Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 214 of 632
CVE-2021-35477P4MEDIUMCVSS 5.5fixed in linux 5.10.46-4 (bookworm)2021
CVE-2021-35477 [MEDIUM] CVE-2021-35477: linux - In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensi...
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not necessarily occur before a store operation that has an attacker-controlled value.
Scope: local
bookworm: resolved (fixed in 5.10.46-4)
bullseye: re
debian
CVE-2017-13693P4LOWCVSS 5.5fixed in acpica-unix 20180209-1 (bookworm)2017
CVE-2017-13693 [MEDIUM] CVE-2017-13693: acpica-unix - The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the L...
The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.
Scope: local
bookw
debian
CVE-2017-13695P4LOWCVSS 5.5fixed in acpica-unix 20180209-1 (bookworm)2017
CVE-2017-13695 [MEDIUM] CVE-2017-13695: acpica-unix - The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux ker...
The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.
Scope: local
bookworm: res
debian
CVE-2017-13694P4LOWCVSS 5.5fixed in acpica-unix 20180209-1 (bookworm)2017
CVE-2017-13694 [MEDIUM] CVE-2017-13694: acpica-unix - The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in th...
The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext caches and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.
Scop
debian
CVE-2019-2101P4MEDIUMCVSS 5.5fixed in linux 4.19.37-1 (bookworm)2019
CVE-2019-2101 [MEDIUM] CVE-2019-2101: linux - In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound ...
In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-111760968.
Scope: local
bookworm: resolved (fixe
debian
CVE-2024-26921P4MEDIUMCVSS 5.5fixed in linux 6.1.85-1 (bookworm)2024
CVE-2024-26921 [MEDIUM] CVE-2024-26921: linux - In the Linux kernel, the following vulnerability has been resolved: inet: inet_...
In the Linux kernel, the following vulnerability has been resolved: inet: inet_defrag: prevent sk release while still in use ip_local_out() and other functions can pass skb->sk as function argument. If the skb is a fragment and reassembly happens before such function call returns, the sk must not be released. This affects skb fragments reassembled via netfilter or s
debian
CVE-2024-38582P4MEDIUMCVSS 5.3fixed in linux 6.1.94-1 (bookworm)2024
CVE-2024-38582 [MEDIUM] CVE-2024-38582: linux - In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix...
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential hang in nilfs_detach_log_writer() Syzbot has reported a potential hang in nilfs_detach_log_writer() called during nilfs2 unmount. Analysis revealed that this is because nilfs_segctor_sync(), which synchronizes with the log writer thread, can be called after nilfs_segctor_destro
debian
CVE-2023-52511P4MEDIUMCVSS 5.3fixed in linux 6.1.64-1 (bookworm)2023
CVE-2023-52511 [MEDIUM] CVE-2023-52511: linux - In the Linux kernel, the following vulnerability has been resolved: spi: sun6i:...
In the Linux kernel, the following vulnerability has been resolved: spi: sun6i: reduce DMA RX transfer width to single byte Through empirical testing it has been determined that sometimes RX SPI transfers with DMA enabled return corrupted data. This is down to single or even multiple bytes lost during DMA transfer from SPI peripheral to memory. It seems the RX FIFO
debian
CVE-2023-4515P4MEDIUMCVSS 5.5fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-4515 [MEDIUM] CVE-2023-4515: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: vali...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate command request size In commit 2b9b8f3b68ed ("ksmbd: validate command payload size"), except for SMB2_OPLOCK_BREAK_HE command, the request size of other commands is not checked, it's not expected. Fix it by add check for request size of other commands.
Scope: local
bookworm: resolved (
debian
CVE-2021-4155P4MEDIUMCVSS 5.5fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-4155 [MEDIUM] CVE-2021-4155: linux - A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS filesyste...
A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS filesystem allowed for size increase of files with unaligned size. A local attacker could use this flaw to leak data on the XFS filesystem otherwise not accessible to them.
Scope: local
bookworm: resolved (fixed in 5.15.15-1)
bullseye: resolved (fixed in 5.10.92-1)
forky: resolved (fixed in 5.15.15
debian
CVE-2024-41030P4MEDIUMCVSS 5.5fixed in linux 6.1.106-1 (bookworm)2024
CVE-2024-41030 [MEDIUM] CVE-2024-41030: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: disc...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: discard write access to the directory open may_open() does not allow a directory to be opened with the write access. However, some writing flags set by client result in adding write access on server, making ksmbd incompatible with FUSE file system. Simply, let's discard the write access when
debian
CVE-2022-49266P4MEDIUMCVSS 5.5fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-49266 [MEDIUM] CVE-2022-49266: linux - In the Linux kernel, the following vulnerability has been resolved: block: fix ...
