cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 455 of 632
CVE-2025-40345P4UNKNOWNfixed in linux 6.1.159-1 (bookworm)2025
CVE-2025-40345 CVE-2025-40345: linux - In the Linux kernel, the following vulnerability has been resolved: usb: storag... In the Linux kernel, the following vulnerability has been resolved: usb: storage: sddr55: Reject out-of-bound new_pba Discovered by Atuin - Automated Vulnerability Discovery Engine. new_pba comes from the status packet returned after each write. A bogus device could report values beyond the block count derived from info->capacity, letting the driver walk off the end of pba_t
debian
CVE-2023-54229P4UNKNOWNfixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-54229 CVE-2023-54229: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath11... In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix registration of 6Ghz-only phy without the full channel range Because of what seems to be a typo, a 6Ghz-only phy for which the BDF does not allow the 7115Mhz channel will fail to register: WARNING: CPU: 2 PID: 106 at net/wireless/core.c:907 wiphy_register+0x914/0x954 Modules linked in: ath1
debian
CVE-2022-50699P4UNKNOWNfixed in linux 6.0.6-1 (bookworm)2022
CVE-2022-50699 CVE-2022-50699: linux - In the Linux kernel, the following vulnerability has been resolved: selinux: en... In the Linux kernel, the following vulnerability has been resolved: selinux: enable use of both GFP_KERNEL and GFP_ATOMIC in convert_context() The following warning was triggered on a hardware environment: SELinux: Converting 162 SID table entries... BUG: sleeping function called from invalid context at __might_sleep+0x60/0x74 0x0 in_atomic(): 1, irqs_disabled(): 128, non_bl
debian
CVE-2023-54147P4UNKNOWNfixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-54147 CVE-2023-54147: linux - In the Linux kernel, the following vulnerability has been resolved: media: plat... In the Linux kernel, the following vulnerability has been resolved: media: platform: mtk-mdp3: Add missing check and free for ida_alloc Add the check for the return value of the ida_alloc in order to avoid NULL pointer dereference. Moreover, free allocated "ctx->id" if mdp_m2m_open fails later in order to avoid memory leak. Scope: local bookworm: resolved (fixed in 6.1.37-1)
debian
CVE-2023-54301P4UNKNOWNfixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-54301 CVE-2023-54301: linux - In the Linux kernel, the following vulnerability has been resolved: serial: 825... In the Linux kernel, the following vulnerability has been resolved: serial: 8250_bcm7271: fix leak in `brcmuart_probe` Smatch reports: drivers/tty/serial/8250/8250_bcm7271.c:1120 brcmuart_probe() warn: 'baud_mux_clk' from clk_prepare_enable() not released on lines: 1032. The issue is fixed by using a managed clock. Scope: local bookworm: resolved (fixed in 6.1.37-1) bullseye
debian
CVE-2023-54302P4UNKNOWNfixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-54302 CVE-2023-54302: linux - In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma:... In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix data race on CQP completion stats CQP completion statistics is read lockesly in irdma_wait_event and irdma_check_cqp_progress while it can be updated in the completion thread irdma_sc_ccq_get_cqe_info on another CPU as KCSAN reports. Make completion statistics an atomic variable to reflect co
debian
CVE-2023-54295P4UNKNOWNfixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-54295 CVE-2023-54295: linux - In the Linux kernel, the following vulnerability has been resolved: mtd: spi-no... In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: Fix shift-out-of-bounds in spi_nor_set_erase_type spi_nor_set_erase_type() was used either to set or to mask out an erase type. When we used it to mask out an erase type a shift-out-of-bounds was hit: UBSAN: shift-out-of-bounds in drivers/mtd/spi-nor/core.c:2237:24 shift exponent 4294967295 is
debian
CVE-2023-54271P4UNKNOWNfixed in linux 6.5.3-1 (forky)2023
CVE-2023-54271 CVE-2023-54271: linux - In the Linux kernel, the following vulnerability has been resolved: blk-cgroup:... In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: Fix NULL deref caused by blkg_policy_data being installed before init blk-iocost sometimes causes the following crash: BUG: kernel NULL pointer dereference, address: 00000000000000e0 ... RIP: 0010:_raw_spin_lock+0x17/0x30 Code: be 01 02 00 00 e8 79 38 39 ff 31 d2 89 d0 5d c3 0f 1f 00 0f 1f 44 00
debian
CVE-2023-54176P4UNKNOWNfixed in linux 6.1.25-1 (bookworm)2023
CVE-2023-54176 CVE-2023-54176: linux - In the Linux kernel, the following vulnerability has been resolved: mptcp: stri... In the Linux kernel, the following vulnerability has been resolved: mptcp: stricter state check in mptcp_worker As reported by Christoph, the mptcp protocol can run the worker when the relevant msk socket is in an unexpected state: connect() // incoming reset + fastclose // the mptcp worker is scheduled mptcp_disconnect() // msk is now CLOSED listen() mptcp_worker() Leading
debian
CVE-2026-23054P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2026
CVE-2026-23054 CVE-2026-23054: linux - In the Linux kernel, the following vulnerability has been resolved: net: hv_net... In the Linux kernel, the following vulnerability has been resolved: net: hv_netvsc: reject RSS hash key programming without RX indirection table RSS configuration requires a valid RX indirection table. When the device reports a single receive queue, rndis_filter_device_add() does not allocate an indirection table, accepting RSS hash key updates in this state leads to a hang.
