Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 245 of 632
CVE-2013-1767P4MEDIUMCVSS 6.2fixed in linux 3.2.41-1 (bookworm)2013
CVE-2013-1767 [MEDIUM] CVE-2013-1767: linux - Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in t...
Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remounting a tmpfs filesystem without specifying a required mpol (aka mempolicy) mount option.
Scope: local
bookworm: resolved (fixed in 3.2.41-1)
bullseye: resolved (fixed in
debian
CVE-2016-2549P4MEDIUMCVSS 6.2fixed in linux 4.4.2-1 (bookworm)2016
CVE-2016-2549 [MEDIUM] CVE-2016-2549: linux - sound/core/hrtimer.c in the Linux kernel before 4.4.1 does not prevent recursive...
sound/core/hrtimer.c in the Linux kernel before 4.4.1 does not prevent recursive callback access, which allows local users to cause a denial of service (deadlock) via a crafted ioctl call.
Scope: local
bookworm: resolved (fixed in 4.4.2-1)
bullseye: resolved (fixed in 4.4.2-1)
forky: resolved (fixed in 4.4.2-1)
sid: resolved (fixed in 4.4.2-1)
trixie: resolved (fixed
debian
CVE-2018-14616P4MEDIUMCVSS 5.5fixed in linux 4.19.9-1 (bookworm)2018
CVE-2018-14616 [MEDIUM] CVE-2018-14616: linux - An issue was discovered in the Linux kernel through 4.17.10. There is a NULL poi...
An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c when operating on a file in a corrupted f2fs image.
Scope: local
bookworm: resolved (fixed in 4.19.9-1)
bullseye: resolved (fixed in 4.19.9-1)
forky: resolved (fixed in 4.19.9-1)
sid: resolved (fixed in 4.19.9-1)
trixie:
debian
CVE-2022-21385P4MEDIUMCVSS 6.2fixed in linux 4.19.37-1 (bookworm)2022
CVE-2022-21385 [MEDIUM] CVE-2022-21385: linux - A flaw in net_rds_alloc_sgs() in Oracle Linux kernels allows unprivileged local ...
A flaw in net_rds_alloc_sgs() in Oracle Linux kernels allows unprivileged local users to crash the machine. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Scope: local
bookworm: resolved (fixed in 4.19.37-1)
bullseye: resolved (fixed in 4.19.37-1)
forky: resolved (fixed in 4.19.37-1)
sid: resolved (fixed in
debian
CVE-2019-19815P4MEDIUMCVSS 5.5fixed in linux 5.3.7-1 (bookworm)2019
CVE-2019-19815 [MEDIUM] CVE-2019-19815: linux - In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a...
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recover_fsync_data in fs/f2fs/recovery.c. This is related to F2FS_P_SB in fs/f2fs/f2fs.h.
Scope: local
bookworm: resolved (fixed in 5.3.7-1)
bullseye: resolved (fixed in 5.3.7-1)
forky: resolved (fixed in 5.3.7-1)
sid: resolved (fixed in 5.3.7-1)
trixie:
debian
CVE-2018-1093P4MEDIUMCVSS 5.5fixed in linux 4.15.17-1 (bookworm)2018
CVE-2018-1093 [MEDIUM] CVE-2018-1093: linux - The ext4_valid_block_bitmap function in fs/ext4/balloc.c in the Linux kernel thr...
The ext4_valid_block_bitmap function in fs/ext4/balloc.c in the Linux kernel through 4.15.15 allows attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 image because balloc.c and ialloc.c do not validate bitmap block numbers.
Scope: local
bookworm: resolved (fixed in 4.15.17-1)
bullseye: resolved (fixed in 4.15.17-1)
forky:
debian
CVE-2018-1092P4MEDIUMCVSS 5.5fixed in linux 4.15.17-1 (bookworm)2018
CVE-2018-1092 [MEDIUM] CVE-2018-1092: linux - The ext4_iget function in fs/ext4/inode.c in the Linux kernel through 4.15.15 mi...
The ext4_iget function in fs/ext4/inode.c in the Linux kernel through 4.15.15 mishandles the case of a root directory with a zero i_links_count, which allows attackers to cause a denial of service (ext4_process_freed_data NULL pointer dereference and OOPS) via a crafted ext4 image.
Scope: local
bookworm: resolved (fixed in 4.15.17-1)
bullseye: resolved (fixed in 4.15.
debian
CVE-2022-48635P4MEDIUMCVSS 6.2fixed in linux 6.0.2-1 (bookworm)2022
CVE-2022-48635 [MEDIUM] CVE-2022-48635: linux - In the Linux kernel, the following vulnerability has been resolved: fsdax: Fix ...
In the Linux kernel, the following vulnerability has been resolved: fsdax: Fix infinite loop in dax_iomap_rw() I got an infinite loop and a WARNING report when executing a tail command in virtiofs. WARNING: CPU: 10 PID: 964 at fs/iomap/iter.c:34 iomap_iter+0x3a2/0x3d0 Modules linked in: CPU: 10 PID: 964 Comm: tail Not tainted 5.19.0-rc7 Call Trace: dax_iomap_rw+0xea
debian
CVE-2019-19037P4MEDIUMCVSS 5.5fixed in linux 5.4.8-1 (bookworm)2019
CVE-2019-19037 [MEDIUM] CVE-2019-19037: linux - ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NU...
ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read_dirblock(inode,0,DIRENT_HTREE) can be zero.
Scope: local
bookworm: resolved (fixed in 5.4.8-1)
bullseye: resolved (fixed in 5.4.8-1)
forky: resolved (fixed in 5.4.8-1)
sid: resolved (fixed in 5.4.8-1)
trixie: resolved (fixed in 5.4.8-1)
debian
CVE-2018-13097P4MEDIUMCVSS 5.5fixed in linux 4.19.9-1 (bookworm)2018
CVE-2018-13097 [MEDIUM] CVE-2018-13097: linux - An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.17.3. T...
