Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 226 of 632
CVE-2021-47228P4MEDIUMCVSS 6.2fixed in linux 5.10.46-1 (bookworm)2021
CVE-2021-47228 [MEDIUM] CVE-2021-47228: linux - In the Linux kernel, the following vulnerability has been resolved: x86/ioremap...
In the Linux kernel, the following vulnerability has been resolved: x86/ioremap: Map EFI-reserved memory as encrypted for SEV Some drivers require memory that is marked as EFI boot services data. In order for this memory to not be re-used by the kernel after ExitBootServices(), efi_mem_reserve() is used to preserve it by inserting a new EFI memory descriptor and mar
debian
CVE-2013-6367P4MEDIUMCVSS 5.7fixed in linux 3.12.5-1 (bookworm)2013
CVE-2013-6367 [MEDIUM] CVE-2013-6367: linux - The apic_get_tmcct function in arch/x86/kvm/lapic.c in the KVM subsystem in the ...
The apic_get_tmcct function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via crafted modifications of the TMICT value.
Scope: local
bookworm: resolved (fixed in 3.12.5-1)
bullseye: resolved (fixed in 3.12.5-1)
forky: resolved (fixed in 3.12.5-
debian
CVE-2018-14614P4MEDIUMCVSS 5.5fixed in linux 4.19.9-1 (bookworm)2018
CVE-2018-14614 [MEDIUM] CVE-2018-14614: linux - An issue was discovered in the Linux kernel through 4.17.10. There is an out-of-...
An issue was discovered in the Linux kernel through 4.17.10. There is an out-of-bounds access in __remove_dirty_segment() in fs/f2fs/segment.c when mounting an f2fs image.
Scope: local
bookworm: resolved (fixed in 4.19.9-1)
bullseye: resolved (fixed in 4.19.9-1)
forky: resolved (fixed in 4.19.9-1)
sid: resolved (fixed in 4.19.9-1)
trixie: resolved (fixed in 4.19.9-1
debian
CVE-2019-19036P4MEDIUMCVSS 5.5fixed in linux 5.3.7-1 (bookworm)2019
CVE-2019-19036 [MEDIUM] CVE-2019-19036: linux - btrfs_root_node in fs/btrfs/ctree.c in the Linux kernel through 5.3.12 allows a ...
btrfs_root_node in fs/btrfs/ctree.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because rcu_dereference(root->node) can be zero.
Scope: local
bookworm: resolved (fixed in 5.3.7-1)
bullseye: resolved (fixed in 5.3.7-1)
forky: resolved (fixed in 5.3.7-1)
sid: resolved (fixed in 5.3.7-1)
trixie: resolved (fixed in 5.3.7-1)
debian
CVE-2018-13093P4MEDIUMCVSS 5.5fixed in linux 4.17.14-1 (bookworm)2018
CVE-2018-13093 [MEDIUM] CVE-2018-13093: linux - An issue was discovered in fs/xfs/xfs_icache.c in the Linux kernel through 4.17....
An issue was discovered in fs/xfs/xfs_icache.c in the Linux kernel through 4.17.3. There is a NULL pointer dereference and panic in lookup_slow() on a NULL inode->i_ops pointer when doing pathwalks on a corrupted xfs image. This occurs because of a lack of proper validation that cached inodes are free during allocation.
Scope: local
bookworm: resolved (fixed in 4.17
debian
CVE-2015-8956P4MEDIUMCVSS 6.1fixed in linux 4.2.1-1 (bookworm)2015
CVE-2015-8956 [MEDIUM] CVE-2015-8956: linux - The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel...
The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 4.2 allows local users to obtain sensitive information or cause a denial of service (NULL pointer dereference) via vectors involving a bind system call on a Bluetooth RFCOMM socket.
Scope: local
bookworm: resolved (fixed in 4.2.1-1)
bullseye: resolved (fixed in 4.2.1-1)
forky: reso
debian
CVE-2024-26843P4MEDIUMCVSS 6.0fixed in linux 6.1.82-1 (bookworm)2024
CVE-2024-26843 [MEDIUM] CVE-2024-26843: linux - In the Linux kernel, the following vulnerability has been resolved: efi: runtim...
In the Linux kernel, the following vulnerability has been resolved: efi: runtime: Fix potential overflow of soft-reserved region size md_size will have been narrowed if we have >= 4GB worth of pages in a soft-reserved region.
Scope: local
bookworm: resolved (fixed in 6.1.82-1)
bullseye: resolved (fixed in 5.10.216-1)
forky: resolved (fixed in 6.7.7-1)
sid: resolved
debian
CVE-2015-8950P4MEDIUMCVSS 5.5fixed in linux 4.0.4-1 (bookworm)2015
CVE-2015-8950 [MEDIUM] CVE-2015-8950: linux - arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION...
arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory by triggering a dma_mmap call.
Scope: local
bookworm: resolved (fixed in 4.0.4-1)
bullseye: resolved (fixed in 4.0.4-1)
forky:
debian
CVE-2018-1000199P4MEDIUMCVSS 5.5fixed in linux 4.15.17-1 (bookworm)2018
CVE-2018-1000199 [MEDIUM] CVE-2018-1000199: linux - The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modi...
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptrace. This vulnerability appears to have been fixed in git commit f67b15037a7a50c57f72e69a6d59941ad90a0f0f.
Scope: l
debian
CVE-2024-53240P4MEDIUMCVSS 5.7fixed in linux 6.1.123-1 (bookworm)2024
CVE-2024-53240 [MEDIUM] CVE-2024-53240: linux - In the Linux kernel, the following vulnerability has been resolved: xen/netfron...
