cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 297 of 632
CVE-2018-20449P4MEDIUMCVSS 5.5fixed in linux 4.15.4-1 (bookworm)2018
CVE-2018-20449 [MEDIUM] CVE-2018-20449: linux - The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kerne... The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading "callback=" lines in a debugfs file. Scope: local bookworm: resolved (fixed in 4.15.4-1) bullseye: resolved (fixed in 4.15.4-1) forky: resolved (fixed in 4.15.4-1) sid: resolved (fixed in 4.15.4-1) trixie: re
debian
CVE-2022-1263P4MEDIUMCVSS 5.5fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-1263 [MEDIUM] CVE-2022-1263: linux - A NULL pointer dereference issue was found in KVM when releasing a vCPU with dir... A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of service. Scope: local bookworm: resolved (fixed in 5.17.3-1) bullseye: resolved forky: resolved (fixed in 5.17.3-1
debian
CVE-2020-14385P4MEDIUMCVSS 5.5fixed in linux 5.8.7-1 (bookworm)2020
CVE-2020-14385 [MEDIUM] CVE-2020-14385: linux - A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file syste... A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt. This can lead to the filesystem being shutdown, or otherwise rendered inaccessible until it is remounted, leading to a denial of service. The highest threat from this
debian
CVE-2020-27673P4MEDIUMCVSS 5.5fixed in linux 5.9.6-1 (bookworm)2020
CVE-2020-27673 [MEDIUM] CVE-2020-27673: linux - An issue was discovered in the Linux kernel through 5.9.1, as used with Xen thro... An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e99502f76271. Scope: local bookworm: resolved (fixed in 5.9.6-1) bullseye: resolved (fixed in 5.9.6-1) forky: resolved (fixed in 5.9.6-1) sid: resolved (fixed in 5.9.6-1) tr
debian
CVE-2025-38399P4MEDIUMCVSS 5.5fixed in linux 6.1.147-1 (bookworm)2025
CVE-2025-38399 [MEDIUM] CVE-2025-38399: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: targe... In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix NULL pointer dereference in core_scsi3_decode_spec_i_port() The function core_scsi3_decode_spec_i_port(), in its error code path, unconditionally calls core_scsi3_lunacl_undepend_item() passing the dest_se_deve pointer, which may be NULL. This can lead to a NULL pointer dereference
debian
CVE-2023-31084P4MEDIUMCVSS 5.5fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-31084 [MEDIUM] CVE-2023-31084: linux - An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux ke... An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the condition is dvb_frontend_test_event(fepriv,events). In dvb_frontend_test_event, down(&fepriv->sem) is called. However, wait_event_interruptible wou
debian
CVE-2025-38472P4MEDIUMCVSS 5.5fixed in linux 6.1.147-1 (bookworm)2025
CVE-2025-38472 [MEDIUM] CVE-2025-38472: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ... In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: fix crash due to removal of uninitialised entry A crash in conntrack was reported while trying to unlink the conntrack entry from the hash bucket list: [exception RIP: __nf_ct_delete_from_lists+172] [..] #7 [ff539b5a2b043aa0] nf_ct_delete at ffffffffc124d421 [nf_conntrack] #
debian
CVE-2017-15128P4MEDIUMCVSS 5.5fixed in linux 4.13.13-1 (bookworm)2017
CVE-2017-15128 [MEDIUM] CVE-2017-15128: linux - A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the... A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cause a denial of service (BUG). Scope: local bookworm: resolved (fixed in 4.13.13-1) bullseye: resolved (fixed in 4.13.13-1) forky: resolved (fixed in 4.13.13-1) sid: resolved (fixed in 4.13.13-1) trixie: resolved (fixed in 4.13.1
debian
CVE-2016-8650P4MEDIUMCVSS 5.5fixed in linux 4.8.11-1 (bookworm)2016
CVE-2016-8650 [MEDIUM] CVE-2016-8650: linux - The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 do... The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent. Scope: local bookworm: resolved (fixed in 4.8.11-1) bullseye: resolved (fixed in 4
debian
CVE-2018-12929P4MEDIUMCVSS 5.5fixed in linux 4.19.37-1 (bookworm)2018
CVE-2018-12929 [MEDIUM] CVE-2018-12929: linux - ntfs_read_locked_inode in the ntfs.ko filesystem driver in the Linux kernel 4.15... ntfs_read_locked_inode in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a use-after-free read and possibly cause a denial of service (kernel oops or panic) via a crafted ntfs filesystem. Scope: local bookworm: resolved (fixed in 4.19.37-1) bullseye: resolved (fixed in 4.19.37-1) forky: resolved (fixed in 4.19.37-1) sid: resolve
debian
CVE-2025-21959P4MEDIUMCVSS 5.5fixed in linux 6.1.133-1 (bookworm)2025
CVE-2025-21959 [MEDIUM] CVE-2025-21959: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ... In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() Since commit b36e4523d4d5 ("netfilter: nf_conncount: fix garbage collection confirm race"), `cpu` and `jiffies32` were introduced to the struct nf_conncount_tuple. The commit made nf_conncount_add() initialize `conn
debian
