Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 289 of 632
CVE-2022-50774P4UNKNOWNfixed in linux 6.0.3-1 (bookworm)2022
CVE-2022-50774 CVE-2022-50774: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: qat...
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - fix DMA transfer direction When CONFIG_DMA_API_DEBUG is selected, while running the crypto self test on the QAT crypto algorithms, the function add_dma_entry() reports a warning similar to the one below, saying that overlapping mappings are not supported. This occurs in tests where the input an
debian
CVE-2023-53843P4UNKNOWNfixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-53843 CVE-2023-53843: linux - In the Linux kernel, the following vulnerability has been resolved: net: openvs...
In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject negative ifindex Recent changes in net-next (commit 759ab1edb56c ("net: store netdevs in an xarray")) refactored the handling of pre-assigned ifindexes and let syzbot surface a latent problem in ovs. ovs does not validate ifindex, making it possible to create netdev ports with negati
debian
CVE-2023-53847P4UNKNOWNfixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-53847 CVE-2023-53847: linux - In the Linux kernel, the following vulnerability has been resolved: usb-storage...
In the Linux kernel, the following vulnerability has been resolved: usb-storage: alauda: Fix uninit-value in alauda_check_media() Syzbot got KMSAN to complain about access to an uninitialized value in the alauda subdriver of usb-storage: BUG: KMSAN: uninit-value in alauda_transport+0x462/0x57f0 drivers/usb/storage/alauda.c:1137 CPU: 0 PID: 12279 Comm: usb-storage Not tainted
debian
CVE-2023-54158P4UNKNOWNfixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-54158 CVE-2023-54158: linux - In the Linux kernel, the following vulnerability has been resolved: btrfs: don'...
In the Linux kernel, the following vulnerability has been resolved: btrfs: don't free qgroup space unless specified Boris noticed in his simple quotas testing that he was getting a leak with Sweet Tea's change to subvol create that stopped doing a transaction commit. This was just a side effect of that change. In the delayed inode code we have an optimization that will free
debian
CVE-2022-50828P4UNKNOWNfixed in linux 6.0.3-1 (bookworm)2022
CVE-2022-50828 CVE-2022-50828: linux - In the Linux kernel, the following vulnerability has been resolved: clk: zynqmp...
In the Linux kernel, the following vulnerability has been resolved: clk: zynqmp: Fix stack-out-of-bounds in strncpy` "BUG: KASAN: stack-out-of-bounds in strncpy+0x30/0x68" Linux-ATF interface is using 16 bytes of SMC payload. In case clock name is longer than 15 bytes, string terminated NULL character will not be received by Linux. Add explicit NULL character at last byte to
debian
CVE-2022-50735P4UNKNOWNfixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50735 CVE-2022-50735: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:...
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: do not run mt76u_status_worker if the device is not running Fix the following NULL pointer dereference avoiding to run mt76u_status_worker thread if the device is not running yet. KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 0 PID: 98 Comm: kworker/u2:2 Not tainted
debian
CVE-2022-50730P4UNKNOWNfixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50730 CVE-2022-50730: linux - In the Linux kernel, the following vulnerability has been resolved: ext4: silen...
In the Linux kernel, the following vulnerability has been resolved: ext4: silence the warning when evicting inode with dioread_nolock When evicting an inode with default dioread_nolock, it could be raced by the unwritten extents converting kworker after writeback some new allocated dirty blocks. It convert unwritten extents to written, the extents could be merged to upper le
debian
CVE-2025-40281P4UNKNOWNfixed in linux 6.1.159-1 (bookworm)2025
CVE-2025-40281 CVE-2025-40281: linux - In the Linux kernel, the following vulnerability has been resolved: sctp: preve...
In the Linux kernel, the following vulnerability has been resolved: sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto syzbot reported a possible shift-out-of-bounds [1] Blamed commit added rto_alpha_max and rto_beta_max set to 1000. It is unclear if some sctp users are setting very large rto_alpha and/or rto_beta. In order to prevent user regression, pe
debian
CVE-2025-40264P4UNKNOWNfixed in linux 6.1.159-1 (bookworm)2025
CVE-2025-40264 CVE-2025-40264: linux - In the Linux kernel, the following vulnerability has been resolved: be2net: pas...
In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called with the wrb_params argument being NULL at be_send_pkt_to_bmc() call site. This may lead to dereferencing a NULL pointer when processing a workaround for specific packet, as commit bc0c3405abbb ("be2net: fix a Tx stall bug caused by
debian
CVE-2025-40115P4UNKNOWNfixed in linux 6.1.158-1 (bookworm)2025
CVE-2025-40115 CVE-2025-40115: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3s...
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix crash in transport port remove by using ioc_info() During mpt3sas_transport_port_remove(), messages were logged with dev_printk() against &mpt3sas_port->port->dev. At this point the SAS transport device may already be partially unregistered or freed, leading to a crash when accessing its s
debian
CVE-2022-50720P4UNKNOWNfixed in linux 6.0.3-1 (bookworm)2022
CVE-2022-50720 CVE-2022-50720: linux - In the Linux kernel, the following vulnerability has been resolved: x86/apic: D...
