Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 461 of 632
CVE-2012-3510P4MEDIUMCVSS 5.6fixed in linux 2.6.20-1 (bookworm)2012
CVE-2012-3510 [MEDIUM] CVE-2012-3510: linux - Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in...
Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially sensitive information from kernel memory or cause a denial of service (system crash) via a taskstats TASKSTATS_CMD_ATTR_PID command.
Scope: local
bookworm: resolved (fixed in 2.6.20-1)
bullseye: resolved (fixed in 2.6
debian
CVE-2023-39194P4LOWCVSS 3.2fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-39194 [LOW] CVE-2023-39194: linux - A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw ex...
A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.
Scope: local
bookworm: resolved (fixe
debian
CVE-2016-6198P4MEDIUMCVSS 5.5fixed in linux 4.5.5-1 (bookworm)2016
CVE-2016-6198 [MEDIUM] CVE-2016-6198: linux - The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename ...
The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed to a self-hardlink, which allows local users to cause a denial of service (system crash) via a rename system call, related to fs/namei.c and fs/open.c.
Scope: local
bookworm: resolved (fixed in 4.5.5-1)
bullseye: resolved (fixed in 4.5.5-1)
for
debian
CVE-2019-19051P4MEDIUMCVSS 5.5fixed in linux 5.3.15-1 (bookworm)2019
CVE-2019-19051 [MEDIUM] CVE-2019-19051: linux - A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/...
A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-6f3ef5c25cc7.
Scope: local
bookworm: resolved (fixed in 5.3.15-1)
bullseye: resolved (fixed in 5.3.15-1)
forky: resolved (fixed in 5.3.15-1)
sid: resolved (fix
debian
CVE-2022-28356P4MEDIUMCVSS 5.5fixed in linux 5.16.18-1 (bookworm)2022
CVE-2022-28356 [MEDIUM] CVE-2022-28356: linux - In the Linux kernel before 5.17.1, a refcount leak bug was found in net/llc/af_l...
In the Linux kernel before 5.17.1, a refcount leak bug was found in net/llc/af_llc.c.
Scope: local
bookworm: resolved (fixed in 5.16.18-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: resolved (fixed in 5.16.18-1)
sid: resolved (fixed in 5.16.18-1)
trixie: resolved (fixed in 5.16.18-1)
debian
CVE-2016-4470P4MEDIUMCVSS 5.5fixed in linux 4.6.2-2 (bookworm)2016
CVE-2016-4470 [MEDIUM] CVE-2016-4470: linux - The key_reject_and_link function in security/keys/key.c in the Linux kernel thro...
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.
Scope: local
bookworm: resolved (fixed in 4.6.2-2)
bullseye: resolved (fixed in 4.6.2-2)
for
debian
CVE-2018-10323P4MEDIUMCVSS 5.5fixed in linux 4.16.5-1 (bookworm)2018
CVE-2018-10323 [MEDIUM] CVE-2018-10323: linux - The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux ...
The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_bmapi_write NULL pointer dereference) via a crafted xfs image.
Scope: local
bookworm: resolved (fixed in 4.16.5-1)
bullseye: resolved (fixed in 4.16.5-1)
forky: resolved (fixed in 4.16.5-1)
sid: resolved (fixed in
debian
CVE-2016-4581P4MEDIUMCVSS 5.5fixed in linux 4.5.4-1 (bookworm)2016
CVE-2016-4581 [MEDIUM] CVE-2016-4581: linux - fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount p...
fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a certain case involving a slave mount, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted series of mount system calls.
Scope: local
bookworm: resolved (fixed in 4.5.4-1)
bullseye: resolved (fixed in 4.5.4-1)
forky: r
debian
CVE-2014-0203P4MEDIUMCVSS 5.5fixed in linux 2.6.33-1 (bookworm)2014
CVE-2014-0203 [MEDIUM] CVE-2014-0203: linux - The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 do...
The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service (incorrect free operations and system crash) via an open system call.
Scope: local
bookworm: resolved (fixed in 2.6.33-1)
bullseye: resolved (fixed in
debian
CVE-2022-0286P4MEDIUMCVSS 5.5fixed in linux 5.14.6-1 (bookworm)2022
CVE-2022-0286 [MEDIUM] CVE-2022-0286: linux - A flaw was found in the Linux kernel. A null pointer dereference in bond_ipsec_a...
A flaw was found in the Linux kernel. A null pointer dereference in bond_ipsec_add_sa() may lead to local denial of service.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
debian
CVE-2016-3695P4MEDIUMCVSS 5.5fixed in linux 4.5.1-1 (bookworm)2016
CVE-2016-3695 [MEDIUM] CVE-2016-3695: linux - The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel a...
The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disable APEI error injection through EINJ when securelevel is set.
