cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 293 of 632
CVE-2023-1032P4MEDIUMCVSS 4.7fixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-1032 [MEDIUM] CVE-2023-1032: linux - The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in ... The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15c7691e9b13cbe9bf6c65c365350e056067. Scope: local bookworm: resolved (fixed in 6.1.20-1) bullseye: resolved forky: resolved (fixed in 6.1.20-1) sid: re
debian
CVE-2025-39726P4MEDIUMCVSS 4.7fixed in linux 6.16.3-1 (forky)2025
CVE-2025-39726 [MEDIUM] CVE-2025-39726: linux - In the Linux kernel, the following vulnerability has been resolved: s390/ism: f... In the Linux kernel, the following vulnerability has been resolved: s390/ism: fix concurrency management in ism_cmd() The s390x ISM device data sheet clearly states that only one request-response sequence is allowable per ISM function at any point in time. Unfortunately as of today the s390/ism driver in Linux does not honor that requirement. This patch aims to rect
debian
CVE-2024-49998P4MEDIUMCVSS 4.7fixed in linux 6.11.4-1 (forky)2024
CVE-2024-49998 [MEDIUM] CVE-2024-49998: linux - In the Linux kernel, the following vulnerability has been resolved: net: dsa: i... In the Linux kernel, the following vulnerability has been resolved: net: dsa: improve shutdown sequence Alexander Sverdlin presents 2 problems during shutdown with the lan9303 driver. One is specific to lan9303 and the other just happens to reproduce there. The first problem is that lan9303 is unique among DSA drivers in that it calls dev_get_drvdata() at "arbitrary
debian
CVE-2018-7191P4MEDIUMCVSS 6.9fixed in linux 4.14.2-1 (bookworm)2018
CVE-2018-7191 [MEDIUM] CVE-2018-7191: linux - In the tun subsystem in the Linux kernel before 4.13.14, dev_get_valid_name is n... In the tun subsystem in the Linux kernel before 4.13.14, dev_get_valid_name is not called before register_netdevice. This allows local users to cause a denial of service (NULL pointer dereference and panic) via an ioctl(TUNSETIFF) call with a dev name containing a / character. This is similar to CVE-2013-4343. Scope: local bookworm: resolved (fixed in 4.14.2-1) bullse
debian
CVE-2022-0812P4MEDIUMCVSS 4.3fixed in linux 5.7.10-1 (bookworm)2022
CVE-2022-0812 [MEDIUM] CVE-2022-0812: linux - An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/r... An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c in the Linux Kernel. This flaw allows an attacker with normal user privileges to leak kernel information. Scope: local bookworm: resolved (fixed in 5.7.10-1) bullseye: resolved (fixed in 5.7.10-1) forky: resolved (fixed in 5.7.10-1) sid: resolved (fixed in 5.7.10-1) trixie: resol
debian
CVE-2019-3701P4LOWCVSS 4.4fixed in linux 4.19.20-1 (bookworm)2019
CVE-2019-3701 [MEDIUM] CVE-2019-3701: linux - An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel th... An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_ADMIN can create a CAN frame modification rule that makes the data length code a higher value than the available CAN frame
debian
CVE-2013-4254P4MEDIUMCVSS 6.9fixed in linux 3.10.11-1 (bookworm)2013
CVE-2013-4254 [MEDIUM] CVE-2013-4254: linux - The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel ... The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by adding a hardware event to an event group led by a software event. Scope: local bookworm: resolved (fixed in 3.10.11-1) bullseye: resolved (fi
debian
CVE-2022-3524P4MEDIUMCVSS 4.3fixed in linux 6.0.7-1 (bookworm)2022
CVE-2022-3524 [MEDIUM] CVE-2022-3524: linux - A vulnerability was found in Linux Kernel. It has been declared as problematic. ... A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function ipv6_renew_options of the component IPv6 Handler. The manipulation leads to memory leak. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211021 was assigned to this vulnerability. S
debian
CVE-2020-35508P4MEDIUMCVSS 4.5fixed in linux 5.9.9-1 (bookworm)2020
CVE-2020-35508 [MEDIUM] CVE-2020-35508: linux - A flaw possibility of race condition and incorrect initialization of the process... A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process. Scope: local bookworm: resolved (fixed in 5.9.9-1) bullseye: resolved (
debian
CVE-2016-9604P4MEDIUMCVSS 4.4fixed in linux 4.9.25-1 (bookworm)2016
CVE-2016-9604 [MEDIUM] CVE-2016-9604: linux - It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct ... It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '.dns_resolver' in RHEL-7 or '.builtin_trusted_keys' upstream, by joining it as its session keyring. This allows root to bypass module signature verification by adding a new public key of its own devising to the keyring. Scope: local bookworm: resolve
debian
CVE-2023-5158P4MEDIUMCVSS 6.5fixed in linux 6.1.64-1 (bookworm)2023