An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.17.3. There is an out-of-bounds read or a divide-by-zero error for an incorrect user_block_count in a corrupted f2fs image, leading to a denial of service (BUG).
Scope: local
bookworm: resolved (fixed in 4.19.9-1)
bullseye: resolved (fixed in 4.19.9-1)
forky: resolved (fixed in 4.19.9-1)
sid: r
debian
CVE-2018-13095P4MEDIUMCVSS 5.5fixed in linux 4.18.6-1 (bookworm)2018
CVE-2018-13095 [MEDIUM] CVE-2018-13095: linux - An issue was discovered in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel thr...
An issue was discovered in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.17.3. A denial of service (memory corruption and BUG) can occur for a corrupted xfs image upon encountering an inode that is in extent format, but has more extents than fit in the inode fork.
Scope: local
bookworm: resolved (fixed in 4.18.6-1)
bullseye: resolved (fixed in 4.18.6-1
debian
CVE-2015-8964P4MEDIUMCVSS 5.5fixed in linux 4.5.1-1 (bookworm)2015
CVE-2015-8964 [MEDIUM] CVE-2015-8964: linux - The tty_set_termios_ldisc function in drivers/tty/tty_ldisc.c in the Linux kerne...
The tty_set_termios_ldisc function in drivers/tty/tty_ldisc.c in the Linux kernel before 4.5 allows local users to obtain sensitive information from kernel memory by reading a tty data structure.
Scope: local
bookworm: resolved (fixed in 4.5.1-1)
bullseye: resolved (fixed in 4.5.1-1)
forky: resolved (fixed in 4.5.1-1)
sid: resolved (fixed in 4.5.1-1)
trixie: resolved
debian
CVE-2023-52529P4MEDIUMCVSS 6.0fixed in linux 6.1.64-1 (bookworm)2023
CVE-2023-52529 [MEDIUM] CVE-2023-52529: linux - In the Linux kernel, the following vulnerability has been resolved: HID: sony: ...
In the Linux kernel, the following vulnerability has been resolved: HID: sony: Fix a potential memory leak in sony_probe() If an error occurs after a successful usb_alloc_urb() call, usb_free_urb() should be called.
Scope: local
bookworm: resolved (fixed in 6.1.64-1)
bullseye: resolved
forky: resolved (fixed in 6.5.8-1)
sid: resolved (fixed in 6.5.8-1)
trixie: resol
debian
CVE-2021-45868P4MEDIUMCVSS 5.5fixed in linux 5.15.3-1 (bookworm)2021
CVE-2021-45868 [MEDIUM] CVE-2021-45868: linux - In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the b...
In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). This can, for example, lead to a kernel/locking/rwsem.c use-after-free if there is a corrupted quota file.
Scope: local
bookworm: resolved (fixed in 5.15.3-1)
bullseye: resolved (fixed in 5.10.84-1)
forky: resolved (fixed in 5.15.3-1)
sid: resolve
debian
CVE-2022-47929P4MEDIUMCVSS 5.5fixed in linux 6.1.7-1 (bookworm)2022
CVE-2022-47929 [MEDIUM] CVE-2022-47929: linux - In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic ...
In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that is set up with "tc qdisc" and "tc class" commands. This affects qdisc_graft in net/sched/sch_api.c.
Scope: local
bookworm: resolved (fixed in 6.1.7
debian
CVE-2019-19922P4MEDIUMCVSS 5.5fixed in linux 5.3.9-1 (bookworm)2019
CVE-2019-19922 [MEDIUM] CVE-2019-19922: linux - kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is u...
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign worklo
debian
CVE-2022-49138P4MEDIUMCVSS 5.7fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-49138 [MEDIUM] CVE-2022-49138: linux - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ...
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Ignore multiple conn complete events When one of the three connection complete events is received multiple times for the same handle, the device is registered multiple times which leads to memory corruptions. Therefore, consequent events for a single connection are ignored. The
debian
CVE-2024-49569P4MEDIUMCVSS 5.7fixed in linux 6.12.5-1 (forky)2024
CVE-2024-49569 [MEDIUM] CVE-2024-49569: linux - In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: ...
In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: unquiesce admin_q before destroy it Kernel will hang on destroy admin_q while we create ctrl failed, such as following calltrace: PID: 23644 TASK: ff2d52b40f439fc0 CPU: 2 COMMAND: "nvme" #0 [ff61d23de260fb78] __schedule at ffffffff8323bc15 #1 [ff61d23de260fc08] schedule at ffffffff8323c01
debian
CVE-2022-49561P4MEDIUMCVSS 5.5fixed in linux 5.18.2-1 (bookworm)2022
CVE-2022-49561 [MEDIUM] CVE-2022-49561: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: re-fetch conntrack after insertion In case the conntrack is clashing, insertion can free skb->_nfct and set skb->_nfct to the already-confirmed entry. This wasn't found before because the conntrack entry and the extension space used to free'd after an rcu grace period, plus the
debian
CVE-2021-47397P4MEDIUMCVSS 5.5fixed in linux 5.14.12-1 (bookworm)2021
CVE-2021-47397 [MEDIUM] CVE-2021-47397: linux - In the Linux kernel, the following vulnerability has been resolved: sctp: break...
In the Linux kernel, the following vulnerability has been resolved: sctp: break out if skb_header_pointer returns NULL in sctp_rcv_ootb We should always check if skb_header_pointer's return is NULL before using it, otherwise it may cause null-ptr-deref, as syzbot reported: KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:sctp_rcv_ootb
debian