Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 248 of 632
CVE-2026-22997P4MEDIUMCVSS 5.5fixed in linux 6.1.162-1 (bookworm)2026
CVE-2026-22997 [MEDIUM] CVE-2026-22997: linux - In the Linux kernel, the following vulnerability has been resolved: net: can: j...
In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session upon receiving the second rts Since j1939_session_deactivate_activate_next() in j1939_tp_rxtimer() is called only when the timer is enabled, we need to call j1939_session_deactivate_activate_next() if we cancelled the timer. Othe
debian
CVE-2025-71120P4MEDIUMCVSS 5.5fixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-71120 [MEDIUM] CVE-2025-71120: linux - In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svc...
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf A zero length gss_token results in pages == 0 and in_token->pages[0] is NULL. The code unconditionally evaluates page_address(in_token->pages[0]) for the initial memcpy, which can dereference NULL even when the cop
debian
CVE-2017-7616P4MEDIUMCVSS 5.5fixed in linux 4.9.25-1 (bookworm)2017
CVE-2017-7616 [MEDIUM] CVE-2017-7616: linux - Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/me...
Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/mempolicy.c in the Linux kernel through 4.10.9 allows local users to obtain sensitive information from uninitialized stack data by triggering failure of a certain bitmap operation.
Scope: local
bookworm: resolved (fixed in 4.9.25-1)
bullseye: resolved (fixed in 4.9.25-1)
forky: resolved (fix
debian
CVE-2017-5550P4MEDIUMCVSS 5.5fixed in linux 4.9.6-1 (bookworm)2017
CVE-2017-5550 [MEDIUM] CVE-2017-5550: linux - Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux ker...
Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to obtain sensitive information from uninitialized heap-memory locations in opportunistic circumstances by reading from a pipe after an incorrect buffer-release decision.
Scope: local
bookworm: resolved (fixed in 4.9.6-1)
bullseye: resolved (fixed in 4.9
debian
CVE-2018-20510P4MEDIUMCVSS 5.5fixed in linux 4.16.5-1 (bookworm)2018
CVE-2018-20510 [MEDIUM] CVE-2018-20510: linux - The print_binder_transaction_ilocked function in drivers/android/binder.c in the...
The print_binder_transaction_ilocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading "*from *code *flags" lines in a debugfs file.
Scope: local
bookworm: resolved (fixed in 4.16.5-1)
bullseye: resolved (fixed in 4.16.5-1)
forky: resolved (fixed in 4.16.5-1)
sid: resolved (fixed in
debian
CVE-2018-5995P4MEDIUMCVSS 5.5fixed in linux 4.15.4-1 (bookworm)2018
CVE-2018-5995 [MEDIUM] CVE-2018-5995: linux - The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4...
The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "pages/cpu" printk call.
Scope: local
bookworm: resolved (fixed in 4.15.4-1)
bullseye: resolved (fixed in 4.15.4-1)
forky: resolved (fixed in 4.15.4-1)
sid: resolved (fixed in 4.15.4-1)
trixie: r
debian
CVE-2025-21673P4MEDIUMCVSS 5.5fixed in linux 6.12.11-1 (forky)2025
CVE-2025-21673 [MEDIUM] CVE-2025-21673: linux - In the Linux kernel, the following vulnerability has been resolved: smb: client...
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::hostname When shutting down the server in cifs_put_tcp_session(), cifsd thread might be reconnecting to multiple DFS targets before it realizes it should exit the loop, so @server->hostname can't be freed as long as cifsd thread isn't done. Otherwise
debian
CVE-2025-21663P4LOWCVSS 5.5fixed in linux 6.12.10-1 (forky)2025
CVE-2025-21663 [MEDIUM] CVE-2025-21663: linux - In the Linux kernel, the following vulnerability has been resolved: net: stmmac...
In the Linux kernel, the following vulnerability has been resolved: net: stmmac: dwmac-tegra: Read iommu stream id from device tree Nvidia's Tegra MGBE controllers require the IOMMU "Stream ID" (SID) to be written to the MGBE_WRAP_AXI_ASID0_CTRL register. The current driver is hard coded to use MGBE0's SID for all controllers. This causes softirq time outs and kerne
debian
CVE-2023-42754P4MEDIUMCVSS 5.5fixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-42754 [MEDIUM] CVE-2023-42754: linux - A NULL pointer dereference flaw was found in the Linux kernel ipv4 stack. The so...
A NULL pointer dereference flaw was found in the Linux kernel ipv4 stack. The socket buffer (skb) was assumed to be associated with a device before calling __ip_options_compile, which is not always the case if the skb is re-routed by ipvs. This issue may allow a local user with CAP_NET_ADMIN privileges to crash the system.
Scope: local
bookworm: resolved (fixed in 6
debian
CVE-2018-5953P4MEDIUMCVSS 5.5fixed in linux 4.15.4-1 (bookworm)2018
CVE-2018-5953 [MEDIUM] CVE-2018-5953: linux - The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.1...
The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.
Scope: local
bookworm: resolved (fixed in 4.15.4-1)
bullseye: resolved (fixed in 4.15.4-1)
forky: resolved (fixed in 4.15.4-1)
sid: resolved (fixed in 4.15.4-1)
trixi
debian
CVE-2026-22991P4MEDIUMCVSS 5.5fixed in linux 6.1.162-1 (bookworm)2026
CVE-2026-22991 [MEDIUM] CVE-2026-22991: linux - In the Linux kernel, the following vulnerability has been resolved: libceph: ma...
