cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 462 of 632
CVE-2018-19407P4MEDIUMCVSS 5.5fixed in linux 4.19.9-1 (bookworm)2018
CVE-2018-19407 [MEDIUM] CVE-2018-19407: linux - The vcpu_scan_ioapic function in arch/x86/kvm/x86.c in the Linux kernel through ... The vcpu_scan_ioapic function in arch/x86/kvm/x86.c in the Linux kernel through 4.19.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) via crafted system calls that reach a situation where ioapic is uninitialized. Scope: local bookworm: resolved (fixed in 4.19.9-1) bullseye: resolved (fixed in 4.19.9-1) forky: resolved (fixed in 4.
debian
CVE-2017-18208P4MEDIUMCVSS 5.5fixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-18208 [MEDIUM] CVE-2017-18208: linux - The madvise_willneed function in mm/madvise.c in the Linux kernel before 4.14.4 ... The madvise_willneed function in mm/madvise.c in the Linux kernel before 4.14.4 allows local users to cause a denial of service (infinite loop) by triggering use of MADVISE_WILLNEED for a DAX mapping. Scope: local bookworm: resolved (fixed in 4.14.7-1) bullseye: resolved (fixed in 4.14.7-1) forky: resolved (fixed in 4.14.7-1) sid: resolved (fixed in 4.14.7-1) trixie
debian
CVE-2018-10021P4MEDIUMCVSS 5.5fixed in linux 4.15.17-1 (bookworm)2018
CVE-2018-10021 [MEDIUM] CVE-2018-10021: linux - drivers/scsi/libsas/sas_scsi_host.c in the Linux kernel before 4.16 allows local... drivers/scsi/libsas/sas_scsi_host.c in the Linux kernel before 4.16 allows local users to cause a denial of service (ata qc leak) by triggering certain failure conditions. NOTE: a third party disputes the relevance of this report because the failure can only occur for physically proximate attackers who unplug SAS Host Bus Adapter cables Scope: local bookworm: resolv
debian
CVE-2016-8645P4MEDIUMCVSS 5.5fixed in linux 4.8.11-1 (bookworm)2016
CVE-2016-8645 [MEDIUM] CVE-2016-8645: linux - The TCP stack in the Linux kernel before 4.8.10 mishandles skb truncation, which... The TCP stack in the Linux kernel before 4.8.10 mishandles skb truncation, which allows local users to cause a denial of service (system crash) via a crafted application that makes sendto system calls, related to net/ipv4/tcp_ipv4.c and net/ipv6/tcp_ipv6.c. Scope: local bookworm: resolved (fixed in 4.8.11-1) bullseye: resolved (fixed in 4.8.11-1) forky: resolved (fixe
debian
CVE-2025-21955P4MEDIUMCVSS 5.5fixed in linux 6.12.20-1 (forky)2025
CVE-2025-21955 [MEDIUM] CVE-2025-21955: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: prev... In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent connection release during oplock break notification ksmbd_work could be freed when after connection release. Increment r_count of ksmbd_conn to indicate that requests are not finished yet and to not release the connection. Scope: local bookworm: open bullseye: resolved forky: resolved
debian
CVE-2018-10087P4MEDIUMCVSS 5.5fixed in linux 4.13.4-1 (bookworm)2018
CVE-2018-10087 [MEDIUM] CVE-2018-10087: linux - The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when... The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service by triggering an attempted use of the -INT_MIN value. Scope: local bookworm: resolved (fixed in 4.13.4-1) bullseye: resolved (fixed in 4.13.4-1) forky: resolved (fixed in 4.13.4-1) sid
debian
CVE-2019-19462P4MEDIUMCVSS 5.5fixed in linux 5.6.14-2 (bookworm)2019
CVE-2019-19462 [MEDIUM] CVE-2019-19462: linux - relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local user... relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result. Scope: local bookworm: resolved (fixed in 5.6.14-2) bullseye: resolved (fixed in 5.6.14-2) forky: resolved (fixed in 5.6.14-2) sid: resolved (fixed in 5.6.14-2) trixie: resolved (fixed in 5.
