Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 35 of 632
CVE-2015-1465P3HIGHCVSS 7.8fixed in linux 3.16.7-ckt7-1 (bookworm)2015
CVE-2015-1465 [HIGH] CVE-2015-1465: linux - The IPv4 implementation in the Linux kernel before 3.18.8 does not properly cons...
The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period for redirecting lookups in the absence of caching, which allows remote attackers to cause a denial of service (memory consumption or system crash) via a flood of packets.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt7-1)
bulls
debian
CVE-2025-38052P3HIGHCVSS 7.8fixed in linux 6.1.147-1 (bookworm)2025
CVE-2025-38052 [HIGH] CVE-2025-38052: linux - In the Linux kernel, the following vulnerability has been resolved: net/tipc: f...
In the Linux kernel, the following vulnerability has been resolved: net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done Syzbot reported a slab-use-after-free with the following call trace: ================================================================== BUG: KASAN: slab-use-after-free in tipc_aead_encrypt_done+0x4bd/0x510 net/tipc/crypto.c:840 Read of s
debian
CVE-2025-21927P3HIGHCVSS 7.8fixed in linux 6.12.19-1 (forky)2025
CVE-2025-21927 [HIGH] CVE-2025-21927: linux - In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: f...
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu() nvme_tcp_recv_pdu() doesn't check the validity of the header length. When header digests are enabled, a target might send a packet with an invalid header length (e.g. 255), causing nvme_tcp_verify_hdgst() to access memory outside the all
debian
CVE-2017-12188P3HIGHCVSS 7.8fixed in linux 4.13.4-2 (bookworm)2017
CVE-2017-12188 [HIGH] CVE-2017-12188: linux - arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisatio...
arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute arbitrary code on the host OS or cause a denial of service (incorrect index during page walking, and host OS crash), aka an "MMU potential stack buffe
debian
CVE-2025-39841P3HIGHCVSS 7.8fixed in linux 6.1.153-1 (bookworm)2025
CVE-2025-39841 [HIGH] CVE-2025-39841: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc:...
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix buffer free/clear order in deferred receive path Fix a use-after-free window by correcting the buffer release sequence in the deferred receive path. The code freed the RQ buffer first and only then cleared the context pointer under the lock. Concurrent paths (e.g., ABTS and the repost
debian
CVE-2022-4378P3HIGHCVSS 7.8fixed in linux 6.0.12-1 (bookworm)2022
CVE-2022-4378 [HIGH] CVE-2022-4378: linux - A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a ...
A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Scope: local
bookworm: resolved (fixed in 6.0.12-1)
bullseye: resolved (fixed in 5.10.158-1)
forky: resolved (fixed in 6.0.12-1)
sid: resolved
debian
CVE-2023-2236P3HIGHCVSS 7.8fixed in linux 6.0.12-1 (bookworm)2023
CVE-2023-2236 [HIGH] CVE-2023-2236: linux - A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exp...
A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability. We recommend upgrading past commit 9d94c04c0db024922e886c9fd429659f22f48ea4.
Scope: l
debian
CVE-2018-9516P3HIGHCVSS 7.8fixed in linux 4.17.6-1 (bookworm)2018
CVE-2018-9516 [HIGH] CVE-2018-9516: linux - In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of ...
In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-71361580.
Scope: local
bookworm: resolved (fixed in 4
debian
CVE-2021-41864P3HIGHCVSS 7.8fixed in linux 5.14.12-1 (bookworm)2021
CVE-2021-41864 [HIGH] CVE-2021-41864: linux - prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before ...
prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.
Scope: local
bookworm: resolved (fixed in 5.14.12-1)
bullseye: resolved (fixed in 5.10.84-1)
forky: resolved (fixed in 5.14.12-1)
sid: resolved (fixed in 5.14.12-1)
tr
debian
CVE-2020-35519P3HIGHCVSS 7.8fixed in linux 5.9.15-1 (bookworm)2020
CVE-2020-35519 [HIGH] CVE-2020-35519: linux - An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x2...
An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to confident
debian
CVE-2025-38527P3HIGHCVSS 7.8fixed in linux 6.1.147-1 (bookworm)2025
CVE-2025-38527 [HIGH] CVE-2025-38527: linux - In the Linux kernel, the following vulnerability has been resolved: smb: client...
