Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 34 of 632
CVE-2024-38616P3HIGHCVSS 8.2fixed in linux 6.1.94-1 (bookworm)2024
CVE-2024-38616 [HIGH] CVE-2024-38616: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: carl9...
In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: re-fix fortified-memset warning The carl9170_tx_release() function sometimes triggers a fortified-memset warning in my randconfig builds: In file included from include/linux/string.h:254, from drivers/net/wireless/ath/carl9170/tx.c:40: In function 'fortify_memset_chk', inlined from 'ca
debian
CVE-2024-36886P3HIGHCVSS 7.8fixed in linux 6.1.94-1 (bookworm)2024
CVE-2024-36886 [HIGH] CVE-2024-36886: linux - In the Linux kernel, the following vulnerability has been resolved: tipc: fix U...
In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in error path Sam Page (sam4k) working with Trend Micro Zero Day Initiative reported a UAF in the tipc_buf_append() error path: BUG: KASAN: slab-use-after-free in kfree_skb_list_reason+0x47e/0x4c0 linux/net/core/skbuff.c:1183 Read of size 8 at addr ffff88804d2a7c80 by task poc/8034 CPU:
debian
CVE-2018-1087P3HIGHCVSS 8.0fixed in linux 4.15.17-1 (bookworm)2018
CVE-2018-1087 [HIGH] CVE-2018-1087: linux - kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel...
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the processor did not deliver interrupts and exceptions, rather
debian
CVE-2020-29661P3HIGHCVSS 7.8fixed in linux 5.9.15-1 (bookworm)2020
CVE-2020-29661 [HIGH] CVE-2020-29661: linux - A locking issue was discovered in the tty subsystem of the Linux kernel through ...
A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.
Scope: local
bookworm: resolved (fixed in 5.9.15-1)
bullseye: resolved (fixed in 5.9.15-1)
forky: resolved (fixed in 5.9.15-1)
sid: resolved (fixed in 5.9.15-1)
trixie: resolved (fixed
debian
CVE-2022-29581P3HIGHCVSS 7.8fixed in linux 5.17.6-1 (bookworm)2022
CVE-2022-29581 [HIGH] CVE-2022-29581: linux - Improper Update of Reference Count vulnerability in net/sched of Linux Kernel al...
Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.
Scope: local
bookworm: resolved (fixed in 5.17.6-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: resolved (fixed in 5.17.6-1)
sid: resolve
debian
CVE-2022-2639P3HIGHCVSS 7.8fixed in linux 5.17.6-1 (bookworm)2022
CVE-2022-2639 [HIGH] CVE-2022-2639: linux - An integer coercion error was found in the openvswitch kernel module. Given a su...
An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZE as expected, potentially leading to an out-of-bounds write access. This flaw allows a local user to crash or potentially escalate t
debian
CVE-2020-12657P3HIGHCVSS 7.8fixed in linux 5.6.7-1 (bookworm)2020
CVE-2020-12657 [HIGH] CVE-2020-12657: linux - An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-f...
An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body.
Scope: local
bookworm: resolved (fixed in 5.6.7-1)
bullseye: resolved (fixed in 5.6.7-1)
forky: resolved (fixed in 5.6.7-1)
sid: resolved (fixed in 5.6.7-1)
trixie: resolved (fixed in 5.6.7-1)
debian
CVE-2019-2054P3HIGHCVSS 7.8fixed in linux 4.8.5-1 (bookworm)2019
CVE-2019-2054 [HIGH] CVE-2019-2054: linux - In the seccomp implementation prior to kernel version 4.8, there is a possible s...
In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-119769499
Scope: local
debian
CVE-2018-1128P3HIGHCVSS 7.5fixed in ceph 12.2.8+dfsg1-1 (bookworm)2018
CVE-2018-1128 [HIGH] CVE-2018-1128: ceph - It was found that cephx authentication protocol did not verify ceph clients corr...
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are b
debian
CVE-2021-33631P3MEDIUMCVSS 5.5fixed in linux 6.1.4-1 (bookworm)2021
CVE-2021-33631 [MEDIUM] CVE-2021-33631: linux - Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (files...
Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.4-1)
debian
CVE-2018-20976P3HIGHCVSS 7.8fixed in linux 4.18.6-1 (bookworm)2018
CVE-2018-20976 [HIGH] CVE-2018-20976: linux - An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A...
