cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 373 of 632
CVE-2023-54270P4UNKNOWNfixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-54270 CVE-2023-54270: linux - In the Linux kernel, the following vulnerability has been resolved: media: usb:... In the Linux kernel, the following vulnerability has been resolved: media: usb: siano: Fix use after free bugs caused by do_submit_urb There are UAF bugs caused by do_submit_urb(). One of the KASan reports is shown below: [ 36.403605] BUG: KASAN: use-after-free in worker_thread+0x4a2/0x890 [ 36.406105] Read of size 8 at addr ffff8880059600e8 by task kworker/0:2/49 [ 36.40831
debian
CVE-2023-54283P4UNKNOWNfixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-54283 CVE-2023-54283: linux - In the Linux kernel, the following vulnerability has been resolved: bpf: Addres... In the Linux kernel, the following vulnerability has been resolved: bpf: Address KCSAN report on bpf_lru_list KCSAN reported a data-race when accessing node->ref. Although node->ref does not have to be accurate, take this chance to use a more common READ_ONCE() and WRITE_ONCE() pattern instead of data_race(). There is an existing bpf_lru_node_is_ref() and bpf_lru_node_set_re
debian
CVE-2022-50870P4UNKNOWNfixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50870 CVE-2022-50870: linux - In the Linux kernel, the following vulnerability has been resolved: powerpc/rta... In the Linux kernel, the following vulnerability has been resolved: powerpc/rtas: avoid device tree lookups in rtas_os_term() rtas_os_term() is called during panic. Its behavior depends on a couple of conditions in the /rtas node of the device tree, the traversal of which entails locking and local IRQ state changes. If the kernel panics while devtree_lock is held, rtas_os_te
debian
CVE-2025-68356P4LOWfixed in linux 6.17.13-1 (forky)2025
CVE-2025-68356 [LOW] CVE-2025-68356: linux - In the Linux kernel, the following vulnerability has been resolved: gfs2: Preve... In the Linux kernel, the following vulnerability has been resolved: gfs2: Prevent recursive memory reclaim Function new_inode() returns a new inode with inode->i_mapping->gfp_mask set to GFP_HIGHUSER_MOVABLE. This value includes the __GFP_FS flag, so allocations in that address space can recurse into filesystem memory reclaim. We don't want that to happen because it ca
debian
CVE-2025-40192P4LOWfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40192 [LOW] CVE-2025-40192: linux - In the Linux kernel, the following vulnerability has been resolved: Revert "ipm... In the Linux kernel, the following vulnerability has been resolved: Revert "ipmi: fix msg stack when IPMI is disconnected" This reverts commit c608966f3f9c2dca596967501d00753282b395fc. This patch has a subtle bug that can cause the IPMI driver to go into an infinite loop if the BMC misbehaves in a certain way. Apparently certain BMCs do misbehave this way because sever
debian
CVE-2025-40218P4LOWfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40218 [LOW] CVE-2025-40218: linux - In the Linux kernel, the following vulnerability has been resolved: mm/damon/va... In the Linux kernel, the following vulnerability has been resolved: mm/damon/vaddr: do not repeat pte_offset_map_lock() until success DAMON's virtual address space operation set implementation (vaddr) calls pte_offset_map_lock() inside the page table walk callback function. This is for reading and writing page table accessed bits. If pte_offset_map_lock() fails, it ret
debian
CVE-2023-53799P4UNKNOWNfixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-53799 CVE-2023-53799: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: api... In the Linux kernel, the following vulnerability has been resolved: crypto: api - Use work queue in crypto_destroy_instance The function crypto_drop_spawn expects to be called in process context. However, when an instance is unregistered while it still has active users, the last user may cause the instance to be freed in atomic context. Fix this by delaying the freeing to a
debian
CVE-2025-68296P4UNKNOWNfixed in linux 6.17.11-1 (forky)2025
CVE-2025-68296 CVE-2025-68296: linux - In the Linux kernel, the following vulnerability has been resolved: drm, fbcon,... In the Linux kernel, the following vulnerability has been resolved: drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup Protect vga_switcheroo_client_fb_set() with console lock. Avoids OOB access in fbcon_remap_all(). Without holding the console lock the call races with switching outputs. VGA switcheroo calls fbcon_remap_all() when switching clients. The fbcon fu
debian
CVE-2025-40136P4UNKNOWNfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40136 CVE-2025-40136: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: his... In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - request reserved interrupt for virtual function The device interrupt vector 3 is an error interrupt for physical function and a reserved interrupt for virtual function. However, the driver has not registered the reserved interrupt for virtual function. When allocating interrupts, the n
debian
CVE-2023-54105P4UNKNOWNfixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-54105 CVE-2023-54105: linux - In the Linux kernel, the following vulnerability has been resolved: can: isotp:... In the Linux kernel, the following vulnerability has been resolved: can: isotp: check CAN address family in isotp_bind() Add missing check to block non-AF_CAN binds. Syzbot created some code which matched the right sockaddr struct size but used AF_XDP (0x2C) instead of AF_CAN (0x1D) in the address family field: bind$xdp(r2, &(0x7f0000000540)={0x2c, 0x0, r4, 0x0, r2}, 0x10) ^