In the Linux kernel, the following vulnerability has been resolved: xen/netfront: fix crash when removing device When removing a netfront device directly after a suspend/resume cycle it might happen that the queues have not been setup again, causing a crash during the attempt to stop the queues another time. Fix that by checking the queues are existing before trying
debian
CVE-2025-38191P4MEDIUMCVSS 5.5fixed in linux 6.1.147-1 (bookworm)2025
CVE-2025-38191 [MEDIUM] CVE-2025-38191: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in destroy_previous_session If client set ->PreviousSessionId on kerberos session setup stage, NULL pointer dereference error will happen. Since sess->user is not set yet, It can pass the user argument as NULL to destroy_previous_session. sess->user will be set in
debian
CVE-2022-2078P4MEDIUMCVSS 5.5fixed in linux 5.18.2-1 (bookworm)2022
CVE-2022-2078 [MEDIUM] CVE-2022-2078: linux - A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() func...
A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to trigger a buffer overflow via nft_set_desc_concat_parse() , causing a denial of service and possibly to run code.
Scope: local
bookworm: resolved (fixed in 5.18.2-1)
bullseye: resolved (fixed in 5.10.120-1)
forky: resolved (fixed in 5.18.2-1)
sid: reso
debian
CVE-2014-0155P4LOWCVSS 5.5fixed in linux 3.14.4-1 (bookworm)2014
CVE-2014-0155 [MEDIUM] CVE-2014-0155: linux - The ioapic_deliver function in virt/kvm/ioapic.c in the Linux kernel through 3.1...
The ioapic_deliver function in virt/kvm/ioapic.c in the Linux kernel through 3.14.1 does not properly validate the kvm_irq_delivery_to_apic return value, which allows guest OS users to cause a denial of service (host OS crash) via a crafted entry in the redirection table of an I/O APIC. NOTE: the affected code was moved to the ioapic_service function before the vulner
debian
CVE-2024-27402P4MEDIUMCVSS 5.8fixed in linux 6.1.82-1 (bookworm)2024
CVE-2024-27402 [MEDIUM] CVE-2024-27402: linux - In the Linux kernel, the following vulnerability has been resolved: phonet/pep:...
In the Linux kernel, the following vulnerability has been resolved: phonet/pep: fix racy skb_queue_empty() use The receive queues are protected by their respective spin-lock, not the socket lock. This could lead to skb_peek() unexpectedly returning NULL or a pointer to an already dequeued socket buffer.
Scope: local
bookworm: resolved (fixed in 6.1.82-1)
bullseye: o
debian
CVE-2019-10207P4MEDIUMCVSS 5.5fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-10207 [MEDIUM] CVE-2019-10207: linux - A flaw was found in the Linux kernel's Bluetooth implementation of UART, all ver...
A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye
debian
CVE-2022-42703P4MEDIUMCVSS 5.5fixed in linux 5.19.11-1 (bookworm)2022
CVE-2022-42703 [MEDIUM] CVE-2022-42703: linux - mm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf...
mm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf anon_vma double reuse.
Scope: local
bookworm: resolved (fixed in 5.19.11-1)
bullseye: resolved (fixed in 5.10.140-1)
forky: resolved (fixed in 5.19.11-1)
sid: resolved (fixed in 5.19.11-1)
trixie: resolved (fixed in 5.19.11-1)
debian
CVE-2024-44946P4MEDIUMCVSS 5.5fixed in linux 6.1.112-1 (bookworm)2024
CVE-2024-44946 [MEDIUM] CVE-2024-44946: linux - In the Linux kernel, the following vulnerability has been resolved: kcm: Serial...
In the Linux kernel, the following vulnerability has been resolved: kcm: Serialise kcm_sendmsg() for the same socket. syzkaller reported UAF in kcm_release(). [0] The scenario is 1. Thread A builds a skb with MSG_MORE and sets kcm->seq_skb. 2. Thread A resumes building skb from kcm->seq_skb but is blocked by sk_stream_wait_memory() 3. Thread B calls sendmsg() concur
debian
CVE-2024-26901P4MEDIUMCVSS 5.5fixed in linux 6.1.85-1 (bookworm)2024
CVE-2024-26901 [MEDIUM] CVE-2024-26901: linux - In the Linux kernel, the following vulnerability has been resolved: do_sys_name...
In the Linux kernel, the following vulnerability has been resolved: do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak syzbot identified a kernel information leak vulnerability in do_sys_name_to_handle() and issued the following report [1]. [1] "BUG: KMSAN: kernel-infoleak in instrument_copy_to_user include/linux/instrumented.h:114 [inline] BUG: KMSAN: ke
debian
CVE-2022-49330P4MEDIUMCVSS 5.5fixed in linux 5.18.5-1 (bookworm)2022
CVE-2022-49330 [MEDIUM] CVE-2022-49330: linux - In the Linux kernel, the following vulnerability has been resolved: tcp: fix tc...
In the Linux kernel, the following vulnerability has been resolved: tcp: fix tcp_mtup_probe_success vs wrong snd_cwnd syzbot got a new report [1] finally pointing to a very old bug, added in initial support for MTU probing. tcp_mtu_probe() has checks about starting an MTU probe if tcp_snd_cwnd(tp) >= 11. But nothing prevents tcp_snd_cwnd(tp) to be reduced later and
debian
CVE-2022-41218P4MEDIUMCVSS 5.5fixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-41218 [MEDIUM] CVE-2022-41218: linux - In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is...
In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved (fixed in 5.10.162-1)
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
debian