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_break A race condition can occur in cifs_oplock_break() leading to a use-after-free of the cinode structure when unmounting: cifs_oplock_break() _cifsFileInfo_put(cfile) cifsFileInfo_put_final() cifs_sb_deactive() [last ref, start releasing sb] kill_sb()
debian
CVE-2025-21855P3HIGHCVSS 7.8fixed in linux 6.1.133-1 (bookworm)2025
CVE-2025-21855 [HIGH] CVE-2025-21855: linux - In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Do...
In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Don't reference skb after sending to VIOS Previously, after successfully flushing the xmit buffer to VIOS, the tx_bytes stat was incremented by the length of the skb. It is invalid to access the skb memory after sending the buffer to the VIOS because, at any point after sending, the VIOS can
debian
CVE-2025-68817P3HIGHCVSS 7.8fixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-68817 [HIGH] CVE-2025-68817: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency Under high concurrency, A tree-connection object (tcon) is freed on a disconnect path while another path still holds a reference and later executes *_put()/write on it.
Scope: local
bookworm: resolved (fixed in 6.1.162-1)
bullseye:
debian
CVE-2021-20194P3HIGHCVSS 7.8fixed in linux 5.10.19-1 (bookworm)2021
CVE-2021-20194 [HIGH] CVE-2021-20194: linux - There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel...
There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_getsockopt() functi
debian
CVE-2025-38676P3HIGHCVSS 7.8fixed in linux 6.1.153-1 (bookworm)2025
CVE-2025-38676 [HIGH] CVE-2025-38676: linux - In the Linux kernel, the following vulnerability has been resolved: iommu/amd: ...
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Avoid stack buffer overflow from kernel cmdline While the kernel command line is considered trusted in most environments, avoid writing 1 byte past the end of "acpiid" if the "str" argument is maximum length.
Scope: local
bookworm: resolved (fixed in 6.1.153-1)
bullseye: resolved (fixed in
debian
CVE-2023-52624P3HIGHCVSS 7.8fixed in linux 6.7.7-1 (forky)2023
CVE-2023-52624 [HIGH] CVE-2023-52624: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amd/dis...
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before executing GPINT commands [Why] DMCUB can be in idle when we attempt to interface with the HW through the GPINT mailbox resulting in a system hang. [How] Add dc_wake_and_execute_gpint() to wrap the wake, execute, sleep sequence. If the GPINT executes successfully then
debian
CVE-2021-28691P3HIGHCVSS 7.8fixed in linux 5.10.46-1 (bookworm)2021
CVE-2021-28691 [HIGH] CVE-2021-28691: linux - Guest triggered use-after-free in Linux xen-netback A malicious or buggy network...
Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malformed packet. Such kernel thread termination will lead to a use-after-free in Linux netback when the backend is destroyed,
debian
CVE-2021-3760P3LOWCVSS 7.8fixed in linux 5.14.16-1 (bookworm)2021
CVE-2021-3760 [HIGH] CVE-2021-3760: linux - A flaw was found in the Linux kernel. A use-after-free vulnerability in the NFC ...
A flaw was found in the Linux kernel. A use-after-free vulnerability in the NFC stack can lead to a threat to confidentiality, integrity, and system availability.
Scope: local
bookworm: resolved (fixed in 5.14.16-1)
bullseye: resolved (fixed in 5.10.84-1)
forky: resolved (fixed in 5.14.16-1)
sid: resolved (fixed in 5.14.16-1)
trixie: resolved (fixed in 5.14.16-1)
debian
CVE-2021-23134P3HIGHCVSS 7.8fixed in linux 5.10.38-1 (bookworm)2021
CVE-2021-23134 [HIGH] CVE-2021-23134: linux - Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 al...
Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.
Scope: local
bookworm: resolved (fixed in 5.10.38-1)
bullseye: resolved (fixed in 5.10.38-1)
forky: resolved (fixed in 5.
debian
CVE-2022-0516P3HIGHCVSS 7.8fixed in linux 5.16.10-1 (bookworm)2022
CVE-2022-0516 [HIGH] CVE-2022-0516: linux - A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s39...
A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw affects Linux kernel versions prior to 5.17-rc4.
Scope: local
bookworm: resolved (fixed in 5.16.10-1)
bullseye: resolved (fix
debian