Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 463 of 632
CVE-2017-14340P4MEDIUMCVSS 5.5fixed in linux 4.12.13-1 (bookworm)2017
CVE-2017-14340 [MEDIUM] CVE-2017-14340: linux - The XFS_IS_REALTIME_INODE macro in fs/xfs/xfs_linux.h in the Linux kernel before...
The XFS_IS_REALTIME_INODE macro in fs/xfs/xfs_linux.h in the Linux kernel before 4.13.2 does not verify that a filesystem has a realtime device, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via vectors related to setting an RHINHERIT flag on a directory.
Scope: local
bookworm: resolved (fixed in 4.12.13-1)
bullseye: resol
debian
CVE-2019-9857P4MEDIUMCVSS 5.5fixed in linux 4.19.37-1 (bookworm)2019
CVE-2019-9857 [MEDIUM] CVE-2019-9857: linux - In the Linux kernel through 5.0.2, the function inotify_update_existing_watch() ...
In the Linux kernel through 5.0.2, the function inotify_update_existing_watch() in fs/notify/inotify/inotify_user.c neglects to call fsnotify_put_mark() with IN_MASK_CREATE after fsnotify_find_mark(), which will cause a memory leak (aka refcount leak). Finally, this will cause a denial of service.
Scope: local
bookworm: resolved (fixed in 4.19.37-1)
bullseye: resolved
debian
CVE-2017-18241P4MEDIUMCVSS 5.5fixed in linux 4.13.4-1 (bookworm)2017
CVE-2017-18241 [MEDIUM] CVE-2017-18241: linux - fs/f2fs/segment.c in the Linux kernel before 4.13 allows local users to cause a ...
fs/f2fs/segment.c in the Linux kernel before 4.13 allows local users to cause a denial of service (NULL pointer dereference and panic) by using a noflush_merge option that triggers a NULL value for a flush_cmd_control data structure.
Scope: local
bookworm: resolved (fixed in 4.13.4-1)
bullseye: resolved (fixed in 4.13.4-1)
forky: resolved (fixed in 4.13.4-1)
sid: re
debian
CVE-2024-35834P4LOWCVSS 5.5fixed in linux 6.7.7-1 (forky)2024
CVE-2024-35834 [MEDIUM] CVE-2024-35834: linux - In the Linux kernel, the following vulnerability has been resolved: xsk: recycl...
In the Linux kernel, the following vulnerability has been resolved: xsk: recycle buffer in case Rx queue was full Add missing xsk_buff_free() call when __xsk_rcv_zc() failed to produce descriptor to XSK Rx queue.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.7.7-1)
sid: resolved (fixed in 6.7.7-1)
trixie: resolved (fixed in 6.7.7-1)
debian
CVE-2024-56632P4LOWCVSS 5.5fixed in linux 6.12.5-1 (forky)2024
CVE-2024-56632 [MEDIUM] CVE-2024-56632: linux - In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: f...
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix the memleak while create new ctrl failed Now while we create new ctrl failed, we have not free the tagset occupied by admin_q, here try to fix it.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.12.5-1)
sid: resolved (fixed in 6.12.5-1)
trixie: resolved (
debian
CVE-2019-19055P4LOWCVSS 5.5fixed in linux 5.4.6-1 (bookworm)2019
CVE-2019-19055 [MEDIUM] CVE-2019-19055: linux - A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/...
A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering nl80211hdr_put() failures, aka CID-1399c59fa929. NOTE: third parties dispute the relevance of this because it occurs on a code path where a successful allocation
debian
CVE-2017-9242P4MEDIUMCVSS 5.5fixed in linux 4.9.30-1 (bookworm)2017
CVE-2017-9242 [MEDIUM] CVE-2017-9242: linux - The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel thro...
The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking whether an overwrite of an skb data structure may occur, which allows local users to cause a denial of service (system crash) via crafted system calls.
Scope: local
bookworm: resolved (fixed in 4.9.30-1)
bullseye: resolved (fixed in 4.9.30-1)
forky: resol
debian
CVE-2021-4149P4MEDIUMCVSS 5.5fixed in linux 5.14.16-1 (bookworm)2021
CVE-2021-4149 [MEDIUM] CVE-2021-4149: linux - A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the...
A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem.
Scope: local
bookworm: resolved (fixed in 5.14.16-1)
bullseye: open
forky: resolved (fixed in 5.14.16-1)
sid: resolved (fixed
debian
CVE-2017-15121P4MEDIUMCVSS 5.5fixed in linux 3.11.5-1 (bookworm)2017
CVE-2017-15121 [MEDIUM] CVE-2017-15121: linux - A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and cras...
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.
Scope: local
bookworm: resolved (fixed in 3.11.5-1)
bullseye: resolved (fixed in 3.11.5-1)
forky: resolved (fixed in 3.11.5-1)
sid: resolved (fixed in 3.11.5-1)
trixie: resolved (fixed in
debian
CVE-2017-8071P4MEDIUMCVSS 5.5fixed in linux 4.9.10-1 (bookworm)2017
CVE-2017-8071 [MEDIUM] CVE-2017-8071: linux - drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 uses a spinlock ...
drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 uses a spinlock without considering that sleeping is possible in a USB HID request callback, which allows local users to cause a denial of service (deadlock) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.9.10-1)
bullseye: resolved (fixed in 4.9.10-1)
forky: resolved (fixed in 4.9.10
debian
CVE-2024-35998P4MEDIUMCVSS 5.5fixed in linux 6.1.90-1 (bookworm)2024
CVE-2024-35998 [MEDIUM] CVE-2024-35998: linux - In the Linux kernel, the following vulnerability has been resolved: smb3: fix l...
