Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 3 of 632
CVE-2024-26987P2MEDIUMCVSS 5.5Exploitedfixed in linux 6.1.90-1 (bookworm)2024
CVE-2024-26987 [MEDIUM] CVE-2024-26987: linux - In the Linux kernel, the following vulnerability has been resolved: mm/memory-f...
In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix deadlock when hugetlb_optimize_vmemmap is enabled When I did hard offline test with hugetlb pages, below deadlock occurs: ====================================================== WARNING: possible circular locking dependency detected 6.8.0-11409-gf6cef5f8c37f #1 Not tainted ----
debian
CVE-2025-37899P2HIGHCVSS 7.8Exploitedfixed in linux 6.1.159-1 (bookworm)2025
CVE-2025-37899 [HIGH] CVE-2025-37899: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in session logoff The sess->user object can currently be in use by another thread, for example if another connection has sent a session setup request to bind to the session being free'd. The handler for that connection could be in the smb2_sess_setup function which makes use
debian
CVE-2015-1805P2HIGHCVSS 7.2Exploitedfixed in linux 3.16.2-2 (bookworm)2015
CVE-2015-1805 [HIGH] CVE-2015-1805: linux - The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux k...
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun."
Sc
debian
CVE-2017-7533P3HIGHCVSS 7.0ExploitedPoCfixed in linux 4.12.6-1 (bookworm)2017
CVE-2017-7533 [HIGH] CVE-2017-7533: linux - Race condition in the fsnotify implementation in the Linux kernel through 4.12.4...
Race condition in the fsnotify implementation in the Linux kernel through 4.12.4 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that leverages simultaneous execution of the inotify_handle_event and vfs_rename functions.
Scope: local
bookworm: resolved (fixed in 4.12.6-1)
bullseye: resolved (fixed in 4.12.
debian
CVE-2017-5753P2MEDIUMCVSS 5.6PoCfixed in linux 4.15.11-1 (bookworm)2017
CVE-2017-5753 [MEDIUM] CVE-2017-5753: linux - Systems with microprocessors utilizing speculative execution and branch predicti...
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Scope: local
bookworm: resolved (fixed in 4.15.11-1)
bullseye: resolved (fixed in 4.15.11-1)
forky: resolved (fixed in 4.15.11-1)
sid: resolved (fixed in 4.15.11-1)
trixie
debian
CVE-2017-5715P2MEDIUMCVSS 5.6PoCfixed in amd64-microcode 3.20180515.1 (bookworm)2017
CVE-2017-5715 [MEDIUM] CVE-2017-5715: amd64-microcode - Systems with microprocessors utilizing speculative execution and indirect branch...
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Scope: local
bookworm: resolved (fixed in 3.20180515.1)
bullseye: resolved (fixed in 3.20180515.1)
forky: resolved (fixed in 3.20180515.1)
sid: resolved
debian
CVE-2024-35960P3CRITICALCVSS 9.1Exploitedfixed in linux 6.1.90-1 (bookworm)2024
CVE-2024-35960 [CRITICAL] CVE-2024-35960: linux - In the Linux kernel, the following vulnerability has been resolved: net/mlx5: P...
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Properly link new fs rules into the tree Previously, add_rule_fg would only add newly created rules from the handle into the tree when they had a refcount of 1. On the other hand, create_flow_handle tries hard to find and reference already existing identical rules instead of creating new
debian
CVE-2019-6974P2HIGHCVSS 8.1PoCfixed in linux 4.19.20-1 (bookworm)2019
CVE-2019-6974 [HIGH] CVE-2019-6974: linux - In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main....
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
Scope: local
bookworm: resolved (fixed in 4.19.20-1)
bullseye: resolved (fixed in 4.19.20-1)
forky: resolved (fixed in 4.19.20-1)
sid: resolved (fixed in 4.19.20-1)
trixie: resolved (fixed in 4.19.20-1)
debian
CVE-2021-3490P2HIGHCVSS 7.8PoCfixed in linux 5.10.38-1 (bookworm)2021
CVE-2021-3490 [HIGH] CVE-2021-3490: linux - The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux ke...
