Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 25 of 632
CVE-2015-4004P3LOWCVSS 8.5fixed in linux 4.3-1 (bookworm)2015
CVE-2015-4004 [HIGH] CVE-2015-4004: linux - The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted lengt...
The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 4.3-1)
bullseye: resolved (fixed in 4.3-1)
forky:
debian
CVE-2019-15538P3HIGHCVSS 7.5fixed in linux 5.2.17-1 (bookworm)2019
CVE-2019-15538 [HIGH] CVE-2019-15538: linux - An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux...
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well in remote DoS if
debian
CVE-2016-7910P3HIGHCVSS 7.8fixed in linux 4.7.2-1 (bookworm)2016
CVE-2016-7910 [HIGH] CVE-2016-7910: linux - Use-after-free vulnerability in the disk_seqf_stop function in block/genhd.c in ...
Use-after-free vulnerability in the disk_seqf_stop function in block/genhd.c in the Linux kernel before 4.7.1 allows local users to gain privileges by leveraging the execution of a certain stop operation even if the corresponding start operation had failed.
Scope: local
bookworm: resolved (fixed in 4.7.2-1)
bullseye: resolved (fixed in 4.7.2-1)
forky: resolved (fixed in
debian
CVE-2017-0786P3HIGHCVSS 8.8fixed in linux 4.13.4-2 (bookworm)2017
CVE-2017-0786 [HIGH] CVE-2017-0786: linux - A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: An...
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37351060. References: B-V2017060101.
Scope: local
bookworm: resolved (fixed in 4.13.4-2)
bullseye: resolved (fixed in 4.13.4-2)
forky: resolved (fixed in 4.13.4-2)
sid: resolved (fixed in 4.13.4-2)
trixie: resolved (fixed in 4.13.4-2)
debian
CVE-2021-45485P3HIGHCVSS 7.5fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-45485 [HIGH] CVE-2021-45485: linux - In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_co...
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
fo
debian
CVE-2020-16119P3MEDIUMCVSS 6.3fixed in linux 5.14.6-1 (bookworm)2020
CVE-2020-16119 [MEDIUM] CVE-2020-16119: linux - Use-after-free vulnerability in the Linux kernel exploitable by a local attacker...
Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a listener after being released. Fixed in Ubuntu Linux kernel 5.4.0-51.56, 5.3.0-68.63, 4.15.0-121.123, 4.4.0-193.224, 3.13.0.182.191 and 3.2.0-149.196.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye
debian
CVE-2021-38207P3HIGHCVSS 7.5fixed in linux 5.10.46-1 (bookworm)2021
CVE-2021-38207 [HIGH] CVE-2021-38207: linux - drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 a...
drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial of service (buffer overflow and lockup) by sending heavy network traffic for about ten minutes.
Scope: local
bookworm: resolved (fixed in 5.10.46-1)
bullseye: resolved (fixed in 5.10.46-1)
forky: resolved (fixed in 5.10.46-1)
sid: resolved (fixed in
debian
CVE-2019-18805P3CRITICALCVSS 9.8fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-18805 [CRITICAL] CVE-2019-18805: linux - An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before...
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other impact, aka CID-19fad20d15a6.
Scope: local
bookworm:
debian
CVE-2022-47940P3HIGHCVSS 8.1fixed in linux 5.19.6-1 (bookworm)2022
CVE-2022-47940 [HIGH] CVE-2022-47940: linux - An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5....
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2_write.
Scope: local
bookworm: resolved (fixed in 5.19.6-1)
bullseye: resolved
forky: resolved (fixed in 5.19.6-1)
sid: resolved (fixed in 5.19.6-1)
trixie: resolved (fixed in 5.19.6-1)
debian
CVE-2018-9363P3HIGHCVSS 8.4fixed in linux 4.17.15-1 (bookworm)2018
CVE-2018-9363 [HIGH] CVE-2018-9363: linux - In the hidp_process_report in bluetooth, there is an integer overflow. This coul...
In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-65853588 References: Upstream kernel.
