-2017-18549P4MEDIUMCVSS 5.5fixed in linux 4.13.4-1 (bookworm)2017
CVE-2017-18549 [MEDIUM] CVE-2017-18549: linux - An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel b... An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory because aac_send_raw_srb does not initialize the reply structure. Scope: local bookworm: resolved (fixed in 4.13.4-1) bullseye: resolved (fixed in 4.13.4-1) forky: resolved (fixed in 4.13.4-1) sid: resolved (fixed in 4.13.4-1
debian
CVE-2018-16658P4MEDIUMCVSS 5.5fixed in linux 4.18.6-1 (bookworm)2018
CVE-2018-16658 [MEDIUM] CVE-2018-16658: linux - An issue was discovered in the Linux kernel before 4.18.6. An information leak i... An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. This is similar to CVE-2018-10940. Scope: local bookworm: resolved (fixed in 4.18.6-1) bullseye: resolved (
debian
CVE-2017-18550P4MEDIUMCVSS 5.5fixed in linux 4.13.4-1 (bookworm)2017
CVE-2017-18550 [MEDIUM] CVE-2017-18550: linux - An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel b... An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory because aac_get_hba_info does not initialize the hbainfo structure. Scope: local bookworm: resolved (fixed in 4.13.4-1) bullseye: resolved (fixed in 4.13.4-1) forky: resolved (fixed in 4.13.4-1) sid: resolved (fixed in 4.13.4
debian
CVE-2023-52636P4LOWCVSS 5.5fixed in linux 6.7.7-1 (forky)2023
CVE-2023-52636 [MEDIUM] CVE-2023-52636: linux - In the Linux kernel, the following vulnerability has been resolved: libceph: ju... In the Linux kernel, the following vulnerability has been resolved: libceph: just wait for more data to be available on the socket A short read may occur while reading the message footer from the socket. Later, when the socket is ready for another read, the messenger invokes all read_partial_*() handlers, including read_partial_sparse_msg_data(). The expectation is
debian
CVE-2017-14140P4MEDIUMCVSS 5.5fixed in linux 4.12.12-1 (bookworm)2017
CVE-2017-14140 [MEDIUM] CVE-2017-14140: linux - The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doe... The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the target process, enabling a local attacker to learn the memory layout of a setuid executable despite ASLR. Scope: local bookworm: resolved (fixed in 4.12.12-1) bullseye: resolved (fixed in 4.12.12-1) forky: resolved (fixed in 4.12.12-1) sid: resolved (f
debian
CVE-2022-0854P4MEDIUMCVSS 5.5fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-0854 [MEDIUM] CVE-2022-0854: linux - A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a u... A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space. Scope: local bookworm: resolved (fixed in 5.17.3-1) bullseye: resolved (fixed in 5.10.120-1) forky: resolved (fixed in 5.17.3-1) sid: resolved (fixed in 5.17.3-1) trixie: resolved (fixed i
debian
Debian Linux vulnerabilities | cvebase