cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 219 of 632
CVE-2015-7837P4LOWCVSS 5.5fixed in linux 4.5.1-1 (bookworm)2015
CVE-2015-7837 [MEDIUM] CVE-2015-7837: linux - The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterpri... The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot. Scope: local bookworm: resolved (fixed in 4.5.1-1) bullseye: resolved (fixed in 4.5.1-1
debian
CVE-2017-7495P4MEDIUMCVSS 5.5fixed in linux 4.6.2-1 (bookworm)2017
CVE-2017-7495 [MEDIUM] CVE-2017-7495: linux - fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is... fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows local users to obtain sensitive information from other users' files in opportunistic circumstances by waiting for a hardware reset, creating a new file, making write system calls, and reading this file. Scope: local bookwo
debian
CVE-2020-10768P4MEDIUMCVSS 5.5fixed in linux 5.7.6-1 (bookworm)2020
CVE-2020-10768 [MEDIUM] CVE-2020-10768: linux - A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, whe... A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being 'force disabled' when it is not and opens the system to Spectre v2 attacks. The highest threat from this vulnerability is to confidentiality. Scope: local bookwor
debian
CVE-2017-15537P4MEDIUMCVSS 5.5fixed in linux 4.13.10-1 (bookworm)2017
CVE-2017-15537 [MEDIUM] CVE-2017-15537: linux - The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, w... The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, when a processor supports the xsave feature but not the xsaves feature, does not correctly handle attempts to set reserved bits in the xstate header via the ptrace() or rt_sigreturn() system call, allowing local users to read the FPU registers of other processes on the system, related to
debian
CVE-2017-9605P4MEDIUMCVSS 5.5fixed in linux 4.11.6-1 (bookworm)2017
CVE-2017-9605 [MEDIUM] CVE-2017-9605: linux - The vmw_gb_surface_define_ioctl function (accessible via DRM_IOCTL_VMW_GB_SURFAC... The vmw_gb_surface_define_ioctl function (accessible via DRM_IOCTL_VMW_GB_SURFACE_CREATE) in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.11.4 defines a backup_handle variable but does not give it an initial value. If one attempts to create a GB surface, with a previously allocated DMA buffer to be used as a backup buffer, the backup_handle va
debian
CVE-2025-68365P4MEDIUMCVSS 5.5fixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-68365 [MEDIUM] CVE-2025-68365: linux - In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: I... In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize allocated memory before use KMSAN reports: Multiple uninitialized values detected: - KMSAN: uninit-value in ntfs_read_hdr (3) - KMSAN: uninit-value in bcmp (3) Memory is allocated by __getname(), which is a wrapper for kmem_cache_alloc(). This memory is used before being properl
debian
CVE-2023-53360P4MEDIUMCVSS 5.5fixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-53360 [MEDIUM] CVE-2023-53360: linux - In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Re... In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Rework scratch handling for READ_PLUS (again) I found that the read code might send multiple requests using the same nfs_pgio_header, but nfs4_proc_read_setup() is only called once. This is how we ended up occasionally double-freeing the scratch buffer, but also means we set a NULL pointer
debian
CVE-2016-1237P4MEDIUMCVSS 5.5fixed in linux 4.6.2-2 (bookworm)2016
CVE-2016-1237 [MEDIUM] CVE-2016-1237: linux - nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended fil... nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c. Scope: local bookworm: resolved (fixed in 4.6.2-2) bullseye: resolved (fixed in 4.6.2-2) forky: resolved (fixed in 4.6.2-2) sid: resolved (fixed in 4.6.2-2) trixie: resolved (fixed in 4.6.2-2)
debian
CVE-2025-71183P4MEDIUMCVSS 5.5fixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-71183 [MEDIUM] CVE-2025-71183: linux - In the Linux kernel, the following vulnerability has been resolved: btrfs: alwa... In the Linux kernel, the following vulnerability has been resolved: btrfs: always detect conflicting inodes when logging inode refs After rename exchanging (either with the rename exchange operation or regular renames in multiple non-atomic steps) two inodes and at least one of them is a directory, we can end up with a log tree that contains only of the inodes and a
debian
CVE-2022-26966P4MEDIUMCVSS 5.5fixed in linux 5.16.12-1 (bookworm)2022
CVE-2022-26966 [MEDIUM] CVE-2022-26966: linux - An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr97... An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device. Scope: local bookworm: resolved (fixed in 5.16.12-1) bullseye: resolved (fixed in 5.10.103-1) forky: resolved (fixed in 5.16.12-1) sid: resolved (fixed in 5.16.12-1) trixie: re
debian
CVE-2025-40300P4MEDIUMCVSS 5.5fixed in linux 6.1.153-1 (bookworm)2025
CVE-2025-40300 [MEDIUM] CVE-2025-40300: linux - In the Linux kernel, the following vulnerability has been resolved: x86/vmscape... In the Linux kernel, the following vulnerability has been resolved: x86/vmscape: Add conditional IBPB mitigation VMSCAPE is a vulnerability that exploits insufficient branch predictor isolation between a guest and a userspace hypervisor (like QEMU). Existing mitigations already protect kernel/KVM from a malicious guest. Userspace can additionally be protected by flu