An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
Scope: local
bookworm: resolved (fixed in 4.18.6-1)
bullseye: resolved (fixed in 4.18.6-1)
forky: resolved (fixed in 4.18.6-1)
sid: resolved (fixed in 4.18.6-1)
trixie: resolved (fixed in 4.18.6-1)
debian
CVE-2020-25670P3HIGHCVSS 7.8fixed in linux 5.10.38-1 (bookworm)2020
CVE-2020-25670 [HIGH] CVE-2020-25670: linux - A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind(...
A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations.
Scope: local
bookworm: resolved (fixed in 5.10.38-1)
bullseye: resolved (fixed in 5.10.38-1)
forky: resolved (fixed in 5.10.38-1)
sid: resolved (fixed in 5.10.38-1)
trixie: resolved (fixed in 5.10.38-1)
debian
CVE-2021-37576P3HIGHCVSS 7.8fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-37576 [HIGH] CVE-2021-37576: linux - arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc...
arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.46-5)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolv
debian
CVE-2021-33033P3HIGHCVSS 7.8fixed in linux 5.10.24-1 (bookworm)2021
CVE-2021-33033 [HIGH] CVE-2021-33033: linux - The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net/i...
The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DOI definitions is mishandled, aka CID-ad5d07f4a9cd. This leads to writing an arbitrary value.
Scope: local
bookworm: resolved (fixed in 5.10.24-1)
bullseye: resolved (fixed in 5.10.24-1)
forky: resolved (fixed in 5.10.24-1
debian
CVE-2015-8966P3HIGHCVSS 7.8fixed in linux 4.4.2-1 (bookworm)2015
CVE-2015-8966 [HIGH] CVE-2015-8966: linux - arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 4.4 allows local us...
arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 4.4 allows local users to gain privileges via a crafted (1) F_OFD_GETLK, (2) F_OFD_SETLK, or (3) F_OFD_SETLKW command in an fcntl64 system call.
Scope: local
bookworm: resolved (fixed in 4.4.2-1)
bullseye: resolved (fixed in 4.4.2-1)
forky: resolved (fixed in 4.4.2-1)
sid: resolved (fixed in 4.4.2-1)
trixie: r
debian
CVE-2019-18675P3HIGHCVSS 7.8fixed in linux 4.16.16-1 (bookworm)2019
CVE-2019-18675 [HIGH] CVE-2019-18675: linux - The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia...
The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allows local users (with /dev/video0 access) to obtain read and write permissions on kernel physical pages, which can possibly result in a privilege escalation.
Scope: local
bookworm:
debian
CVE-2018-8822P3HIGHCVSS 7.8fixed in linux 4.15.17-1 (bookworm)2018
CVE-2018-8822 [HIGH] CVE-2018-8822: linux - Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncp...
Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel through 4.15.11, and in drivers/staging/ncpfs/ncplib_kernel.c in the Linux kernel 4.16-rc through 4.16-rc6, could be exploited by malicious NCPFS servers to crash the kernel or execute code.
Scope: local
bookworm: resolved (fixed in 4.15.17-1)
bullseye: resol
debian
CVE-2016-3157P3HIGHCVSS 7.8fixed in linux 4.5.1-1 (bookworm)2016
CVE-2016-3157 [HIGH] CVE-2016-3157: linux - The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel doe...
The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV Xen guests, which allows local guest OS users to gain privileges, cause a denial of service (guest OS crash), or obtain sensitive information by leveraging I/O port access.
Scope: local
bookworm: resolved (fixed in 4.5.1-1)
bullseye: resolved (
debian
CVE-2020-25671P3HIGHCVSS 7.8fixed in linux 5.10.38-1 (bookworm)2020
CVE-2020-25671 [HIGH] CVE-2020-25671: linux - A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_co...
A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalations.
Scope: local
bookworm: resolved (fixed in 5.10.38-1)
bullseye: resolved (fixed in 5.10.38-1)
forky: resolved (fixed in 5.10.38-1)
sid: resolved (fixed in 5.10.38-1)
trixie: resolved (fixed in 5.10.38-1)
debian
CVE-2025-37778P3HIGHCVSS 7.8fixed in linux 6.1.135-1 (bookworm)2025
CVE-2025-37778 [HIGH] CVE-2025-37778: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix dangling pointer in krb_authenticate krb_authenticate frees sess->user and does not set the pointer to NULL. It calls ksmbd_krb5_authenticate to reinitialise sess->user but that function may return without doing so. If that happens then smb2_sess_setup, which calls krb_authenticate, will be
debian