Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 4 of 632
CVE-2021-43267P2CRITICALCVSS 9.8fixed in linux 5.14.16-1 (bookworm)2021
CVE-2021-43267 [CRITICAL] CVE-2021-43267: linux - An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16....
An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.
Scope: local
bookworm: resolved (fixed in 5.14.16-1)
bullseye: resolved (fixed in 5.10.84-1)
forky: resol
debian
CVE-2022-1043P3HIGHCVSS 8.8PoCfixed in linux 5.14.6-1 (bookworm)2022
CVE-2022-1043 [HIGH] CVE-2022-1043: linux - A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows...
A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows an attacker with a local account to corrupt system memory, crash the system or escalate privileges.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.
debian
CVE-2019-11477P2HIGHCVSS 7.5fixed in linux 4.19.37-4 (bookworm)2019
CVE-2019-11477 [HIGH] CVE-2019-11477: linux - Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subj...
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8
debian
CVE-2019-11479P2HIGHCVSS 7.5fixed in linux 4.19.37-4 (bookworm)2019
CVE-2019-11479 [HIGH] CVE-2019-11479: linux - Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48...
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in c
debian
CVE-2017-1000112P3LOWCVSS 7.0PoCfixed in linux 4.12.6-1 (bookworm)2017
CVE-2017-1000112 [HIGH] CVE-2017-1000112: linux - Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. W...
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_append_data() calls ip_ufo_append_data() to append. However in between two send() calls, the append path can be switched from UFO to non-UFO one, which leads to a memory corruption. In case UFO packet lengths exceeds MTU, copy = maxfraglen -
debian
CVE-2016-4997P3HIGHCVSS 7.8PoCfixed in linux 4.6.2-2 (bookworm)2016
CVE-2016-4997 [HIGH] CVE-2016-4997: linux - The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations...
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.
Scope: local
bookworm: resolved (
debian
CVE-2019-11478P2MEDIUMCVSS 5.3fixed in linux 4.19.37-4 (bookworm)2019
CVE-2019-11478 [MEDIUM] CVE-2019-11478: linux - Jonathan Looney discovered that the TCP retransmission queue implementation in t...
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed
debian
CVE-2017-5123P3HIGHCVSS 8.8PoCfixed in linux 4.13.4-2 (bookworm)2017
CVE-2017-5123 [HIGH] CVE-2017-5123: linux - Insufficient data validation in waitid allowed an user to escape sandboxes on Li...
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
Scope: local
bookworm: resolved (fixed in 4.13.4-2)
bullseye: resolved (fixed in 4.13.4-2)
forky: resolved (fixed in 4.13.4-2)
sid: resolved (fixed in 4.13.4-2)
trixie: resolved (fixed in 4.13.4-2)
debian
CVE-2015-8660P3MEDIUMCVSS 6.7PoCfixed in linux 4.3.3-3 (bookworm)2015
CVE-2015-8660 [MEDIUM] CVE-2015-8660: linux - The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3...
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.
Scope: local
bookworm: resolved (fixed in 4.3.3-3)
bullseye: resolved (fixed in 4.3.3-3)
forky:
debian
CVE-2018-17182P3HIGHCVSS 7.8PoCfixed in linux 4.18.10-1 (bookworm)2018
CVE-2018-17182 [HIGH] CVE-2018-17182: linux - An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_a...
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, map, unmap, invalidation, and dereference operations.
Scope: local
bookworm: resolved (fixed in 4.18.10-1)
bullseye: resol
debian
CVE-2022-0995P3HIGHCVSS 7.8PoCfixed in linux 5.16.18-1 (bookworm)2022
CVE-2022-0995 [HIGH] CVE-2022-0995: linux - An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_q...
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
Scope: local
bookworm: resolved (fixed in 5.16.18-1)
bullseye: resolved (fixed in 5.10.106-1)
forky: r
debian
CVE-2023-0210P2HIGHCVSS 7.5fixed in linux 6.1.7-1 (bookworm)2023
CVE-2023-0210 [HIGH] CVE-2023-0210: linux - A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to cra...
A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based systems.
Scope: local
bookworm: resolved (fixed in 6.1.7-1)
bullseye: resolved
forky: resolved (fixed in 6.1.7-1)
sid: resolved (fixed in 6.1.7-1)
trixie: resolved (fixed in 6.1.7-1)
debian
CVE-2017-6074P3HIGHCVSS 7.8PoCfixed in linux 4.9.13-1 (bookworm)2017
CVE-2017-6074 [HIGH] CVE-2017-6074: linux - The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel thro...
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2017-7558P3MEDIUMCVSS 5.1PoCfixed in linux 4.12.13-1 (bookworm)2017
CVE-2017-7558 [MEDIUM] CVE-2017-7558: linux - A kernel data leak due to an out-of-bound read was found in the Linux kernel in ...
A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions present since version 4.7-rc1 through version 4.13. A data leak happens when these functions fill in sockaddr data structures used to export socket's diagnostic information. As a result, up to 100 bytes of the slab data c
debian
CVE-2017-15649P3HIGHCVSS 7.8PoCfixed in linux 4.13.10-1 (bookworm)2017
CVE-2017-15649 [HIGH] CVE-2017-15649: linux - net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to g...
net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet_do_bind) that leads to a use-after-free, a different vulnerability than CVE-2017-6346.
Scope: local
bookworm: resolved (fixed in 4
debian
CVE-2016-6187P3HIGHCVSS 7.8PoCfixed in linux 4.6.4-1 (bookworm)2016
CVE-2016-6187 [HIGH] CVE-2016-6187: linux - The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel...
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which allows local users to gain privileges by triggering an AppArmor setprocattr hook.
Scope: local
bookworm: resolved (fixed in 4.6.4-1)
bullseye: resolved (fixed in 4.6.4-1)
forky: resolved (fixed in 4.6.4-1)
sid: resolved (fixed in 4.6.4-1
debian
CVE-2022-47939P2CRITICALCVSS 9.8fixed in linux 5.19.6-1 (bookworm)2022
CVE-2022-47939 [CRITICAL] CVE-2022-47939: linux - An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5....
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_DISCONNECT.
Scope: local
bookworm: resolved (fixed in 5.19.6-1)
bullseye: resolved
forky: resolved (fixed in 5.19.6-1)
sid: resolved (fixed in 5.19.6-1)
trixie: resolved (fixed in 5.19.6-1)
debian
CVE-2022-22942P3HIGHCVSS 7.8PoCfixed in linux 5.15.15-2 (bookworm)2022
CVE-2022-22942 [HIGH] CVE-2022-22942: linux - The vmwgfx driver contains a local privilege escalation vulnerability that allow...
The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer.
Scope: local
bookworm: resolved (fixed in 5.15.15-2)
bullseye: resolved (fixed in 5.10.92-2)
forky: resolved (fixed in 5.15.15-2)
sid: resolved (fixed in 5.15.15-2)
trixi
debian
CVE-2014-9322P3HIGHCVSS 7.8PoCfixed in linux 3.16.7-ckt2-1 (bookworm)2014
CVE-2014-9322 [HIGH] CVE-2014-9322: linux - arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly h...
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt2-1)
bullseye: resolved (fix
debian
CVE-2017-8824P3HIGHCVSS 7.8PoCfixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-8824 [HIGH] CVE-2017-8824: linux - The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.1...
The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.
Scope: local
bookworm: resolved (fixed in 4.14.7-1)
bullseye: resolved (fixed in 4.14.7-1)
forky: resolved (fixed in 4.14.7-1)
sid: resol
debian