Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 296 of 632
CVE-2016-3961P4MEDIUMCVSS 5.5fixed in linux 4.5.2-1 (bookworm)2016
CVE-2016-3961 [MEDIUM] CVE-2016-3961: linux - Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs suppor...
Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area.
Scope: local
bookworm: resolved (fixed in 4.5.2-1)
bullseye: resolved (fixed in 4.5.2-1)
forky: resolved (fixed in 4.5.2-1)
sid: resolved
debian
CVE-2022-0617P4MEDIUMCVSS 5.5fixed in linux 5.16.7-1 (bookworm)2022
CVE-2022-0617 [MEDIUM] CVE-2022-0617: linux - A flaw null pointer dereference in the Linux kernel UDF file system functionalit...
A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.
Scope: local
bookworm: resolved (fixed in 5.16.7-1)
bullseye: resolved (fixed in 5.10.103-1)
debian
CVE-2020-9391P4MEDIUMCVSS 5.5fixed in linux 5.5.13-1 (bookworm)2020
CVE-2020-9391 [MEDIUM] CVE-2020-9391: linux - An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AAr...
An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause heap corruption with the GNU C Library malloc implem
debian
CVE-2025-22042P4MEDIUMCVSS 5.5fixed in linux 6.1.135-1 (bookworm)2025
CVE-2025-22042 [MEDIUM] CVE-2025-22042: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: add ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for create lease context Add missing bounds check for create lease context.
Scope: local
bookworm: resolved (fixed in 6.1.135-1)
bullseye: resolved
forky: resolved (fixed in 6.12.25-1)
sid: resolved (fixed in 6.12.25-1)
trixie: resolved (fixed in 6.12.25-1)
debian
CVE-2020-25673P4MEDIUMCVSS 5.5fixed in linux 5.10.38-1 (bookworm)2020
CVE-2020-25673 [MEDIUM] CVE-2020-25673: linux - A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock...
A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system.
Scope: local
bookworm: resolved (fixed in 5.10.38-1)
bullseye: resolved (fixed in 5.10.38-1)
forky: resolved (fixed in 5.10.38-1)
sid: resolved (fixed in 5.10.38-1)
trixie: resolved (fixed in 5.10.38-1)
debian
CVE-2020-11669P4MEDIUMCVSS 5.5fixed in linux 5.2.6-1 (bookworm)2020
CVE-2020-11669 [MEDIUM] CVE-2020-11669: linux - An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. ...
An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/idle_book3s.S does not have save/restore functionality for PNV_POWERSAVE_AMR, PNV_POWERSAVE_UAMOR, and PNV_POWERSAVE_AMOR, aka CID-53a712bae5dd.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
debian
CVE-2021-38198P4MEDIUMCVSS 5.5fixed in linux 5.10.46-1 (bookworm)2021
CVE-2021-38198 [MEDIUM] CVE-2021-38198: linux - arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly co...
arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page, leading to a missing guest protection page fault.
Scope: local
bookworm: resolved (fixed in 5.10.46-1)
bullseye: resolved (fixed in 5.10.46-1)
forky: resolved (fixed in 5.10.46-1)
sid: resolved (fixed in 5.10.46-1)
trixie: resolved (fixed i
debian
CVE-2021-47559P4MEDIUMCVSS 5.5fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-47559 [MEDIUM] CVE-2021-47559: linux - In the Linux kernel, the following vulnerability has been resolved: net/smc: Fi...
In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix NULL pointer dereferencing in smc_vlan_by_tcpsk() Coverity reports a possible NULL dereferencing problem: in smc_vlan_by_tcpsk(): 6. returned_null: netdev_lower_get_next returns NULL (checked 29 out of 30 times). 7. var_assigned: Assigning: ndev = NULL return value from netdev_lower_get
debian
CVE-2025-21707P4MEDIUMCVSS 5.5fixed in linux 6.1.129-1 (bookworm)2025
CVE-2025-21707 [MEDIUM] CVE-2025-21707: linux - In the Linux kernel, the following vulnerability has been resolved: mptcp: cons...
In the Linux kernel, the following vulnerability has been resolved: mptcp: consolidate suboption status MPTCP maintains the received sub-options status is the bitmask carrying the received suboptions and in several bitfields carrying per suboption additional info. Zeroing the bitmask before parsing is not enough to ensure a consistent status, and the MPTCP code has
debian
CVE-2022-49452P4MEDIUMCVSS 5.5fixed in linux 5.18.5-1 (bookworm)2022
CVE-2022-49452 [MEDIUM] CVE-2022-49452: linux - In the Linux kernel, the following vulnerability has been resolved: dpaa2-eth: ...
In the Linux kernel, the following vulnerability has been resolved: dpaa2-eth: retrieve the virtual address before dma_unmap The TSO header was DMA unmapped before the virtual address was retrieved and then used to free the buffer. This meant that we were actually removing the DMA map and then trying to search for it to help in retrieving the virtual address. This l
debian
CVE-2025-22074P4LOWCVSS 5.5fixed in linux 6.12.25-1 (forky)2025
CVE-2025-22074 [MEDIUM] CVE-2025-22074: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix r_count dec/increment mismatch r_count is only increased when there is an oplock break wait, so r_count inc/decrement are not paired. This can cause r_count to become negative, which can lead to a problem where the ksmbd thread does not terminate.