debian
CVE-2023-54101P4UNKNOWNfixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-54101 CVE-2023-54101: linux - In the Linux kernel, the following vulnerability has been resolved: driver: soc... In the Linux kernel, the following vulnerability has been resolved: driver: soc: xilinx: use _safe loop iterator to avoid a use after free The hash_for_each_possible() loop dereferences "eve_data" to get the next item on the list. However the loop frees eve_data so it leads to a use after free. Use hash_for_each_possible_safe() instead. Scope: local bookworm: resolved (fixed
debian
CVE-2025-40113P4LOWfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40113 [LOW] CVE-2025-40113: linux - In the Linux kernel, the following vulnerability has been resolved: remoteproc:... In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom: pas: Shutdown lite ADSP DTB on X1E The ADSP firmware on X1E has separate firmware binaries for the main firmware and the DTB. The same applies for the "lite" firmware loaded by the boot firmware. When preparing to load the new ADSP firmware we shutdown the lite_pas_id for the main fir
debian
CVE-2025-40177P4LOWfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40177 [LOW] CVE-2025-40177: linux - In the Linux kernel, the following vulnerability has been resolved: accel/qaic:... In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Fix bootlog initialization ordering As soon as we queue MHI buffers to receive the bootlog from the device, we could be receiving data. Therefore all the resources needed to process that data need to be setup prior to queuing the buffers. We currently initialize some of the resources after
debian
CVE-2025-40189P4LOWfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40189 [LOW] CVE-2025-40189: linux - In the Linux kernel, the following vulnerability has been resolved: net: usb: l... In the Linux kernel, the following vulnerability has been resolved: net: usb: lan78xx: Fix lost EEPROM read timeout error(-ETIMEDOUT) in lan78xx_read_raw_eeprom Syzbot reported read of uninitialized variable BUG with following call stack. lan78xx 8-1:1.0 (unnamed net_device) (uninitialized): EEPROM read operation timeout ================================================
debian
CVE-2025-40209P4LOWfixed in linux 6.17.8-1 (forky)2025
CVE-2025-40209 [LOW] CVE-2025-40209: linux - In the Linux kernel, the following vulnerability has been resolved: btrfs: fix ... In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leak of qgroup_list in btrfs_add_qgroup_relation When btrfs_add_qgroup_relation() is called with invalid qgroup levels (src >= dst), the function returns -EINVAL directly without freeing the preallocated qgroup_list structure passed by the caller. This causes a memory leak because the
debian
CVE-2025-68742P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-68742 CVE-2025-68742: linux - In the Linux kernel, the following vulnerability has been resolved: bpf: Fix in... In the Linux kernel, the following vulnerability has been resolved: bpf: Fix invalid prog->stats access when update_effective_progs fails Syzkaller triggers an invalid memory access issue following fault injection in update_effective_progs. The issue can be described as follows: __cgroup_bpf_detach update_effective_progs compute_effective_progs bpf_prog_array_alloc items[ind
debian
CVE-2025-68740P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-68740 CVE-2025-68740: linux - In the Linux kernel, the following vulnerability has been resolved: ima: Handle... In the Linux kernel, the following vulnerability has been resolved: ima: Handle error code returned by ima_filter_rule_match() In ima_match_rules(), if ima_filter_rule_match() returns -ENOENT due to the rule being NULL, the function incorrectly skips the 'if (!rc)' check and sets 'result = true'. The LSM rule is considered a match, causing extra files to be measured by IMA.
debian
CVE-2023-54032P4UNKNOWNfixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-54032 CVE-2023-54032: linux - In the Linux kernel, the following vulnerability has been resolved: btrfs: fix ... In the Linux kernel, the following vulnerability has been resolved: btrfs: fix race when deleting quota root from the dirty cow roots list When disabling quotas we are deleting the quota root from the list fs_info->dirty_cowonly_roots without taking the lock that protects it, which is struct btrfs_fs_info::trans_lock. This unsynchronized list manipulation may cause chaos if
debian
CVE-2023-54226P4UNKNOWNfixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-54226 CVE-2023-54226: linux - In the Linux kernel, the following vulnerability has been resolved: af_unix: Fi... In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix data races around sk->sk_shutdown. KCSAN found a data race around sk->sk_shutdown where unix_release_sock() and unix_shutdown() update it under unix_state_lock(), OTOH unix_poll() and unix_dgram_poll() read it locklessly. We need to annotate the writes and reads with WRITE_ONCE() and READ_ONCE()
debian
CVE-2023-54160P4UNKNOWNfixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-54160 CVE-2023-54160: linux - In the Linux kernel, the following vulnerability has been resolved: firmware: a... In the Linux kernel, the following vulnerability has been resolved: firmware: arm_sdei: Fix sleep from invalid context BUG Running a preempt-rt (v6.2-rc3-rt1) based kernel on an Ampere Altra triggers: BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:46 in_atomic(): 0, irqs_disabled(): 128, non_block: 0, pid: 24, name: cpuhp/0 preempt_count:
debian
Debian Linux vulnerabilities | cvebase