In the Linux kernel, the following vulnerability has been resolved: x86/apic: Don't disable x2APIC if locked The APIC supports two modes, legacy APIC (or xAPIC), and Extended APIC (or x2APIC). X2APIC mode is mostly compatible with legacy APIC, but it disables the memory-mapped APIC interface in favor of one that uses MSRs. The APIC mode is controlled by the EXT bit in the AP
debian
CVE-2025-40230P4LOWfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40230 [LOW] CVE-2025-40230: linux - In the Linux kernel, the following vulnerability has been resolved: mm: prevent...
In the Linux kernel, the following vulnerability has been resolved: mm: prevent poison consumption when splitting THP When performing memory error injection on a THP (Transparent Huge Page) mapped to userspace on an x86 server, the kernel panics with the following trace. The expected behavior is to terminate the affected process instead of panicking the kernel, as the
debian
CVE-2022-50844P4UNKNOWNfixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50844 CVE-2022-50844: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu:...
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix type of second parameter in odn_edit_dpm_table() callback With clang's kernel control flow integrity (kCFI, CONFIG_CFI_CLANG), indirect call targets are validated against the expected function pointer prototype to make sure the call target is valid to help mitigate ROP attacks. If they are no
debian
CVE-2022-50819P4UNKNOWNfixed in linux 6.0.3-1 (bookworm)2022
CVE-2022-50819 CVE-2022-50819: linux - In the Linux kernel, the following vulnerability has been resolved: udmabuf: Se...
In the Linux kernel, the following vulnerability has been resolved: udmabuf: Set ubuf->sg = NULL if the creation of sg table fails When userspace tries to map the dmabuf and if for some reason (e.g. OOM) the creation of the sg table fails, ubuf->sg needs to be set to NULL. Otherwise, when the userspace subsequently closes the dmabuf fd, we'd try to erroneously free the inval
debian
CVE-2022-50817P4UNKNOWNfixed in linux 6.0.6-1 (bookworm)2022
CVE-2022-50817 CVE-2022-50817: linux - In the Linux kernel, the following vulnerability has been resolved: net: hsr: a...
In the Linux kernel, the following vulnerability has been resolved: net: hsr: avoid possible NULL deref in skb_clone() syzbot got a crash [1] in skb_clone(), caused by a bug in hsr_get_untagged_frame(). When/if create_stripped_skb_hsr() returns NULL, we must not attempt to call skb_clone(). While we are at it, replace a WARN_ONCE() by netdev_warn_once(). [1] general protecti
debian
CVE-2022-50812P4UNKNOWNfixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50812 CVE-2022-50812: linux - In the Linux kernel, the following vulnerability has been resolved: security: R...
In the Linux kernel, the following vulnerability has been resolved: security: Restrict CONFIG_ZERO_CALL_USED_REGS to gcc or clang > 15.0.6 A bad bug in clang's implementation of -fzero-call-used-regs can result in NULL pointer dereferences (see the links above the check for more information). Restrict CONFIG_CC_HAS_ZERO_CALL_USED_REGS to either a supported GCC version or a c
debian
CVE-2023-53861P4UNKNOWNfixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-53861 CVE-2023-53861: linux - In the Linux kernel, the following vulnerability has been resolved: ext4: corre...
In the Linux kernel, the following vulnerability has been resolved: ext4: correct grp validation in ext4_mb_good_group Group corruption check will access memory of grp and will trigger kernel crash if grp is NULL. So do NULL check before corruption check.
Scope: local
bookworm: resolved (fixed in 6.1.55-1)
bullseye: resolved (fixed in 5.10.197-1)
forky: resolved (fixed in 6.
debian
CVE-2022-50849P4UNKNOWNfixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50849 CVE-2022-50849: linux - In the Linux kernel, the following vulnerability has been resolved: pstore: Avo...
In the Linux kernel, the following vulnerability has been resolved: pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP An oops can be induced by running 'cat /proc/kcore > /dev/null' on devices using pstore with the ram backend because kmap_atomic() assumes lowmem pages are accessible with __va(). Unable to handle kernel paging request at virtual address ffffff807ff2b000
debian
CVE-2022-50884P4UNKNOWNfixed in linux 6.0.3-1 (bookworm)2022
CVE-2022-50884 CVE-2022-50884: linux - In the Linux kernel, the following vulnerability has been resolved: drm: Preven...
In the Linux kernel, the following vulnerability has been resolved: drm: Prevent drm_copy_field() to attempt copying a NULL pointer There are some struct drm_driver fields that are required by drivers since drm_copy_field() attempts to copy them to user-space via DRM_IOCTL_VERSION. But it can be possible that a driver has a bug and did not set some of the fields, which leads
debian
CVE-2025-68361P4LOWfixed in linux 6.17.13-1 (forky)2025
CVE-2025-68361 [LOW] CVE-2025-68361: linux - In the Linux kernel, the following vulnerability has been resolved: erofs: limi...
In the Linux kernel, the following vulnerability has been resolved: erofs: limit the level of fs stacking for file-backed mounts Otherwise, it could cause potential kernel stack overflow (e.g., EROFS mounting itself).
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.17.13-1)
sid: resolved (fixed in 6.17.13-1)
trixie: resolved (fixed in 6.1
debian