Scope: local
bookworm: resolved (fixed in 4.5.1-1)
bullseye: resolved (fixed in 4.5.1-1)
forky: resolved (fix
debian
CVE-2018-10322P4MEDIUMCVSS 5.5fixed in linux 4.16.5-1 (bookworm)2018
CVE-2018-10322 [MEDIUM] CVE-2018-10322: linux - The xfs_dinode_verify function in fs/xfs/libxfs/xfs_inode_buf.c in the Linux ker...
The xfs_dinode_verify function in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_ilock_attr_map_shared invalid pointer dereference) via a crafted xfs image.
Scope: local
bookworm: resolved (fixed in 4.16.5-1)
bullseye: resolved (fixed in 4.16.5-1)
forky: resolved (fixed in 4.16.5-1)
sid: resolved
debian
CVE-2018-6554P4MEDIUMCVSS 5.5fixed in linux 4.17.3-1 (bookworm)2018
CVE-2018-6554 [MEDIUM] CVE-2018-6554: linux - Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers...
Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (memory consumption) by repeatedly binding an AF_IRDA socket.
Scope: local
bookworm: resolved (fixed in 4.17.3-1)
bullseye: resolved (fixed in 4.17.3-1)
forky: resolved (fixed in 4.1
debian
CVE-2015-8970P4MEDIUMCVSS 5.5fixed in linux 4.4.2-1 (bookworm)2015
CVE-2015-8970 [MEDIUM] CVE-2015-8970: linux - crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a ...
crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted application that does not supply a key, related to the lrw_crypt function in cr
debian
CVE-2024-36964P4MEDIUMCVSS 5.5fixed in linux 6.1.94-1 (bookworm)2024
CVE-2024-36964 [MEDIUM] CVE-2024-36964: linux - In the Linux kernel, the following vulnerability has been resolved: fs/9p: only...
In the Linux kernel, the following vulnerability has been resolved: fs/9p: only translate RWX permissions for plain 9P2000 Garbage in plain 9P2000's perm bits is allowed through, which causes it to be able to set (among others) the suid bit. This was presumably not the intent since the unix extended bits are handled explicitly and conditionally on .u.
Scope: local
b
debian
CVE-2021-47374P4MEDIUMCVSS 5.5fixed in linux 5.14.9-1 (bookworm)2021
CVE-2021-47374 [MEDIUM] CVE-2021-47374: linux - In the Linux kernel, the following vulnerability has been resolved: dma-debug: ...
In the Linux kernel, the following vulnerability has been resolved: dma-debug: prevent an error message from causing runtime problems For some drivers, that use the DMA API. This error message can be reached several millions of times per second, causing spam to the kernel's printk buffer and bringing the CPU usage up to 100% (so, it should be rate limited). However,
debian
CVE-2018-1130P4MEDIUMCVSS 5.5fixed in linux 4.15.17-1 (bookworm)2018
CVE-2018-1130 [MEDIUM] CVE-2018-1130: linux - Linux kernel before version 4.16-rc7 is vulnerable to a null pointer dereference...
Linux kernel before version 4.16-rc7 is vulnerable to a null pointer dereference in dccp_write_xmit() function in net/dccp/output.c in that allows a local user to cause a denial of service by a number of certain crafted system calls.
Scope: local
bookworm: resolved (fixed in 4.15.17-1)
bullseye: resolved (fixed in 4.15.17-1)
forky: resolved (fixed in 4.15.17-1)
sid: r
debian
CVE-2021-38208P4MEDIUMCVSS 5.5fixed in linux 5.10.46-1 (bookworm)2021
CVE-2021-38208 [MEDIUM] CVE-2021-38208: linux - net/nfc/llcp_sock.c in the Linux kernel before 5.12.10 allows local unprivileged...
net/nfc/llcp_sock.c in the Linux kernel before 5.12.10 allows local unprivileged users to cause a denial of service (NULL pointer dereference and BUG) by making a getsockname call after a certain type of failure of a bind call.
Scope: local
bookworm: resolved (fixed in 5.10.46-1)
bullseye: resolved (fixed in 5.10.46-1)
forky: resolved (fixed in 5.10.46-1)
sid: resol
debian
CVE-2015-1350P4MEDIUMCVSS 5.5fixed in linux 4.8.11-1 (bookworm)2015
CVE-2015-1350 [MEDIUM] CVE-2015-1350: linux - The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirem...
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark du
debian
CVE-2017-18216P4MEDIUMCVSS 5.5fixed in linux 4.15.4-1 (bookworm)2017
CVE-2017-18216 [MEDIUM] CVE-2017-18216: linux - In fs/ocfs2/cluster/nodemanager.c in the Linux kernel before 4.15, local users c...
In fs/ocfs2/cluster/nodemanager.c in the Linux kernel before 4.15, local users can cause a denial of service (NULL pointer dereference and BUG) because a required mutex is not used.
Scope: local
bookworm: resolved (fixed in 4.15.4-1)
bullseye: resolved (fixed in 4.15.4-1)
forky: resolved (fixed in 4.15.4-1)
sid: resolved (fixed in 4.15.4-1)
trixie: resolved (fixed i
debian