CVE-2024-43856P4MEDIUMCVSS 5.5fixed in linux 6.1.106-1 (bookworm)2024
CVE-2024-43856 [MEDIUM] CVE-2024-43856: linux - In the Linux kernel, the following vulnerability has been resolved: dma: fix ca... In the Linux kernel, the following vulnerability has been resolved: dma: fix call order in dmam_free_coherent dmam_free_coherent() frees a DMA allocation, which makes the freed vaddr available for reuse, then calls devres_destroy() to remove and free the data structure used to track the DMA allocation. Between the two calls, it is possible for a concurrent task to m
debian
CVE-2022-50483P4MEDIUMCVSS 5.5fixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50483 [MEDIUM] CVE-2022-50483: linux - In the Linux kernel, the following vulnerability has been resolved: net: enetc:... In the Linux kernel, the following vulnerability has been resolved: net: enetc: avoid buffer leaks on xdp_do_redirect() failure Before enetc_clean_rx_ring_xdp() calls xdp_do_redirect(), each software BD in the RX ring between index orig_i and i can have one of 2 refcount values on its page. We are the owner of the current buffer that is being processed, so the refco
debian
CVE-2023-53635P4MEDIUMCVSS 5.5fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-53635 [MEDIUM] CVE-2023-53635: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ... In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: fix wrong ct->timeout value (struct nf_conn)->timeout is an interval before the conntrack confirmed. After confirmed, it becomes a timestamp. It is observed that timeout of an unconfirmed conntrack: - Set by calling ctnetlink_change_timeout(). As a result, `nfct_time_stamp` was
debian
CVE-2021-4442P4MEDIUMCVSS 5.5fixed in linux 5.10.24-1 (bookworm)2021
CVE-2021-4442 [MEDIUM] CVE-2021-4442: linux - In the Linux kernel, the following vulnerability has been resolved: tcp: add sa... In the Linux kernel, the following vulnerability has been resolved: tcp: add sanity tests to TCP_QUEUE_SEQ Qingyu Li reported a syzkaller bug where the repro changes RCV SEQ _after_ restoring data in the receive queue. mprotect(0x4aa000, 12288, PROT_READ) = 0 mmap(0x1ffff000, 4096, PROT_NONE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x1ffff000 mmap(0x20000000, 16
debian
CVE-2016-7916P4MEDIUMCVSS 5.5fixed in linux 4.5.4-1 (bookworm)2016
CVE-2016-7916 [MEDIUM] CVE-2016-7916: linux - Race condition in the environ_read function in fs/proc/base.c in the Linux kerne... Race condition in the environ_read function in fs/proc/base.c in the Linux kernel before 4.5.4 allows local users to obtain sensitive information from kernel memory by reading a /proc/*/environ file during a process-setup time interval in which environment-variable copying is incomplete. Scope: local bookworm: resolved (fixed in 4.5.4-1) bullseye: resolved (fixed in 4
debian
CVE-2021-4095P4MEDIUMCVSS 5.5fixed in linux 5.17.3-1 (bookworm)2021
CVE-2021-4095 [MEDIUM] CVE-2021-4095: linux - A NULL pointer dereference was found in the Linux kernel's KVM when dirty ring l... A NULL pointer dereference was found in the Linux kernel's KVM when dirty ring logging is enabled without an active vCPU context. An unprivileged local attacker on the host may use this flaw to cause a kernel oops condition and thus a denial of service by issuing a KVM_XEN_HVM_SET_ATTR ioctl. This flaw affects Linux kernel versions prior to 5.17-rc1. Scope: local book
debian
CVE-2022-49997P4MEDIUMCVSS 5.5fixed in linux 5.19.6-1 (bookworm)2022
CVE-2022-49997 [MEDIUM] CVE-2022-49997: linux - In the Linux kernel, the following vulnerability has been resolved: net: lantiq... In the Linux kernel, the following vulnerability has been resolved: net: lantiq_xrx200: restore buffer if memory allocation failed In a situation where memory allocation fails, an invalid buffer address is stored. When this descriptor is used again, the system panics in the build_skb() function when accessing memory. Scope: local bookworm: resolved (fixed in 5.19.6-
debian
CVE-2025-21805P4LOWCVSS 5.5fixed in linux 6.12.13-1 (forky)2025
CVE-2025-21805 [MEDIUM] CVE-2025-21805: linux - In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: ... In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Add missing deinit() call A warning is triggered when repeatedly connecting and disconnecting the rnbd: list_add corruption. prev->next should be next (ffff88800b13e480), but was ffff88801ecd1338. (prev=ffff88801ecd1340). WARNING: CPU: 1 PID: 36562 at lib/list_debug.c:32 __list_add_valid_
debian
CVE-2018-20509P4MEDIUMCVSS 5.5fixed in linux 4.14.2-1 (bookworm)2018
CVE-2018-20509 [MEDIUM] CVE-2018-20509: linux - The print_binder_ref_olocked function in drivers/android/binder.c in the Linux k... The print_binder_ref_olocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading " ref *desc *node" lines in a debugfs file. Scope: local bookworm: resolved (fixed in 4.14.2-1) bullseye: resolved (fixed in 4.14.2-1) forky: resolved (fixed in 4.14.2-1) sid: resolved (fixed in 4.14.2-1)
debian
Debian Linux vulnerabilities | cvebase