Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 217 of 632
CVE-2023-33951P4MEDIUMCVSS 6.7fixed in linux 6.1.15-1 (bookworm)2023
CVE-2023-33951 [MEDIUM] CVE-2023-33951: linux - A race condition vulnerability was found in the vmwgfx driver in the Linux kerne...
A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.
Scope: local
bookworm: resolved (fixed in 6.1.15-1)
bulls
debian
CVE-2017-16538P4MEDIUMCVSS 6.6fixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-16538 [MEDIUM] CVE-2017-16538: linux - drivers/media/usb/dvb-usb-v2/lmedm04.c in the Linux kernel through 4.13.11 allow...
drivers/media/usb/dvb-usb-v2/lmedm04.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device, related to a missing warm-start check and incorrect attach timing (dm04_lme2510_frontend_attach versus dm04_lme2510_tuner).
Scope: lo
debian
CVE-2017-16525P4MEDIUMCVSS 6.6fixed in linux 4.13.10-1 (bookworm)2017
CVE-2017-16525 [MEDIUM] CVE-2017-16525: linux - The usb_serial_console_disconnect function in drivers/usb/serial/console.c in th...
The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device, related to disconnection and failed setup.
Scope: local
bookworm: resolved (fixed in 4.13.10-1)
bullseye: res
debian
CVE-2024-26886P4MEDIUMCVSS 6.5fixed in linux 6.1.85-1 (bookworm)2024
CVE-2024-26886 [MEDIUM] CVE-2024-26886: linux - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ...
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: af_bluetooth: Fix deadlock Attemting to do sock_lock on .recvmsg may cause a deadlock as shown bellow, so instead of using sock_sock this uses sk_receive_queue.lock on bt_sock_ioctl to avoid the UAF: INFO: task kworker/u9:1:121 blocked for more than 30 seconds. Not tainted 6.7.6-lemon #18
debian
CVE-2017-2596P4MEDIUMCVSS 6.5fixed in linux 4.9.13-1 (bookworm)2017
CVE-2017-2596 [MEDIUM] CVE-2017-2596: linux - The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel th...
The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel through 4.9.8 improperly emulates the VMXON instruction, which allows KVM L1 guest OS users to cause a denial of service (host OS memory consumption) by leveraging the mishandling of page references.
Scope: local
bookworm: resolved (fixed in 4.9.13-1)
bullseye: resolved (fixed in 4.9.13-1)
f
debian
CVE-2016-5412P4MEDIUMCVSS 6.5fixed in linux 4.7.2-1 (bookworm)2016
CVE-2016-5412 [MEDIUM] CVE-2016-5412: linux - arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on Power...
arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on PowerPC platforms, when CONFIG_KVM_BOOK3S_64_HV is enabled, allows guest OS users to cause a denial of service (host OS infinite loop) by making a H_CEDE hypercall during the existence of a suspended transaction.
Scope: local
bookworm: resolved (fixed in 4.7.2-1)
bullseye: resolved (fixed in 4.
debian
CVE-2018-14610P4MEDIUMCVSS 5.5fixed in linux 4.19.9-1 (bookworm)2018
CVE-2018-14610 [MEDIUM] CVE-2018-14610: linux - An issue was discovered in the Linux kernel through 4.17.10. There is out-of-bou...
An issue was discovered in the Linux kernel through 4.17.10. There is out-of-bounds access in write_extent_buffer() when mounting and operating a crafted btrfs image, because of a lack of verification that each block group has a corresponding chunk at mount time, within btrfs_read_block_groups in fs/btrfs/extent-tree.c.
Scope: local
bookworm: resolved (fixed in 4.19
debian
CVE-2020-25285P4MEDIUMCVSS 6.4fixed in linux 5.8.10-1 (bookworm)2020
CVE-2020-25285 [MEDIUM] CVE-2020-25285: linux - A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux ke...
A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.
Scope: local
bookworm: resolved (fixed in 5.8.10-1)
bullseye: resolved (fixed in 5.8.10-1)
forky: resolved (fixed in 5.
debian
CVE-2018-14613P4MEDIUMCVSS 5.5fixed in linux 4.19.9-1 (bookworm)2018
CVE-2018-14613 [MEDIUM] CVE-2018-14613: linux - An issue was discovered in the Linux kernel through 4.17.10. There is an invalid...
An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in io_ctl_map_page() when mounting and operating a crafted btrfs image, because of a lack of block group item validation in check_leaf_item in fs/btrfs/tree-checker.c.
Scope: local
bookworm: resolved (fixed in 4.19.9-1)
bullseye: resolved (fixed in 4.19.9-1)
forky: r
debian
CVE-2018-13099P4MEDIUMCVSS 5.5fixed in linux 4.18.10-1 (bookworm)2018
CVE-2018-13099 [MEDIUM] CVE-2018-13099: linux - An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A d...
An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (out-of-bounds memory access and BUG) can occur for a modified f2fs filesystem image in which an inline inode contains an invalid reserved blkaddr.
