cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 378 of 632
CVE-2015-1339P4MEDIUMCVSS 6.2fixed in linux 4.4.2-1 (bookworm)2015
CVE-2015-1339 [MEDIUM] CVE-2015-1339: linux - Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux ... Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many times. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: resolved (fixed in 4.4.2-1) forky: resolved (fixed in 4.4.2-1) sid:
debian
CVE-2023-6915P4MEDIUMCVSS 6.2fixed in linux 6.1.76-1 (bookworm)2023
CVE-2023-6915 [MEDIUM] CVE-2023-6915: linux - A Null pointer dereference problem was found in ida_free in lib/idr.c in the Lin... A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attacker using this library to cause a denial of service problem due to a missing check at a function return. Scope: local bookworm: resolved (fixed in 6.1.76-1) bullseye: resolved (fixed in 5.10.209-1) forky: resolved (fixed in 6.6.13-1) sid: resolved (f
debian
CVE-2023-52844P4MEDIUMCVSS 6.2fixed in linux 6.1.64-1 (bookworm)2023
CVE-2023-52844 [MEDIUM] CVE-2023-52844: linux - In the Linux kernel, the following vulnerability has been resolved: media: vidt... In the Linux kernel, the following vulnerability has been resolved: media: vidtv: psi: Add check for kstrdup Add check for the return value of kstrdup() and return the error if it fails in order to avoid NULL pointer dereference. Scope: local bookworm: resolved (fixed in 6.1.64-1) bullseye: resolved (fixed in 5.10.205-1) forky: resolved (fixed in 6.6.8-1) sid: resol
debian
CVE-2023-52858P4MEDIUMCVSS 6.2fixed in linux 6.1.64-1 (bookworm)2023
CVE-2023-52858 [MEDIUM] CVE-2023-52858: linux - In the Linux kernel, the following vulnerability has been resolved: clk: mediat... In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: clk-mt7629: Add check for mtk_alloc_clk_data Add the check for the return value of mtk_alloc_clk_data() in order to avoid NULL pointer dereference. Scope: local bookworm: resolved (fixed in 6.1.64-1) bullseye: resolved (fixed in 5.10.205-1) forky: resolved (fixed in 6.6.8-1) sid: reso
debian
CVE-2017-12168P4MEDIUMCVSS 6.0fixed in linux 4.8.11-1 (bookworm)2017
CVE-2017-12168 [MEDIUM] CVE-2017-12168: linux - The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel ... The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM guest OS users to cause a denial of service (assertion failure and host OS crash) by accessing the Performance Monitors Cycle Count Register (PMCCNTR). Scope: local bookworm: resolved (fixed in 4.8.11-1) bullseye: resolved (fixed in 4.8.11-1) forky: re
debian
CVE-2018-1095P4MEDIUMCVSS 5.5fixed in linux 4.16.5-1 (bookworm)2018
CVE-2018-1095 [MEDIUM] CVE-2018-1095: linux - The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel thr... The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image. Scope: local bookworm: resolved (fixe
debian
CVE-2018-13098P4MEDIUMCVSS 5.5fixed in linux 4.18.10-1 (bookworm)2018
CVE-2018-13098 [MEDIUM] CVE-2018-13098: linux - An issue was discovered in fs/f2fs/inode.c in the Linux kernel through 4.17.3. A... An issue was discovered in fs/f2fs/inode.c in the Linux kernel through 4.17.3. A denial of service (slab out-of-bounds read and BUG) can occur for a modified f2fs filesystem image in which FI_EXTRA_ATTR is set in an inode. Scope: local bookworm: resolved (fixed in 4.18.10-1) bullseye: resolved (fixed in 4.18.10-1) forky: resolved (fixed in 4.18.10-1) sid: resolved (
debian
CVE-2021-44879P4MEDIUMCVSS 5.5fixed in linux 5.16.7-1 (bookworm)2021
CVE-2021-44879 [MEDIUM] CVE-2021-44879: linux - In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special fi... In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. Scope: local bookworm: resolved (fixed in 5.16.7-1) bullseye: resolved (fixed in 5.10.205-2) forky: resolved (fixed in 5.16.7-1) sid: resolved (fixed in 5.16.7-1) trixie: resolved (fixed in 5.16.7-1)
debian
CVE-2024-27388P4MEDIUMCVSS 5.5fixed in linux 6.1.85-1 (bookworm)2024
CVE-2024-27388 [MEDIUM] CVE-2024-27388: linux - In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix... In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix some memleaks in gssx_dec_option_array The creds and oa->data need to be freed in the error-handling paths after their allocation. So this patch add these deallocations in the corresponding paths. Scope: local bookworm: resolved (fixed in 6.1.85-1) bullseye: resolved (fixed in 5.10.216-1
debian
CVE-2024-36929P4MEDIUMCVSS 5.5fixed in linux 6.1.94-1 (bookworm)2024
CVE-2024-36929 [MEDIUM] CVE-2024-36929: linux - In the Linux kernel, the following vulnerability has been resolved: net: core: ... In the Linux kernel, the following vulnerability has been resolved: net: core: reject skb_copy(_expand) for fraglist GSO skbs SKB_GSO_FRAGLIST skbs must not be linearized, otherwise they become invalid. Return NULL if such an skb is passed to skb_copy or skb_copy_expand, in order to prevent a crash on a potential later call to skb_gso_segment. Scope: local bookworm:
