Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 437 of 632
CVE-2025-37951P4MEDIUMCVSS 5.5fixed in linux 6.1.140-1 (bookworm)2025
CVE-2025-37951 [MEDIUM] CVE-2025-37951: linux - In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Ad...
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Add job to pending list if the reset was skipped When a CL/CSD job times out, we check if the GPU has made any progress since the last timeout. If so, instead of resetting the hardware, we skip the reset and let the timer get rearmed. This gives long-running jobs a chance to complete. Howev
debian
CVE-2025-38071P4MEDIUMCVSS 5.5fixed in linux 6.1.147-1 (bookworm)2025
CVE-2025-38071 [MEDIUM] CVE-2025-38071: linux - In the Linux kernel, the following vulnerability has been resolved: x86/mm: Che...
In the Linux kernel, the following vulnerability has been resolved: x86/mm: Check return value from memblock_phys_alloc_range() At least with CONFIG_PHYSICAL_START=0x100000, if there is < 4 MiB of contiguous free memory available at this point, the kernel will crash and burn because memblock_phys_alloc_range() returns 0 on failure, which leads memblock_phys_free() t
debian
CVE-2025-37962P4MEDIUMCVSS 5.5fixed in linux 6.1.140-1 (bookworm)2025
CVE-2025-37962 [MEDIUM] CVE-2025-37962: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix memory leak in parse_lease_state() The previous patch that added bounds check for create lease context introduced a memory leak. When the bounds check fails, the function returns NULL without freeing the previously allocated lease_ctx_info structure. This patch fixes the issue by adding k
debian
CVE-2025-37984P4LOWCVSS 5.5fixed in linux 6.16.3-1 (forky)2025
CVE-2025-37984 [MEDIUM] CVE-2025-37984: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: ecd...
In the Linux kernel, the following vulnerability has been resolved: crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() Herbert notes that DIV_ROUND_UP() may overflow unnecessarily if an ecdsa implementation's ->key_size() callback returns an unusually large value. Herbert instead suggests (for a division by 8): X / 8 + !!(X & 7) Based on this formula
debian
CVE-2025-38559P4LOWCVSS 5.5fixed in linux 6.16.3-1 (forky)2025
CVE-2025-38559 [MEDIUM] CVE-2025-38559: linux - In the Linux kernel, the following vulnerability has been resolved: platform/x8...
In the Linux kernel, the following vulnerability has been resolved: platform/x86/intel/pmt: fix a crashlog NULL pointer access Usage of the intel_pmt_read() for binary sysfs, requires a pcidev. The current use of the endpoint value is only valid for telemetry endpoint usage. Without the ep, the crashlog usage causes the following NULL pointer exception: BUG: kernel
debian
CVE-2025-38648P4LOWCVSS 5.5fixed in linux 6.16.3-1 (forky)2025
CVE-2025-38648 [MEDIUM] CVE-2025-38648: linux - In the Linux kernel, the following vulnerability has been resolved: spi: stm32:...
In the Linux kernel, the following vulnerability has been resolved: spi: stm32: Check for cfg availability in stm32_spi_probe The stm32_spi_probe function now includes a check to ensure that the pointer returned by of_device_get_match_data is not NULL before accessing its members. This resolves a warning where a potential NULL pointer dereference could occur when ac
debian
CVE-2025-38417P4LOWCVSS 5.5fixed in linux 6.12.35-1 (forky)2025
CVE-2025-38417 [MEDIUM] CVE-2025-38417: linux - In the Linux kernel, the following vulnerability has been resolved: ice: fix es...
In the Linux kernel, the following vulnerability has been resolved: ice: fix eswitch code memory leak in reset scenario Add simple eswitch mode checker in attaching VF procedure and allocate required port representor memory structures only in switchdev mode. The reset flows triggers VF (if present) detach/attach procedure. It might involve VF port representor(s) re-
debian
CVE-2025-38392P4LOWCVSS 5.5fixed in linux 6.12.37-1 (forky)2025
CVE-2025-38392 [MEDIUM] CVE-2025-38392: linux - In the Linux kernel, the following vulnerability has been resolved: idpf: conve...
In the Linux kernel, the following vulnerability has been resolved: idpf: convert control queue mutex to a spinlock With VIRTCHNL2_CAP_MACFILTER enabled, the following warning is generated on module load: [ 324.701677] BUG: sleeping function called from invalid context at kernel/locking/mutex.c:578 [ 324.701684] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid:
debian
CVE-2025-38360P4LOWCVSS 5.5fixed in linux 6.12.37-1 (forky)2025
CVE-2025-38360 [MEDIUM] CVE-2025-38360: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amd/dis...
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add more checks for DSC / HUBP ONO guarantees [WHY] For non-zero DSC instances it's possible that the HUBP domain required to drive it for sequential ONO ASICs isn't met, potentially causing the logic to the tile to enter an undefined state leading to a system hang. [HOW] Add more c
debian
CVE-2025-38312P4MEDIUMCVSS 5.5fixed in linux 6.1.147-1 (bookworm)2025
CVE-2025-38312 [MEDIUM] CVE-2025-38312: linux - In the Linux kernel, the following vulnerability has been resolved: fbdev: core...
In the Linux kernel, the following vulnerability has been resolved: fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod() In fb_find_mode_cvt(), iff mode->refresh somehow happens to be 0x80000000, cvt.f_refresh will become 0 when multiplying it by 2 due to overflow. It's then passed to fb_cvt_hperiod(), where it's used as a divider -- division by 0 will result
debian
CVE-2025-38231P4MEDIUMCVSS 5.5fixed in linux 6.1.147-1 (bookworm)2025
CVE-2025-38231 [MEDIUM] CVE-2025-38231: linux - In the Linux kernel, the following vulnerability has been resolved: nfsd: Initi...