Scope: local
bookworm: resolved (fixed in 4.17.15-1)
bullseye: resol
debian
CVE-2018-16884P3HIGHCVSS 8.0fixed in linux 4.19.16-1 (bookworm)2018
CVE-2018-16884 [HIGH] CVE-2018-16884: linux - A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted i...
A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation c
debian
CVE-2017-7184P3LOWCVSS 7.8fixed in linux 4.9.18-1 (bookworm)2017
CVE-2017-7184 [HIGH] CVE-2017-7184: linux - The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel ...
The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at Can
debian
CVE-2016-20022P3HIGHCVSS 8.4fixed in linux 4.7.4-1 (bookworm)2016
CVE-2016-20022 [HIGH] CVE-2016-20022: linux - In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c ...
In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products that are no longer supported by the supplier.
Scope: local
bookworm: resolved (fixed in 4.7.4-1)
bullseye: resolved (fixed in 4.7.4-1)
forky: resolved (fixed in 4.7.4-1)
sid
debian
CVE-2023-52434P3HIGHCVSS 8.0fixed in linux 6.1.82-1 (bookworm)2023
CVE-2023-52434 [HIGH] CVE-2023-52434: linux - In the Linux kernel, the following vulnerability has been resolved: smb: client...
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs in smb2_parse_contexts() Validate offsets and lengths before dereferencing create contexts in smb2_parse_contexts(). This fixes following oops when accessing invalid create contexts from server: BUG: unable to handle page fault for address: ffff8881178d8cc3 #PF: supervi
debian
CVE-2022-24122P3HIGHCVSS 7.8fixed in linux 5.15.15-2 (bookworm)2022
CVE-2022-24122 [HIGH] CVE-2022-24122: linux - kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user ...
kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
Scope: local
bookworm: resolved (fixed in 5.15.15-2)
bullseye: resolved
forky: resolved (fixed in 5.15.15-2)
sid: resolved (fixed in 5.15.15-2)
trixie: resolved (fix
debian
CVE-2017-18509P3HIGHCVSS 7.8fixed in linux 4.11.6-1 (bookworm)2017
CVE-2017-18509 [HIGH] CVE-2017-18509: linux - An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By ...
An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with
debian
CVE-2022-42720P3HIGHCVSS 7.8fixed in linux 6.0.2-1 (bookworm)2022
CVE-2022-42720 [HIGH] CVE-2022-42720: linux - Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the ...
Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.
Scope: local
bookworm: resolved (fixed in 6.0.2-1)
bullseye: resolved (fixed in 5.10.149-1)
forky: resolved (fixed
debian
CVE-2024-26952P3HIGHCVSS 7.8fixed in linux 6.1.119-1 (bookworm)2024
CVE-2024-26952 [HIGH] CVE-2024-26952: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial out-of-bounds when buffer offset is invalid I found potencial out-of-bounds when buffer offset fields of a few requests is invalid. This patch set the minimum value of buffer offset field to ->Buffer offset to validate buffer length.
Scope: local
bookworm: resolved (fixed in 6.1.1
debian
CVE-2019-7221P3HIGHCVSS 7.8fixed in linux 4.19.20-1 (bookworm)2019
CVE-2019-7221 [HIGH] CVE-2019-7221: linux - The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.
The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.
Scope: local
bookworm: resolved (fixed in 4.19.20-1)
bullseye: resolved (fixed in 4.19.20-1)
forky: resolved (fixed in 4.19.20-1)
sid: resolved (fixed in 4.19.20-1)
trixie: resolved (fixed in 4.19.20-1)
debian
CVE-2022-1199P3HIGHCVSS 7.5fixed in linux 5.16.18-1 (bookworm)2022
CVE-2022-1199 [HIGH] CVE-2022-1199: linux - A flaw was found in the Linux kernel. This flaw allows an attacker to crash the ...
A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability.
Scope: local
bookworm: resolved (fixed in 5.16.18-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: resolved (fixed in 5.16.18-1)
sid: resolved (fixe
debian