Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 298 of 632
CVE-2022-49768P4MEDIUMCVSS 5.5fixed in linux 6.0.10-1 (bookworm)2022
CVE-2022-49768 [MEDIUM] CVE-2022-49768: linux - In the Linux kernel, the following vulnerability has been resolved: 9p: trans_f...
In the Linux kernel, the following vulnerability has been resolved: 9p: trans_fd/p9_conn_cancel: drop client lock earlier syzbot reported a double-lock here and we no longer need this lock after requests have been moved off to local list: just drop the lock earlier.
Scope: local
bookworm: resolved (fixed in 6.0.10-1)
bullseye: resolved (fixed in 5.10.158-1)
forky: r
debian
CVE-2025-21890P4LOWCVSS 5.5fixed in linux 6.12.19-1 (forky)2025
CVE-2025-21890 [MEDIUM] CVE-2025-21890: linux - In the Linux kernel, the following vulnerability has been resolved: idpf: fix c...
In the Linux kernel, the following vulnerability has been resolved: idpf: fix checksums set in idpf_rx_rsc() idpf_rx_rsc() uses skb_transport_offset(skb) while the transport header is not set yet. This triggers the following warning for CONFIG_DEBUG_NET=y builds. DEBUG_NET_WARN_ON_ONCE(!skb_transport_header_was_set(skb)) [ 69.261620] WARNING: CPU: 7 PID: 0 at ./incl
debian
CVE-2025-38526P4LOWCVSS 5.5fixed in linux 6.16.3-1 (forky)2025
CVE-2025-38526 [MEDIUM] CVE-2025-38526: linux - In the Linux kernel, the following vulnerability has been resolved: ice: add NU...
In the Linux kernel, the following vulnerability has been resolved: ice: add NULL check in eswitch lag check The function ice_lag_is_switchdev_running() is being called from outside of the LAG event handler code. This results in the lag->upper_netdev being NULL sometimes. To avoid a NULL-pointer dereference, there needs to be a check before it is dereferenced.
Scope
debian
CVE-2025-21988P4LOWCVSS 5.5fixed in linux 6.12.20-1 (forky)2025
CVE-2025-21988 [MEDIUM] CVE-2025-21988: linux - In the Linux kernel, the following vulnerability has been resolved: fs/netfs/re...
In the Linux kernel, the following vulnerability has been resolved: fs/netfs/read_collect: add to next->prev_donated If multiple subrequests donate data to the same "next" request (depending on the subrequest completion order), each of them would overwrite the `prev_donated` field, causing data corruption and a BUG() crash ("Can't donate prior to front").
Scope: loc
debian
CVE-2025-21868P4LOWCVSS 5.5fixed in linux 6.12.17-1 (forky)2025
CVE-2025-21868 [MEDIUM] CVE-2025-21868: linux - In the Linux kernel, the following vulnerability has been resolved: net: allow ...
In the Linux kernel, the following vulnerability has been resolved: net: allow small head cache usage with large MAX_SKB_FRAGS values Sabrina reported the following splat: WARNING: CPU: 0 PID: 1 at net/core/dev.c:6935 netif_napi_add_weight_locked+0x8f2/0xba0 Modules linked in: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.14.0-rc1-net-00092-g011b03359038 #996 H
debian
CVE-2025-39758P4LOWCVSS 5.5fixed in linux 6.16.3-1 (forky)2025
CVE-2025-39758 [MEDIUM] CVE-2025-39758: linux - In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: F...
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages Ever since commit c2ff29e99a76 ("siw: Inline do_tcp_sendpages()"), we have been doing this: static int siw_tcp_sendpages(struct socket *s, struct page **page, int offset, size_t size) [...] /* Calculate the number of bytes we need to push, fo
debian
CVE-2021-3759P4MEDIUMCVSS 5.5fixed in linux 5.15.3-1 (bookworm)2021
CVE-2021-3759 [MEDIUM] CVE-2021-3759: linux - A memory overflow vulnerability was found in the Linux kernel’s ipc functionalit...
A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolv
debian
CVE-2021-47090P4MEDIUMCVSS 5.5fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-47090 [MEDIUM] CVE-2021-47090: linux - In the Linux kernel, the following vulnerability has been resolved: mm/hwpoison...
In the Linux kernel, the following vulnerability has been resolved: mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page() Hulk Robot reported a panic in put_page_testzero() when testing madvise() with MADV_SOFT_OFFLINE. The BUG() is triggered when retrying get_any_page(). This is because we keep MF_COUNT_INCREASED flag in second try but the refcnt is
debian
CVE-2013-6376P4MEDIUMCVSS 5.2fixed in linux 3.12.5-1 (bookworm)2013
CVE-2013-6376 [MEDIUM] CVE-2013-6376: linux - The recalculate_apic_map function in arch/x86/kvm/lapic.c in the KVM subsystem i...
The recalculate_apic_map function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (host OS crash) via a crafted ICR write operation in x2apic mode.
Scope: local
bookworm: resolved (fixed in 3.12.5-1)
bullseye: resolved (fixed in 3.12.5-1)
forky: resolved (fixed in 3.12.5-1)
sid: resolve
debian
CVE-2020-25704P4MEDIUMCVSS 5.5fixed in linux 5.9.6-1 (bookworm)2020
CVE-2020-25704 [MEDIUM] CVE-2020-25704: linux - A flaw memory leak in the Linux kernel performance monitoring subsystem was foun...