debian
CVE-2014-8559P4MEDIUMCVSS 5.5fixed in linux 3.16.7-ckt4-1 (bookworm)2014
CVE-2014-8559 [MEDIUM] CVE-2014-8559: linux - The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not p... The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application. Scope: local bookworm: resolved (fixed in 3.16.7-ckt4-1) bullseye: resolved (fixed in 3.16.7-ckt4-1) forky: resolved (fixed in 3.16.7-c
debian
CVE-2024-40937P4MEDIUMCVSS 5.5fixed in linux 6.1.99-1 (bookworm)2024
CVE-2024-40937 [MEDIUM] CVE-2024-40937: linux - In the Linux kernel, the following vulnerability has been resolved: gve: Clear ... In the Linux kernel, the following vulnerability has been resolved: gve: Clear napi->skb before dev_kfree_skb_any() gve_rx_free_skb incorrectly leaves napi->skb referencing an skb after it is freed with dev_kfree_skb_any(). This can result in a subsequent call to napi_get_frags returning a dangling pointer. Fix this by clearing napi->skb before the skb is freed. Sco
debian
CVE-2024-53217P4MEDIUMCVSS 5.5fixed in linux 6.1.123-1 (bookworm)2024
CVE-2024-53217 [MEDIUM] CVE-2024-53217: linux - In the Linux kernel, the following vulnerability has been resolved: NFSD: Preve... In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent NULL dereference in nfsd4_process_cb_update() @ses is initialized to NULL. If __nfsd4_find_backchannel() finds no available backchannel session, setup_callback_client() will try to dereference @ses and segfault. Scope: local bookworm: resolved (fixed in 6.1.123-1) bullseye: resolved (f
debian
CVE-2024-56645P4MEDIUMCVSS 5.5fixed in linux 6.1.123-1 (bookworm)2024
CVE-2024-56645 [MEDIUM] CVE-2024-56645: linux - In the Linux kernel, the following vulnerability has been resolved: can: j1939:... In the Linux kernel, the following vulnerability has been resolved: can: j1939: j1939_session_new(): fix skb reference counting Since j1939_session_skb_queue() does an extra skb_get() for each new skb, do the same for the initial one in j1939_session_new() to avoid refcount underflow. [mkl: clean up commit message] Scope: local bookworm: resolved (fixed in 6.1.123-1
debian
CVE-2018-7492P4MEDIUMCVSS 5.5fixed in linux 4.14.7-1 (bookworm)2018
CVE-2018-7492 [MEDIUM] CVE-2018-7492: linux - A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() func... A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() function in the Linux kernel before 4.14.7 allowing local attackers to cause a system panic and a denial-of-service, related to RDS_GET_MR and RDS_GET_MR_FOR_DEST. Scope: local bookworm: resolved (fixed in 4.14.7-1) bullseye: resolved (fixed in 4.14.7-1) forky: resolved (fixed in 4.14.7-1) sid
debian
CVE-2022-3113P4MEDIUMCVSS 5.5fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-3113 [MEDIUM] CVE-2022-3113: linux - An issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_... An issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.c lacks check of the return value of devm_kzalloc() and will cause the null pointer dereference. Scope: local bookworm: resolved (fixed in 5.17.3-1) bullseye: resolved (fixed in 5.10.113-1) forky: resolved (fixed in 5.17.3-1) sid:
debian
CVE-2019-0154P4MEDIUMCVSS 5.5fixed in linux 5.3.9-2 (bookworm)2019
CVE-2019-0154 [MEDIUM] CVE-2019-0154: linux - Insufficient access control in subsystem for Intel (R) processor graphics in 6th... Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100
debian
CVE-2024-26760P4MEDIUMCVSS 5.5fixed in linux 6.1.82-1 (bookworm)2024
CVE-2024-26760 [MEDIUM] CVE-2024-26760: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: targe... In the Linux kernel, the following vulnerability has been resolved: scsi: target: pscsi: Fix bio_put() for error case As of commit 066ff571011d ("block: turn bio_kmalloc into a simple kmalloc wrapper"), a bio allocated by bio_kmalloc() must be freed by bio_uninit() and kfree(). That is not done properly for the error case, hitting WARN and NULL pointer dereference i
debian
CVE-2018-12896P4MEDIUMCVSS 5.5fixed in linux 4.18.20-1 (bookworm)2018
CVE-2018-12896 [MEDIUM] CVE-2018-12896: linux - An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow ... An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger than INT_MAX, but the accounting is int based. This basically makes the accounting values, which are visible to
debian
CVE-2025-21795P4MEDIUMCVSS 5.5fixed in linux 6.1.129-1 (bookworm)2025
CVE-2025-21795 [MEDIUM] CVE-2025-21795: linux - In the Linux kernel, the following vulnerability has been resolved: NFSD: fix h... In the Linux kernel, the following vulnerability has been resolved: NFSD: fix hang in nfsd4_shutdown_callback If nfs4_client is in courtesy state then there is no point to send the callback. This causes nfsd4_shutdown_callback to hang since cl_cb_inflight is not 0. This hang lasts about 15 minutes until TCP notifies NFSD that the connection was dropped. This patch m
debian
Debian Linux vulnerabilities | cvebase