In the Linux kernel, the following vulnerability has been resolved: nfsd: Initialize ssc before laundromat_work to prevent NULL dereference In nfs4_state_start_net(), laundromat_work may access nfsd_ssc through nfs4_laundromat -> nfsd4_ssc_expire_umount. If nfsd_ssc isn't initialized, this can cause NULL pointer dereference. Normally the delayed start of laundromat_
debian
CVE-2023-53189P4MEDIUMCVSS 5.5fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-53189 [MEDIUM] CVE-2023-53189: linux - In the Linux kernel, the following vulnerability has been resolved: ipv6/addrco...
In the Linux kernel, the following vulnerability has been resolved: ipv6/addrconf: fix a potential refcount underflow for idev Now in addrconf_mod_rs_timer(), reference idev depends on whether rs_timer is not pending. Then modify rs_timer timeout. There is a time gap in [1], during which if the pending rs_timer becomes not pending. It will miss to hold idev, but the
debian
CVE-2023-53474P4MEDIUMCVSS 5.5fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-53474 [MEDIUM] CVE-2023-53474: linux - In the Linux kernel, the following vulnerability has been resolved: x86/MCE/AMD...
In the Linux kernel, the following vulnerability has been resolved: x86/MCE/AMD: Use an u64 for bank_map Thee maximum number of MCA banks is 64 (MAX_NR_BANKS), see a0bc32b3cacf ("x86/mce: Increase maximum number of banks to 64"). However, the bank_map which contains a bitfield of which banks to initialize is of type unsigned int and that overflows when those bit num
debian
CVE-2023-53314P4MEDIUMCVSS 5.5fixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-53314 [MEDIUM] CVE-2023-53314: linux - In the Linux kernel, the following vulnerability has been resolved: fbdev/ep93x...
In the Linux kernel, the following vulnerability has been resolved: fbdev/ep93xx-fb: Do not assign to struct fb_info.dev Do not assing the Linux device to struct fb_info.dev. The call to register_framebuffer() initializes the field to the fbdev device. Drivers should not override its value. Fixes a bug where the driver incorrectly decreases the hardware device's ref
debian
CVE-2023-53660P4MEDIUMCVSS 5.5fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-53660 [MEDIUM] CVE-2023-53660: linux - In the Linux kernel, the following vulnerability has been resolved: bpf, cpumap...
In the Linux kernel, the following vulnerability has been resolved: bpf, cpumap: Handle skb as well when clean up ptr_ring The following warning was reported when running xdp_redirect_cpu with both skb-mode and stress-mode enabled: ------------[ cut here ]------------ Incorrect XDP memory type (-2128176192) usage WARNING: CPU: 7 PID: 1442 at net/core/xdp.c:405 Modul
debian
CVE-2025-38202P4MEDIUMCVSS 5.5fixed in linux 6.1.147-1 (bookworm)2025
CVE-2025-38202 [MEDIUM] CVE-2025-38202: linux - In the Linux kernel, the following vulnerability has been resolved: bpf: Check ...
In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() bpf_map_lookup_percpu_elem() helper is also available for sleepable bpf program. When BPF JIT is disabled or under 32-bit host, bpf_map_lookup_percpu_elem() will not be inlined. Using it in a sleepable bpf program will trigger the
debian
CVE-2025-37986P4LOWCVSS 5.5fixed in linux 6.12.27-1 (forky)2025
CVE-2025-37986 [MEDIUM] CVE-2025-37986: linux - In the Linux kernel, the following vulnerability has been resolved: usb: typec:...
In the Linux kernel, the following vulnerability has been resolved: usb: typec: class: Invalidate USB device pointers on partner unregistration To avoid using invalid USB device pointers after a Type-C partner disconnects, this patch clears the pointers upon partner unregistration. This ensures a clean state for future connections.
Scope: local
bookworm: resolved
bu
debian
CVE-2025-37993P4LOWCVSS 5.5fixed in linux 6.12.29-1 (forky)2025
CVE-2025-37993 [MEDIUM] CVE-2025-37993: linux - In the Linux kernel, the following vulnerability has been resolved: can: m_can:...
In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_class_allocate_dev(): initialize spin lock on device probe The spin lock tx_handling_spinlock in struct m_can_classdev is not being initialized. This leads the following spinlock bad magic complaint from the kernel, eg. when trying to send CAN frames with cansend from can-utils: |
debian
CVE-2022-50415P4MEDIUMCVSS 5.5fixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50415 [MEDIUM] CVE-2022-50415: linux - In the Linux kernel, the following vulnerability has been resolved: parisc: led...
In the Linux kernel, the following vulnerability has been resolved: parisc: led: Fix potential null-ptr-deref in start_task() start_task() calls create_singlethread_workqueue() and not checked the ret value, which may return NULL. And a null-ptr-deref may happen: start_task() create_singlethread_workqueue() # failed, led_wq is NULL queue_delayed_work() queue_delayed
debian
CVE-2022-50390P4MEDIUMCVSS 5.5fixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50390 [MEDIUM] CVE-2022-50390: linux - In the Linux kernel, the following vulnerability has been resolved: drm/ttm: fi...
In the Linux kernel, the following vulnerability has been resolved: drm/ttm: fix undefined behavior in bit shift for TTM_TT_FLAG_PRIV_POPULATED Shifting signed 32-bit value by 31 bits is undefined, so changing significant bit to unsigned. The UBSAN warning calltrace like below: UBSAN: shift-out-of-bounds in ./include/drm/ttm/ttm_tt.h:122:26 left shift of 1 by 31 pla
debian