The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This issue was fixed via commit 049c4e13714e ("bpf: Fix alu32 const subreg bound tracking on bitwise operations") (v5.13-rc4) and
debian
CVE-2017-1000251P2HIGHCVSS 8.0PoCfixed in linux 4.12.13-1 (bookworm)2017
CVE-2017-1000251 [HIGH] CVE-2017-1000251: linux - The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux ke...
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
Scope: local
bookworm: resolved (fixed in 4.12.13-1)
bullseye: resolved (fixed in
debian
CVE-2022-0435P2HIGHCVSS 8.8fixed in linux 5.16.10-1 (bookworm)2022
CVE-2022-0435 [HIGH] CVE-2022-0435: linux - A stack overflow flaw was found in the Linux kernel's TIPC protocol functionalit...
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.
Scope: local
bookworm: resolved (
debian
CVE-2017-16995P2HIGHCVSS 7.8PoCfixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-16995 [HIGH] CVE-2017-16995: linux - The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4...
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect sign extension.
Scope: local
bookworm: resolved (fixed in 4.14.7-1)
bullseye: resolved (fixed in 4.14.7-1)
forky: resolved (fixed in 4.14.7-1)
sid: resol
debian
CVE-2018-8897P2HIGHCVSS 7.8PoCfixed in linux 4.15.17-1 (bookworm)2018
CVE-2018-8897 [HIGH] CVE-2018-8897: linux - A statement in the System Programming Guide of the Intel 64 and IA-32 Architectu...
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS, some Xen config
debian
CVE-2017-7308P2HIGHCVSS 7.8PoCfixed in linux 4.9.18-1 (bookworm)2017
CVE-2017-7308 [HIGH] CVE-2017-7308: linux - The packet_set_ring function in net/packet/af_packet.c in the Linux kernel throu...
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_NET_RAW capability is held), via crafted system calls.
Scope: local
bookworm: resolved (fixed
debian
CVE-2017-5972P3HIGHCVSS 7.5PoCfixed in linux 4.4.2-1 (bookworm)2017
CVE-2017-5972 [HIGH] CVE-2017-5972: linux - The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie p...
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets, as demonstrated by an attack against the kernel-3.10.0 package in CentOS Linux 7. NOTE: third parties have been unable
debian
CVE-2014-0038P3LOWCVSS 6.9PoCfixed in linux 3.13.4-1 (bookworm)2014
CVE-2014-0038 [MEDIUM] CVE-2014-0038: linux - The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13...
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer parameter.
Scope: local
bookworm: resolved (fixed in 3.13.4-1)
bullseye: resolved (fixed in 3.13.4-1)
forky: resolved (fixed in 3.13.4-1)
sid: resolved (fixed
debian
CVE-2016-4557P2HIGHCVSS 7.8PoCfixed in linux 4.5.3-1 (bookworm)2016
CVE-2016-4557 [HIGH] CVE-2016-4557: linux - The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux k...
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or cause a denial of service (use-after-free) via crafted BPF instructions that reference an incorrect file descriptor.
Scope: local
bookworm: resolved (fixed in 4.5.3-1)
bullseye:
debian
CVE-2016-8655P3HIGHCVSS 7.8PoCfixed in linux 4.8.15-1 (bookworm)2016
CVE-2016-8655 [HIGH] CVE-2016-8655: linux - Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allo...
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.
Scope: local
bookworm: resolved (fixed in 4.8.15-1)
bullseye: resolved (fixed i
debian
CVE-2020-12351P3HIGHCVSS 8.8PoCfixed in linux 5.9.1-1 (bookworm)2020
CVE-2020-12351 [HIGH] CVE-2020-12351: linux - Improper input validation in BlueZ may allow an unauthenticated user to potentia...
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
Scope: local
bookworm: resolved (fixed in 5.9.1-1)
bullseye: resolved (fixed in 5.9.1-1)
forky: resolved (fixed in 5.9.1-1)
sid: resolved (fixed in 5.9.1-1)
trixie: resolved (fixed in 5.9.1-1)
debian
CVE-2023-44466P2HIGHCVSS 8.8fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-44466 [HIGH] CVE-2023-44466: linux - An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6....
An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32.
Scope: local
bookworm: resolved (fixed in 6.1.52-1)
bullseye: resolve
debian