In the Linux kernel, the following vulnerability has been resolved: block: fix rq-qos breakage from skipping rq_qos_done_bio() a647a524a467 ("block: don't call rq_qos_ops->done_bio if the bio isn't tracked") made bio_endio() skip rq_qos_done_bio() if BIO_TRACKED is not set. While this fixed a potential oops, it also broke blk-iocost by skipping the done_bio callback
debian
CVE-2024-41038P4MEDIUMCVSS 5.5fixed in linux 6.1.106-1 (bookworm)2024
CVE-2024-41038 [MEDIUM] CVE-2024-41038: linux - In the Linux kernel, the following vulnerability has been resolved: firmware: c...
In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Prevent buffer overrun when processing V2 alg headers Check that all fields of a V2 algorithm header fit into the available firmware data buffer. The wmfw V2 format introduced variable-length strings in the algorithm block header. This means the overall header length is variable, a
debian
CVE-2023-23586P4MEDIUMCVSS 5.5fixed in linux 5.14.6-1 (bookworm)2023
CVE-2023-23586 [MEDIUM] CVE-2023-23586: linux - Due to a vulnerability in the io_uring subsystem, it is possible to leak kernel ...
Due to a vulnerability in the io_uring subsystem, it is possible to leak kernel memory information to the user process. timens_install calls current_is_single_threaded to determine if the current process is single-threaded, but this call does not consider io_uring's io_worker threads, thus it is possible to insert a time namespace's vvar page to process's memory spa
debian
CVE-2024-41029P4LOWCVSS 5.5fixed in linux 6.9.10-1 (forky)2024
CVE-2024-41029 [MEDIUM] CVE-2024-41029: linux - In the Linux kernel, the following vulnerability has been resolved: nvmem: core...
In the Linux kernel, the following vulnerability has been resolved: nvmem: core: limit cell sysfs permissions to main attribute ones The cell sysfs attribute should not provide more access to the nvmem data than the main attribute itself. For example if nvme_config::root_only was set, the cell attribute would still provide read access to everybody. Mask out permissi
debian
CVE-2022-48730P4MEDIUMCVSS 5.5fixed in linux 5.16.10-1 (bookworm)2022
CVE-2022-48730 [MEDIUM] CVE-2022-48730: linux - In the Linux kernel, the following vulnerability has been resolved: dma-buf: he...
In the Linux kernel, the following vulnerability has been resolved: dma-buf: heaps: Fix potential spectre v1 gadget It appears like nr could be a Spectre v1 gadget as it's supplied by a user and used as an array index. Prevent the contents of kernel memory from being leaked to userspace via speculative execution by using array_index_nospec. [sumits: added fixes and
debian
CVE-2022-0264P4MEDIUMCVSS 5.5fixed in linux 5.15.5-2 (bookworm)2022
CVE-2022-0264 [MEDIUM] CVE-2022-0264: linux - A vulnerability was found in the Linux kernel's eBPF verifier when handling inte...
A vulnerability was found in the Linux kernel's eBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel. This flaws affects
debian
CVE-2021-47597P4MEDIUMCVSS 5.5fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-47597 [MEDIUM] CVE-2021-47597: linux - In the Linux kernel, the following vulnerability has been resolved: inet_diag: ...
In the Linux kernel, the following vulnerability has been resolved: inet_diag: fix kernel-infoleak for UDP sockets KMSAN reported a kernel-infoleak [1], that can exploited by unpriv users. After analysis it turned out UDP was not initializing r->idiag_expires. Other users of inet_sk_diag_fill() might make the same mistake in the future, so fix this in inet_sk_diag_f
debian
CVE-2021-47401P4MEDIUMCVSS 5.5fixed in linux 5.14.12-1 (bookworm)2021
CVE-2021-47401 [MEDIUM] CVE-2021-47401: linux - In the Linux kernel, the following vulnerability has been resolved: ipack: ipoc...
In the Linux kernel, the following vulnerability has been resolved: ipack: ipoctal: fix stack information leak The tty driver name is used also after registering the driver and must specifically not be allocated on the stack to avoid leaking information to user space (or triggering an oops). Drivers should not try to encode topology information in the tty device nam
debian
CVE-2022-48687P4MEDIUMCVSS 5.5fixed in linux 5.19.11-1 (bookworm)2022
CVE-2022-48687 [MEDIUM] CVE-2022-48687: linux - In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: f...
In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix out-of-bounds read when setting HMAC data. The SRv6 layer allows defining HMAC data that can later be used to sign IPv6 Segment Routing Headers. This configuration is realised via netlink through four attributes: SEG6_ATTR_HMACKEYID, SEG6_ATTR_SECRET, SEG6_ATTR_SECRETLEN and SEG6_ATTR_
debian