debian
CVE-2024-53241P4MEDIUMCVSS 5.5fixed in linux 6.1.123-1 (bookworm)2024
CVE-2024-53241 [MEDIUM] CVE-2024-53241: linux - In the Linux kernel, the following vulnerability has been resolved: x86/xen: do... In the Linux kernel, the following vulnerability has been resolved: x86/xen: don't do PV iret hypercall through hypercall page Instead of jumping to the Xen hypercall page for doing the iret hypercall, directly code the required sequence in xen-asm.S. This is done in preparation of no longer using hypercall page at all, as it has shown to cause problems with specula
debian
CVE-2025-38331P4MEDIUMCVSS 5.5fixed in linux 6.1.147-1 (bookworm)2025
CVE-2025-38331 [MEDIUM] CVE-2025-38331: linux - In the Linux kernel, the following vulnerability has been resolved: net: ethern... In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Use TOE/TSO on all TCP It is desireable to push the hardware accelerator to also process non-segmented TCP frames: we pass the skb->len to the "TOE/TSO" offloader and it will handle them. Without this quirk the driver becomes unstable and lock up and and crash. I do not know
debian
CVE-2023-50431P4MEDIUMCVSS 5.5fixed in linux 6.1.76-1 (bookworm)2023
CVE-2023-50431 [MEDIUM] CVE-2023-50431: linux - sec_attest_info in drivers/accel/habanalabs/common/habanalabs_ioctl.c in the Lin... sec_attest_info in drivers/accel/habanalabs/common/habanalabs_ioctl.c in the Linux kernel through 6.6.5 allows an information leak to user space because info->pad0 is not initialized. Scope: local bookworm: resolved (fixed in 6.1.76-1) bullseye: resolved forky: resolved (fixed in 6.6.15-1) sid: resolved (fixed in 6.6.15-1) trixie: resolved (fixed in 6.6.15-1)
debian
CVE-2024-40968P4MEDIUMCVSS 5.5fixed in linux 6.1.99-1 (bookworm)2024
CVE-2024-40968 [MEDIUM] CVE-2024-40968: linux - In the Linux kernel, the following vulnerability has been resolved: MIPS: Octeo... In the Linux kernel, the following vulnerability has been resolved: MIPS: Octeon: Add PCIe link status check The standard PCIe configuration read-write interface is used to access the configuration space of the peripheral PCIe devices of the mips processor after the PCIe link surprise down, it can generate kernel panic caused by "Data bus error". So it is necessary
debian
CVE-2022-49533P4MEDIUMCVSS 5.5fixed in linux 5.18.5-1 (bookworm)2022
CVE-2022-49533 [MEDIUM] CVE-2022-49533: linux - In the Linux kernel, the following vulnerability has been resolved: ath11k: Cha... In the Linux kernel, the following vulnerability has been resolved: ath11k: Change max no of active probe SSID and BSSID to fw capability The maximum number of SSIDs in a for active probe requests is currently reported as 16 (WLAN_SCAN_PARAMS_MAX_SSID) when registering the driver. The scan_req_params structure only has the capacity to hold 10 SSIDs. This leads to a
debian
CVE-2023-52488P4MEDIUMCVSS 5.5fixed in linux 6.1.76-1 (bookworm)2023
CVE-2023-52488 [MEDIUM] CVE-2023-52488: linux - In the Linux kernel, the following vulnerability has been resolved: serial: sc1... In the Linux kernel, the following vulnerability has been resolved: serial: sc16is7xx: convert from _raw_ to _noinc_ regmap functions for FIFO The SC16IS7XX IC supports a burst mode to access the FIFOs where the initial register address is sent ($00), followed by all the FIFO data without having to resend the register address each time. In this mode, the IC doesn't
debian
CVE-2024-53153P4LOWCVSS 5.5fixed in linux 6.12.3-1 (forky)2024
CVE-2024-53153 [MEDIUM] CVE-2024-53153: linux - In the Linux kernel, the following vulnerability has been resolved: PCI: qcom-e... In the Linux kernel, the following vulnerability has been resolved: PCI: qcom-ep: Move controller cleanups to qcom_pcie_perst_deassert() Currently, the endpoint cleanup function dw_pcie_ep_cleanup() and EPF deinit notify function pci_epc_deinit_notify() are called during the execution of qcom_pcie_perst_assert() i.e., when the host has asserted PERST#. But quickly a
debian
CVE-2024-49949P4MEDIUMCVSS 5.5fixed in linux 6.1.115-1 (bookworm)2024
CVE-2024-49949 [MEDIUM] CVE-2024-49949: linux - In the Linux kernel, the following vulnerability has been resolved: net: avoid ... In the Linux kernel, the following vulnerability has been resolved: net: avoid potential underflow in qdisc_pkt_len_init() with UFO After commit 7c6d2ecbda83 ("net: be more gentle about silly gso requests coming from user") virtio_net_hdr_to_skb() had sanity check to detect malicious attempts from user space to cook a bad GSO packet. Then commit cf9acc90c80ec ("net:
debian
CVE-2024-27017P4MEDIUMCVSS 5.5fixed in linux 6.1.112-1 (bookworm)2024
CVE-2024-27017 [MEDIUM] CVE-2024-27017: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ... In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: walk over current view on netlink dump The generation mask can be updated while netlink dump is in progress. The pipapo set backend walk iterator cannot rely on it to infer what view of the datastructure is to be used. Add notation to specify if user wants to read/update t
debian
Debian Linux vulnerabilities | cvebase