Scope: local
bookworm: resolved
bullseye:
debian
CVE-2017-1000252P4MEDIUMCVSS 5.5fixed in linux 4.12.13-1 (bookworm)2017
CVE-2017-1000252 [MEDIUM] CVE-2017-1000252: linux - The KVM subsystem in the Linux kernel through 4.13.3 allows guest OS users to ca...
The KVM subsystem in the Linux kernel through 4.13.3 allows guest OS users to cause a denial of service (assertion failure, and hypervisor hang or crash) via an out-of bounds guest_irq value, related to arch/x86/kvm/vmx.c and virt/kvm/eventfd.c.
Scope: local
bookworm: resolved (fixed in 4.12.13-1)
bullseye: resolved (fixed in 4.12.13-1)
forky: resolved (fixed in
debian
CVE-2023-53335P4MEDIUMCVSS 5.5fixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-53335 [MEDIUM] CVE-2023-53335: linux - In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4:...
In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Fix potential null-ptr-deref in pass_establish() If get_ep_from_tid() fails to lookup non-NULL value for ep, ep is dereferenced later regardless of whether it is empty. This patch adds a simple sanity check to fix the issue. Found by Linux Verification Center (linuxtesting.org) with SVAC
debian
CVE-2017-12192P4MEDIUMCVSS 5.5fixed in linux 4.13.4-2 (bookworm)2017
CVE-2017-12192 [MEDIUM] CVE-2017-12192: linux - The keyctl_read_key function in security/keys/keyctl.c in the Key Management sub...
The keyctl_read_key function in security/keys/keyctl.c in the Key Management subcomponent in the Linux kernel before 4.13.5 does not properly consider that a key may be possessed but negatively instantiated, which allows local users to cause a denial of service (OOPS and system crash) via a crafted KEYCTL_READ operation.
Scope: local
bookworm: resolved (fixed in 4.1
debian
CVE-2025-22043P4MEDIUMCVSS 5.5fixed in linux 6.12.25-1 (forky)2025
CVE-2025-22043 [MEDIUM] CVE-2025-22043: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: add ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for durable handle context Add missing bounds check for durable handle context.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 6.12.25-1)
sid: resolved (fixed in 6.12.25-1)
trixie: resolved (fixed in 6.12.25-1)
debian
CVE-2019-20811P4MEDIUMCVSS 5.5fixed in linux 4.19.37-1 (bookworm)2019
CVE-2019-20811 [MEDIUM] CVE-2019-20811: linux - An issue was discovered in the Linux kernel before 5.0.6. In rx_queue_add_kobjec...
An issue was discovered in the Linux kernel before 5.0.6. In rx_queue_add_kobject() and netdev_queue_add_kobject() in net/core/net-sysfs.c, a reference count is mishandled, aka CID-a3e23f719f5c.
Scope: local
bookworm: resolved (fixed in 4.19.37-1)
bullseye: resolved (fixed in 4.19.37-1)
forky: resolved (fixed in 4.19.37-1)
sid: resolved (fixed in 4.19.37-1)
trixie:
debian
CVE-2025-21646P4MEDIUMCVSS 5.5fixed in linux 6.1.128-1 (bookworm)2025
CVE-2025-21646 [MEDIUM] CVE-2025-21646: linux - In the Linux kernel, the following vulnerability has been resolved: afs: Fix th...
In the Linux kernel, the following vulnerability has been resolved: afs: Fix the maximum cell name length The kafs filesystem limits the maximum length of a cell to 256 bytes, but a problem occurs if someone actually does that: kafs tries to create a directory under /proc/net/afs/ with the name of the cell, but that fails with a warning: WARNING: CPU: 0 PID: 9 at fs
debian
CVE-2025-21961P4MEDIUMCVSS 5.5fixed in linux 6.12.20-1 (forky)2025
CVE-2025-21961 [MEDIUM] CVE-2025-21961: linux - In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: ...
In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: fix truesize for mb-xdp-pass case When mb-xdp is set and return is XDP_PASS, packet is converted from xdp_buff to sk_buff with xdp_update_skb_shared_info() in bnxt_xdp_build_skb(). bnxt_xdp_build_skb() passes incorrect truesize argument to xdp_update_skb_shared_info(). The truesize is cal
debian
CVE-2016-9588P4MEDIUMCVSS 5.5fixed in linux 4.8.15-2 (bookworm)2016
CVE-2016-9588 [MEDIUM] CVE-2016-9588: linux - arch/x86/kvm/vmx.c in the Linux kernel through 4.9 mismanages the #BP and #OF ex...
arch/x86/kvm/vmx.c in the Linux kernel through 4.9 mismanages the #BP and #OF exceptions, which allows guest OS users to cause a denial of service (guest OS crash) by declining to handle an exception thrown by an L2 guest.
Scope: local
bookworm: resolved (fixed in 4.8.15-2)
bullseye: resolved (fixed in 4.8.15-2)
forky: resolved (fixed in 4.8.15-2)
sid: resolved (fixed
debian
CVE-2024-26926P4MEDIUMCVSS 5.5fixed in linux 6.1.90-1 (bookworm)2024
CVE-2024-26926 [MEDIUM] CVE-2024-26926: linux - In the Linux kernel, the following vulnerability has been resolved: binder: che...
In the Linux kernel, the following vulnerability has been resolved: binder: check offset alignment in binder_get_object() Commit 6d98eb95b450 ("binder: avoid potential data leakage when copying txn") introduced changes to how binder objects are copied. In doing so, it unintentionally removed an offset alignment check done through calls to binder_alloc_copy_from_buff
debian