In the Linux kernel, the following vulnerability has been resolved: smb3: fix lock ordering potential deadlock in cifs_sync_mid_result Coverity spotted that the cifs_sync_mid_result function could deadlock "Thread deadlock (ORDER_REVERSAL) lock_order: Calling spin_lock acquires lock TCP_Server_Info.srv_lock while holding lock TCP_Server_Info.mid_lock" Addresses-Cove
debian
CVE-2024-56749P4LOWCVSS 5.5fixed in linux 6.12.3-1 (forky)2024
CVE-2024-56749 [MEDIUM] CVE-2024-56749: linux - In the Linux kernel, the following vulnerability has been resolved: dlm: fix dl...
In the Linux kernel, the following vulnerability has been resolved: dlm: fix dlm_recover_members refcount on error If dlm_recover_members() fails we don't drop the references of the previous created root_list that holds and keep all rsbs alive during the recovery. It might be not an unlikely event because ping_members() could run into an -EINTR if another recovery p
debian
CVE-2014-8171P4MEDIUMCVSS 5.5fixed in linux 3.12.6-1 (bookworm)2014
CVE-2014-8171 [MEDIUM] CVE-2014-8171: linux - The memory resource controller (aka memcg) in the Linux kernel allows local user...
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.
Scope: local
bookworm: resolved (fixed in 3.12.6-1)
bullseye: resolved (fixed in 3.12.6-1)
forky: resolved (fixed in 3.12.6-1)
sid: resolved (fixed in 3.12.6-1)
trixie: resolved (fixed i
debian
CVE-2022-27950P4MEDIUMCVSS 5.5fixed in linux 5.16.11-1 (bookworm)2022
CVE-2022-27950 [MEDIUM] CVE-2022-27950: linux - In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exist...
In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error condition.
Scope: local
bookworm: resolved (fixed in 5.16.11-1)
bullseye: resolved
forky: resolved (fixed in 5.16.11-1)
sid: resolved (fixed in 5.16.11-1)
trixie: resolved (fixed in 5.16.11-1)
debian
CVE-2017-15116P4MEDIUMCVSS 5.5fixed in linux 4.2.1-1 (bookworm)2017
CVE-2017-15116 [MEDIUM] CVE-2017-15116: linux - The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows ...
The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).
Scope: local
bookworm: resolved (fixed in 4.2.1-1)
bullseye: resolved (fixed in 4.2.1-1)
forky: resolved (fixed in 4.2.1-1)
sid: resolved (fixed in 4.2.1-1)
trixie: resolved (fixed in 4.2.1-1)
debian
CVE-2017-6353P4MEDIUMCVSS 5.5fixed in linux 4.9.13-1 (bookworm)2017
CVE-2017-6353 [MEDIUM] CVE-2017-6353: linux - net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict ...
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.
Scope: local
bookworm: resolved
debian
CVE-2021-38203P4MEDIUMCVSS 5.5fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-38203 [MEDIUM] CVE-2021-38203: linux - btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of se...
btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.1
debian
CVE-2022-50059P4MEDIUMCVSS 5.5fixed in linux 6.0.2-1 (bookworm)2022
CVE-2022-50059 [MEDIUM] CVE-2022-50059: linux - In the Linux kernel, the following vulnerability has been resolved: ceph: don't...
In the Linux kernel, the following vulnerability has been resolved: ceph: don't leak snap_rwsem in handle_cap_grant When handle_cap_grant is called on an IMPORT op, then the snap_rwsem is held and the function is expected to release it before returning. It currently fails to do that in all cases which could lead to a deadlock.
Scope: local
bookworm: resolved (fixed
debian
CVE-2016-8630P4MEDIUMCVSS 5.5fixed in linux 4.8.7-1 (bookworm)2016
CVE-2016-8630 [MEDIUM] CVE-2016-8630: linux - The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel befor...
The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel before 4.8.7, when KVM is enabled, allows local users to cause a denial of service (host OS crash) via a certain use of a ModR/M byte in an undefined instruction.
Scope: local
bookworm: resolved (fixed in 4.8.7-1)
bullseye: resolved (fixed in 4.8.7-1)
forky: resolved (fixed in 4.8.7-1)
sid: res
debian
CVE-2024-44988P4MEDIUMCVSS 5.5fixed in linux 6.1.112-1 (bookworm)2024
CVE-2024-44988 [MEDIUM] CVE-2024-44988: linux - In the Linux kernel, the following vulnerability has been resolved: net: dsa: m...
In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: Fix out-of-bound access If an ATU violation was caused by a CPU Load operation, the SPID could be larger than DSA_MAX_PORTS (the size of mv88e6xxx_chip.ports[] array).
Scope: local
bookworm: resolved (fixed in 6.1.112-1)
bullseye: resolved (fixed in 5.10.226-1)
forky: resolved (
debian