Scope: local
bookworm: resolved (fixed in 4.18.10-1)
bullseye: resolved (fixed in 4.18.10-1)
forky: resolved (fixed in 4.18
debian
CVE-2018-13100P4MEDIUMCVSS 5.5fixed in linux 4.18.10-1 (bookworm)2018
CVE-2018-13100 [MEDIUM] CVE-2018-13100: linux - An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.17.3, w...
An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.17.3, which does not properly validate secs_per_zone in a corrupted f2fs image, as demonstrated by a divide-by-zero error.
Scope: local
bookworm: resolved (fixed in 4.18.10-1)
bullseye: resolved (fixed in 4.18.10-1)
forky: resolved (fixed in 4.18.10-1)
sid: resolved (fixed in 4.18.10-1)
trixie:
debian
CVE-2013-1848P4MEDIUMCVSS 6.2fixed in linux 3.2.41-1 (bookworm)2013
CVE-2013-1848 [MEDIUM] CVE-2013-1848: linux - fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to fun...
fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to functions in certain circumstances related to printk input, which allows local users to conduct format-string attacks and possibly gain privileges via a crafted application.
Scope: local
bookworm: resolved (fixed in 3.2.41-1)
bullseye: resolved (fixed in 3.2.41-1)
forky: resolved (fixed in 3.
debian
CVE-2024-50251P4MEDIUMCVSS 6.2fixed in linux 6.1.119-1 (bookworm)2024
CVE-2024-50251 [MEDIUM] CVE-2024-50251: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: sanitize offset and length before calling skb_checksum() If access to offset + length is larger than the skbuff length, then skb_checksum() triggers BUG_ON(). skb_checksum() internally subtracts the length parameter while iterating over skbuff, BUG_ON(len) at the end of it ch
debian
CVE-2016-7914P4MEDIUMCVSS 5.5fixed in linux 4.5.3-1 (bookworm)2016
CVE-2016-7914 [MEDIUM] CVE-2016-7914: linux - The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the L...
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and out-of-bounds read) via an application that uses associative-array data structures, as
debian
CVE-2020-27194P4MEDIUMCVSS 5.5fixed in linux 5.9.1-1 (bookworm)2020
CVE-2020-27194 [MEDIUM] CVE-2020-27194: linux - An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or i...
An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values, aka CID-5b9fbeb75b6a.
Scope: local
bookworm: resolved (fixed in 5.9.1-1)
bullseye: resolved (fixed in 5.9.1-1)
forky: resolved (fixed in 5.9.1-1)
sid: resolved (fixed in 5.9.1-1)
trixie: resolved (fixed in 5.
debian
CVE-2023-52765P4MEDIUMCVSS 6.2fixed in linux 6.1.64-1 (bookworm)2023
CVE-2023-52765 [MEDIUM] CVE-2023-52765: linux - In the Linux kernel, the following vulnerability has been resolved: mfd: qcom-s...
In the Linux kernel, the following vulnerability has been resolved: mfd: qcom-spmi-pmic: Fix revid implementation The Qualcomm SPMI PMIC revid implementation is broken in multiple ways. First, it assumes that just because the sibling base device has been registered that means that it is also bound to a driver, which may not be the case (e.g. due to probe deferral or
debian
CVE-2019-19528P4MEDIUMCVSS 6.1fixed in linux 5.3.7-1 (bookworm)2019
CVE-2019-19528 [MEDIUM] CVE-2019-19528: linux - In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caus...
In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driver, aka CID-edc4746f253d.
Scope: local
bookworm: resolved (fixed in 5.3.7-1)
bullseye: resolved (fixed in 5.3.7-1)
forky: resolved (fixed in 5.3.7-1)
sid: resolved (fixed in 5.3.7-1)
trixie: resolved (fixed in 5.3.7-1)
debian
CVE-2024-42224P4MEDIUMCVSS 6.1fixed in linux 6.1.98-1 (bookworm)2024
CVE-2024-42224 [MEDIUM] CVE-2024-42224: linux - In the Linux kernel, the following vulnerability has been resolved: net: dsa: m...
In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: Correct check for empty list Since commit a3c53be55c95 ("net: dsa: mv88e6xxx: Support multiple MDIO busses") mv88e6xxx_default_mdio_bus() has checked that the return value of list_first_entry() is non-NULL. This appears to be intended to guard against the list chip->mdios being
debian
CVE-2026-23172P4HIGHCVSS 8.4fixed in linux 6.1.162-1 (bookworm)2026
CVE-2026-23172 [HIGH] CVE-2026-23172: linux - In the Linux kernel, the following vulnerability has been resolved: net: wwan: ...
In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: fix potential skb->frags overflow in RX path When receiving data in the DPMAIF RX path, the t7xx_dpmaif_set_frag_to_skb() function adds page fragments to an skb without checking if the number of fragments has exceeded MAX_SKB_FRAGS. This could lead to a buffer overflow in skb_shinfo(s
debian
CVE-2019-18885P4MEDIUMCVSS 5.5fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-18885 [MEDIUM] CVE-2019-18885: linux - fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_exte...
fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents NULL pointer dereference via a crafted btrfs image because fs_devices->devices is mishandled within find_device, aka CID-09ba3bc9dd15.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in 5
debian