In the Linux kernel, the following vulnerability has been resolved: libceph: make free_choose_arg_map() resilient to partial allocation free_choose_arg_map() may dereference a NULL pointer if its caller fails after a partial allocation. For example, in decode_choose_args(), if allocation of arg_map->args fails, execution jumps to the fail label and free_choose_arg_m
debian
CVE-2017-14156P4LOWCVSS 5.5fixed in linux 4.12.13-1 (bookworm)2017
CVE-2017-14156 [MEDIUM] CVE-2017-14156: linux - The atyfb_ioctl function in drivers/video/fbdev/aty/atyfb_base.c in the Linux ke...
The atyfb_ioctl function in drivers/video/fbdev/aty/atyfb_base.c in the Linux kernel through 4.12.10 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading locations associated with padding bytes.
Scope: local
bookworm: resolved (fixed in 4.12.13-1)
bullseye: resolved (fixed in 4.12.
debian
CVE-2025-38123P4LOWCVSS 5.5fixed in linux 6.12.35-1 (forky)2025
CVE-2025-38123 [MEDIUM] CVE-2025-38123: linux - In the Linux kernel, the following vulnerability has been resolved: net: wwan: ...
In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: Fix napi rx poll issue When driver handles the napi rx polling requests, the netdev might have been released by the dellink logic triggered by the disconnect operation on user plane. However, in the logic of processing skb in polling, an invalid netdev is still being used, which cau
debian
CVE-2025-38124P4MEDIUMCVSS 5.5fixed in linux 6.1.147-1 (bookworm)2025
CVE-2025-38124 [MEDIUM] CVE-2025-38124: linux - In the Linux kernel, the following vulnerability has been resolved: net: fix ud...
In the Linux kernel, the following vulnerability has been resolved: net: fix udp gso skb_segment after pull from frag_list Commit a1e40ac5b5e9 ("net: gso: fix udp gso fraglist segmentation after pull from frag_list") detected invalid geometry in frag_list skbs and redirects them from skb_segment_list to more robust skb_segment. But some packets with modified geometr
debian
CVE-2018-7754P4MEDIUMCVSS 5.5fixed in linux 4.15.4-1 (bookworm)2018
CVE-2018-7754 [MEDIUM] CVE-2018-7754: linux - The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux ker...
The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16.4rc4 allows local users to obtain sensitive address information by reading "ffree: " lines in a debugfs file.
Scope: local
bookworm: resolved (fixed in 4.15.4-1)
bullseye: resolved (fixed in 4.15.4-1)
forky: resolved (fixed in 4.15.4-1)
sid: resolved (fixed in 4.15.4-1)
tr
debian
CVE-2016-2383P4MEDIUMCVSS 5.5fixed in linux 4.4.2-1 (bookworm)2016
CVE-2016-2383 [MEDIUM] CVE-2016-2383: linux - The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before...
The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.
Scope: local
bookworm: resolved (fixed in 4.4.2-1)
bullseye: resolved (fixed in 4.4
debian
CVE-2022-47946P4MEDIUMCVSS 5.5fixed in linux 5.14.6-1 (bookworm)2022
CVE-2022-47946 [MEDIUM] CVE-2022-47946: linux - An issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-...
An issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-free in io_sqpoll_wait_sq in fs/io_uring.c allows an attacker to crash the kernel, resulting in denial of service. finish_wait can be skipped. An attack can occur in some situations by forking a process and then quickly terminating it. NOTE: later kernel versions, such as the 5.15 longte
debian
CVE-2025-21725P4MEDIUMCVSS 5.5fixed in linux 6.1.129-1 (bookworm)2025
CVE-2025-21725 [MEDIUM] CVE-2025-21725: linux - In the Linux kernel, the following vulnerability has been resolved: smb: client...
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix oops due to unset link speed It isn't guaranteed that NETWORK_INTERFACE_INFO::LinkSpeed will always be set by the server, so the client must handle any values and then prevent oopses like below from happening: Oops: divide error: 0000 [#1] PREEMPT SMP KASAN NOPTI CPU: 0 UID: 0 PID:
debian
CVE-2022-50062P4MEDIUMCVSS 5.5fixed in linux 6.0.2-1 (bookworm)2022
CVE-2022-50062 [MEDIUM] CVE-2022-50062: linux - In the Linux kernel, the following vulnerability has been resolved: net: bgmac:...
In the Linux kernel, the following vulnerability has been resolved: net: bgmac: Fix a BUG triggered by wrong bytes_compl On one of our machines we got: kernel BUG at lib/dynamic_queue_limits.c:27! Internal error: Oops - BUG: 0 [#1] PREEMPT SMP ARM CPU: 0 PID: 1166 Comm: irq/41-bgmac Tainted: G W O 4.14.275-rt132 #1 Hardware name: BRCM XGS iProc task: ee3415c0 task.s
debian
CVE-2020-14314P4MEDIUMCVSS 5.5fixed in linux 5.8.7-1 (bookworm)2020
CVE-2020-14314 [MEDIUM] CVE-2020-14314: linux - A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 wi...
A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a directory with broken indexing. This flaw allows a local user to crash the system if the directory exists. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 5.8.7-1)
bulls
debian