debian
CVE-2019-20810P4MEDIUMCVSS 5.5fixed in linux 5.6.7-1 (bookworm)2019
CVE-2019-20810 [MEDIUM] CVE-2019-20810: linux - go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel bef... go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586. Scope: local bookworm: resolved (fixed in 5.6.7-1) bullseye: resolved (fixed in 5.6.7-1) forky: resolved (fixed in 5.6.7-1) sid: resolved (fixed in 5.6.7-1) trixie: resolved (fixed i
debian
CVE-2017-7542P4MEDIUMCVSS 5.5fixed in linux 4.12.6-1 (bookworm)2017
CVE-2017-7542 [MEDIUM] CVE-2017-7542: linux - The ip6_find_1stfragopt function in net/ipv6/output_core.c in the Linux kernel t... The ip6_find_1stfragopt function in net/ipv6/output_core.c in the Linux kernel through 4.12.3 allows local users to cause a denial of service (integer overflow and infinite loop) by leveraging the ability to open a raw socket. Scope: local bookworm: resolved (fixed in 4.12.6-1) bullseye: resolved (fixed in 4.12.6-1) forky: resolved (fixed in 4.12.6-1) sid: resolved (f
debian
CVE-2017-12193P4MEDIUMCVSS 5.5fixed in linux 4.13.13-1 (bookworm)2017
CVE-2017-12193 [MEDIUM] CVE-2017-12193: linux - The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the L... The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and panic) via a crafted application, as demonstrated by the keyring key type, and key addition and link creation operations. Scope: local bookworm: resol
debian
CVE-2019-20812P4MEDIUMCVSS 5.5fixed in linux 5.4.8-1 (bookworm)2019
CVE-2019-20812 [MEDIUM] CVE-2019-20812: linux - An issue was discovered in the Linux kernel before 5.4.7. The prb_calc_retire_bl... An issue was discovered in the Linux kernel before 5.4.7. The prb_calc_retire_blk_tmo() function in net/packet/af_packet.c can result in a denial of service (CPU consumption and soft lockup) in a certain failure case involving TPACKET_V3, aka CID-b43d1f9f7067. Scope: local bookworm: resolved (fixed in 5.4.8-1) bullseye: resolved (fixed in 5.4.8-1) forky: resolved (f
debian
CVE-2025-38120P4MEDIUMCVSS 5.5fixed in linux 6.1.147-1 (bookworm)2025
CVE-2025-38120 [MEDIUM] CVE-2025-38120: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ... In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo_avx2: fix initial map fill If the first field doesn't cover the entire start map, then we must zero out the remainder, else we leak those bits into the next match round map. The early fix was incomplete and did only fix up the generic C implementation. A followup patch adds
debian
CVE-2016-10147P4MEDIUMCVSS 5.5fixed in linux 4.8.15-1 (bookworm)2016
CVE-2016-10147 [MEDIUM] CVE-2016-10147: linux - crypto/mcryptd.c in the Linux kernel before 4.8.15 allows local users to cause a... crypto/mcryptd.c in the Linux kernel before 4.8.15 allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an AF_ALG socket with an incompatible algorithm, as demonstrated by mcryptd(md5). Scope: local bookworm: resolved (fixed in 4.8.15-1) bullseye: resolved (fixed in 4.8.15-1) forky: resolved (fixed in 4.8.15-1) sid: re
debian
CVE-2020-15393P4MEDIUMCVSS 5.5fixed in linux 5.7.10-1 (bookworm)2020
CVE-2020-15393 [MEDIUM] CVE-2020-15393: linux - In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/us... In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770. Scope: local bookworm: resolved (fixed in 5.7.10-1) bullseye: resolved (fixed in 5.7.10-1) forky: resolved (fixed in 5.7.10-1) sid: resolved (fixed in 5.7.10-1) trixie: resolved (fixed in 5.7.10-1)
debian
CVE-2017-18360P4MEDIUMCVSS 5.5fixed in linux 4.9.30-1 (bookworm)2017
CVE-2017-18360 [MEDIUM] CVE-2017-18360: linux - In change_port_settings in drivers/usb/serial/io_ti.c in the Linux kernel before... In change_port_settings in drivers/usb/serial/io_ti.c in the Linux kernel before 4.11.3, local users could cause a denial of service by division-by-zero in the serial device layer by trying to set very high baud rates. Scope: local bookworm: resolved (fixed in 4.9.30-1) bullseye: resolved (fixed in 4.9.30-1) forky: resolved (fixed in 4.9.30-1) sid: resolved (fixed i
debian
CVE-2014-3646P4MEDIUMCVSS 5.5fixed in linux 3.16.7-1 (bookworm)2014
CVE-2014-3646 [MEDIUM] CVE-2014-3646: linux - arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does ... arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. Scope: local bookworm: resolved (fixed in 3.16.7-1) bullseye: resolved (fixed in 3.16.7-1) forky: resolved (fixed in 3.16.7-1) sid: res
debian
CVE-2016-8646P4MEDIUMCVSS 5.5fixed in linux 4.4.2-1 (bookworm)2016
CVE-2016-8646 [MEDIUM] CVE-2016-8646: linux - The hash_accept function in crypto/algif_hash.c in the Linux kernel before 4.3.6... The hash_accept function in crypto/algif_hash.c in the Linux kernel before 4.3.6 allows local users to cause a denial of service (OOPS) by attempting to trigger use of in-kernel hash algorithms for a socket that has received zero bytes of data. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: resolved (fixed in 4.4.2-1) forky: resolved (fixed in 4.4.2-1) s
debian
CVE-2017-5577P4MEDIUMCVSS 5.5fixed in linux 4.9.6-1 (bookworm)2017
CVE-2017-5577 [MEDIUM] CVE-2017-5577: linux - The vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM d... The vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 does not set an errno value upon certain overflow detections, which allows local users to cause a denial of service (incorrect pointer dereference and OOPS) via inconsistent size values in a VC4_SUBMIT_CL ioctl call. Scope: local bookworm: resolved (f
debian
CVE-2016-9191P4MEDIUMCVSS 5.5fixed in linux 4.9.6-1 (bookworm)2016
CVE-2016-9191 [MEDIUM] CVE-2016-9191: linux - The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles ... The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a crafted application, as demonstrated by trinity. Scope: local bookworm: resolved (fixed in 4.9.6-1) bullseye: resolved (fixed in 4.9
debian
CVE-2017-8925P4LOWCVSS 5.5fixed in linux 4.9.16-1 (bookworm)2017
CVE-2017-8925 [MEDIUM] CVE-2017-8925: linux - The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel be... The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling. Scope: local bookworm: resolved (fixed in 4.9.16-1) bullseye: resolved (fixed in 4.9.16-1) forky: resolved (fixed in 4.9.16-1) sid: resolved (fixed in 4.9.16-1) trixie: r
debian
Debian Linux vulnerabilities | cvebase