CVE-2023-5158 [MEDIUM] CVE-2023-5158: linux - A flaw was found in vringh_kiov_advance in drivers/vhost/vringh.c in the host si... A flaw was found in vringh_kiov_advance in drivers/vhost/vringh.c in the host side of a virtio ring in the Linux Kernel. This issue may result in a denial of service from guest to host via zero length descriptor. Scope: local bookworm: resolved (fixed in 6.1.64-1) bullseye: resolved forky: resolved (fixed in 6.5.8-1) sid: resolved (fixed in 6.5.8-1) trixie: resolved (
debian
CVE-2022-36402P4MEDIUMCVSS 6.3fixed in linux 6.1.52-1 (bookworm)2022
CVE-2022-36402 [MEDIUM] CVE-2022-36402: linux - An integer overflow vulnerability was found in vmwgfx driver in drivers/gpu/vmxg... An integer overflow vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS). Scope: local bookworm: resolved (fixed in 6.1.52-1) bullseye: re
debian
CVE-2023-3863P4MEDIUMCVSS 6.4fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-3863 [MEDIUM] CVE-2023-3863: linux - A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in... A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allows a local user with special privileges to impact a kernel information leak issue. Scope: local bookworm: resolved (fixed in 6.1.52-1) bullseye: resolved (fixed in 5.10.191-1) forky: resolved (fixed in 6.4.4-1) sid: resolved (fixed in 6.4.4-1) trixie
debian
CVE-2016-2543P4MEDIUMCVSS 6.2fixed in linux 4.4.2-1 (bookworm)2016
CVE-2016-2543 [MEDIUM] CVE-2016-2543: linux - The snd_seq_ioctl_remove_events function in sound/core/seq/seq_clientmgr.c in th... The snd_seq_ioctl_remove_events function in sound/core/seq/seq_clientmgr.c in the Linux kernel before 4.4.1 does not verify FIFO assignment before proceeding with FIFO clearing, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted ioctl call. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: resolved (fixed
debian
CVE-2013-1826P4LOWCVSS 6.2fixed in linux 3.2.32-1 (bookworm)2013
CVE-2013-1826 [MEDIUM] CVE-2013-1826: linux - The xfrm_state_netlink function in net/xfrm/xfrm_user.c in the Linux kernel befo... The xfrm_state_netlink function in net/xfrm/xfrm_user.c in the Linux kernel before 3.5.7 does not properly handle error conditions in dump_one_state function calls, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability. Scope: local bookworm: resolved (fixed in 3.
debian
CVE-2016-2550P4MEDIUMCVSS 6.2fixed in linux 4.4.4-1 (bookworm)2016
CVE-2016-2550 [MEDIUM] CVE-2016-2550: linux - The Linux kernel before 4.5 allows local users to bypass file-descriptor limits ... The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging incorrect tracking of descriptor ownership and sending each descriptor over a UNIX socket before closing it. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-4312. Scope: local bookworm: resolved (fixe
debian
CVE-2014-5045P4MEDIUMCVSS 6.2fixed in linux 3.14.15-1 (bookworm)2014
CVE-2014-5045 [MEDIUM] CVE-2014-5045: linux - The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 doe... The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to use the umount system call in conjunction with a symlink, which allows local users to cause a denial of service (memory consumption or use-after-free) or possibly have unspecified other impact via the umount program. Scop
debian
CVE-2016-2548P4MEDIUMCVSS 6.2fixed in linux 4.4.2-1 (bookworm)2016
CVE-2016-2548 [MEDIUM] CVE-2016-2548: linux - sound/core/timer.c in the Linux kernel before 4.4.1 retains certain linked lists... sound/core/timer.c in the Linux kernel before 4.4.1 retains certain linked lists after a close or stop action, which allows local users to cause a denial of service (system crash) via a crafted ioctl call, related to the (1) snd_timer_close and (2) _snd_timer_stop functions. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: resolved (fixed in 4.4.2-1) forky
debian
CVE-2015-8767P4MEDIUMCVSS 6.2fixed in linux 4.3.1-1 (bookworm)2015
CVE-2015-8767 [MEDIUM] CVE-2015-8767: linux - net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage... net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call. Scope: local bookworm: resolved (fixed in 4.3.1-1) bullseye: resolved (fixed in 4.3.1-1) forky: resolved (fixed in 4.3.1-1) sid: resolved (fixed i
debian
CVE-2018-1094P4MEDIUMCVSS 5.5fixed in linux 4.15.17-1 (bookworm)2018
CVE-2018-1094 [MEDIUM] CVE-2018-1094: linux - The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15... The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always initialize the crc32c checksum driver, which allows attackers to cause a denial of service (ext4_xattr_inode_hash NULL pointer dereference and system crash) via a crafted ext4 image. Scope: local bookworm: resolved (fixed in 4.15.17-1) bullseye: resolved (fixed in 4.15.
debian
Debian Linux vulnerabilities | cvebase