A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denial of service.
Scope: local
bookworm: resolved (fixed in 5.9.6-1)
bullseye: resolved (fixed in 5.9.6-1)
forky: resolved (fixed in 5.9.6-1)
sid: resolved (fixed in 5.9.6-1
debian
CVE-2021-47203P4MEDIUMCVSS 5.5fixed in linux 5.15.5-1 (bookworm)2021
CVE-2021-47203 [MEDIUM] CVE-2021-47203: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc:...
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix list_add() corruption in lpfc_drain_txq() When parsing the txq list in lpfc_drain_txq(), the driver attempts to pass the requests to the adapter. If such an attempt fails, a local "fail_msg" string is set and a log message output. The job is then added to a completions list for cance
debian
CVE-2026-22990P4MEDIUMCVSS 5.5fixed in linux 6.1.162-1 (bookworm)2026
CVE-2026-22990 [MEDIUM] CVE-2026-22990: linux - In the Linux kernel, the following vulnerability has been resolved: libceph: re...
In the Linux kernel, the following vulnerability has been resolved: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() If the osdmap is (maliciously) corrupted such that the incremental osdmap epoch is different from what is expected, there is no need to BUG. Instead, just declare the incremental osdmap to be invalid.
Scope: local
bookworm: resolved (
debian
CVE-2025-37820P4MEDIUMCVSS 5.5fixed in linux 6.1.137-1 (bookworm)2025
CVE-2025-37820 [MEDIUM] CVE-2025-37820: linux - In the Linux kernel, the following vulnerability has been resolved: xen-netfron...
In the Linux kernel, the following vulnerability has been resolved: xen-netfront: handle NULL returned by xdp_convert_buff_to_frame() The function xdp_convert_buff_to_frame() may return NULL if it fails to correctly convert the XDP buffer into an XDP frame due to memory constraints, internal errors, or invalid data. Failing to check for NULL may lead to a NULL point
debian
CVE-2021-20265P4MEDIUMCVSS 5.5fixed in linux 4.4.4-1 (bookworm)2021
CVE-2021-20265 [MEDIUM] CVE-2021-20265: linux - A flaw was found in the way memory resources were freed in the unix_stream_recvm...
A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 4.4.4-1)
bullseye: re
debian
CVE-2023-53463P4MEDIUMCVSS 5.5fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-53463 [MEDIUM] CVE-2023-53463: linux - In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Do...
In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Do not reset dql stats on NON_FATAL err All ibmvnic resets, make a call to netdev_tx_reset_queue() when re-opening the device. netdev_tx_reset_queue() resets the num_queued and num_completed byte counters. These stats are used in Byte Queue Limit (BQL) algorithms. The difference between the
debian
CVE-2022-34495P4MEDIUMCVSS 5.5fixed in linux 5.18.5-1 (bookworm)2022
CVE-2022-34495 [MEDIUM] CVE-2022-34495: linux - rpmsg_probe in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18....
rpmsg_probe in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.
Scope: local
bookworm: resolved (fixed in 5.18.5-1)
bullseye: resolved
forky: resolved (fixed in 5.18.5-1)
sid: resolved (fixed in 5.18.5-1)
trixie: resolved (fixed in 5.18.5-1)
debian
CVE-2022-49159P4MEDIUMCVSS 5.5fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-49159 [MEDIUM] CVE-2022-49159: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: qla2x...
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Implement ref count for SRB The timeout handler and the done function are racing. When qla2x00_async_iocb_timeout() starts to run it can be preempted by the normal response path (via the firmware?). qla24xx_async_gpsc_sp_done() releases the SRB unconditionally. When scheduling back to
debian
CVE-2020-10720P4MEDIUMCVSS 5.5fixed in linux 5.2.6-1 (bookworm)2020
CVE-2020-10720 [MEDIUM] CVE-2020-10720: linux - A flaw was found in the Linux kernel's implementation of GRO in versions before ...
A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with local access to crash the system.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in 5.2.6-1)
trixie: resolved (fixed in 5.2.6-1)
debian
CVE-2022-49526P4MEDIUMCVSS 5.5fixed in linux 5.18.5-1 (bookworm)2022
CVE-2022-49526 [MEDIUM] CVE-2022-49526: linux - In the Linux kernel, the following vulnerability has been resolved: md/bitmap: ...
In the Linux kernel, the following vulnerability has been resolved: md/bitmap: don't set sb values if can't pass sanity check If bitmap area contains invalid data, kernel will crash then mdadm triggers "Segmentation fault". This is cluster-md speical bug. In non-clustered env, mdadm will handle broken metadata case. In clustered array, only kernel space handles bitm
debian
CVE-2024-50001P4MEDIUMCVSS 5.5fixed in linux 6.1.115-1 (bookworm)2024
CVE-2024-50001 [MEDIUM] CVE-2024-50001: linux - In the Linux kernel, the following vulnerability has been resolved: net/mlx5: F...
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix error path in multi-packet WQE transmit Remove the erroneous unmap in case no DMA mapping was established The multi-packet WQE transmit code attempts to obtain a DMA mapping for the skb. This could fail, e.g. under memory pressure, when the IOMMU driver just can't allocate more memory
debian