debian
CVE-2025-68804P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-68804 CVE-2025-68804: linux - In the Linux kernel, the following vulnerability has been resolved: platform/ch... In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_ishtp: Fix UAF after unbinding driver After unbinding the driver, another kthread `cros_ec_console_log_work` is still accessing the device, resulting an UAF and crash. The driver doesn't unregister the EC device in .remove() which should shutdown sub-devices synchronously. Fix it. Sc
debian
CVE-2025-68798P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-68798 CVE-2025-68798: linux - In the Linux kernel, the following vulnerability has been resolved: perf/x86/am... In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd: Check event before enable to avoid GPF On AMD machines cpuc->events[idx] can become NULL in a subtle race condition with NMI->throttle->x86_pmu_stop(). Check event for NULL in amd_pmu_enable_all() before enable to avoid a GPF. This appears to be an AMD only issue. Syzkaller reported a GPF in am
debian
CVE-2025-71199P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-71199 CVE-2025-71199: linux - In the Linux kernel, the following vulnerability has been resolved: iio: adc: a... In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91-sama5d2_adc: Fix potential use-after-free in sama5d2_adc driver at91_adc_interrupt can call at91_adc_touch_data_handler function to start the work by schedule_work(&st->touch_st.workq). If we remove the module which will call at91_adc_remove to make cleanup, it will free indio_dev through iio_
debian
CVE-2025-68767P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-68767 CVE-2025-68767: linux - In the Linux kernel, the following vulnerability has been resolved: hfsplus: Ve... In the Linux kernel, the following vulnerability has been resolved: hfsplus: Verify inode mode when loading from disk syzbot is reporting that S_IFMT bits of inode->i_mode can become bogus when the S_IFMT bits of the 16bits "mode" field loaded from disk are corrupted. According to [1], the permissions field was treated as reserved in Mac OS 8 and 9. According to [2], the res
debian
CVE-2025-68813P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-68813 CVE-2025-68813: linux - In the Linux kernel, the following vulnerability has been resolved: ipvs: fix i... In the Linux kernel, the following vulnerability has been resolved: ipvs: fix ipv4 null-ptr-deref in route error path The IPv4 code path in __ip_vs_get_out_rt() calls dst_link_failure() without ensuring skb->dev is set, leading to a NULL pointer dereference in fib_compute_spec_dst() when ipv4_link_failure() attempts to send ICMP destination unreachable messages. The issue em
debian
CVE-2023-54242P4UNKNOWNfixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-54242 CVE-2023-54242: linux - In the Linux kernel, the following vulnerability has been resolved: block, bfq:... In the Linux kernel, the following vulnerability has been resolved: block, bfq: Fix division by zero error on zero wsum When the weighted sum is zero the calculation of limit causes a division by zero error. Fix this by continuing to the next level. This was discovered by running as root: stress-ng --ioprio 0 Fixes divison by error oops: [ 521.450556] divide error: 0000 [#1]
debian
CVE-2013-2892P4LOWCVSS 4.7fixed in linux 3.10.11-1 (bookworm)2013
CVE-2013-2892 [MEDIUM] CVE-2013-2892: linux - drivers/hid/hid-pl.c in the Human Interface Device (HID) subsystem in the Linux ... drivers/hid/hid-pl.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PANTHERLORD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device. Scope: local bookworm: resolved (fixed in 3.10.11-1) bullseye: resolved (fixed in 3.10.11-1) forky: resolve
debian
CVE-2025-40091P4LOWfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40091 [LOW] CVE-2025-40091: linux - In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix ... In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix too early devlink_free() in ixgbe_remove() Since ixgbe_adapter is embedded in devlink, calling devlink_free() prematurely in the ixgbe_remove() path can lead to UAF. Move devlink_free() to the end. KASAN report: BUG: KASAN: use-after-free in ixgbe_reset_interrupt_capability+0x140/0x180 [ixgb
debian
CVE-2025-40072P4LOWfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40072 [LOW] CVE-2025-40072: linux - In the Linux kernel, the following vulnerability has been resolved: fanotify: V... In the Linux kernel, the following vulnerability has been resolved: fanotify: Validate the return value of mnt_ns_from_dentry() before dereferencing The function do_fanotify_mark() does not validate if mnt_ns_from_dentry() returns NULL before dereferencing mntns->user_ns. This causes a NULL pointer dereference in do_fanotify_mark() if the path is not a mount namespace
debian
CVE-2025-40175P4LOWfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40175 [LOW] CVE-2025-40175: linux - In the Linux kernel, the following vulnerability has been resolved: idpf: clean... In the Linux kernel, the following vulnerability has been resolved: idpf: cleanup remaining SKBs in PTP flows When the driver requests Tx timestamp value, one of the first steps is to clone SKB using skb_get. It increases the reference counter for that SKB to prevent unexpected freeing by another component. However, there may be a case where the index is requested, SKB
debian
Debian Linux vulnerabilities | cvebase