cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 463 of 632
CVE-2017-14340P4MEDIUMCVSS 5.5fixed in linux 4.12.13-1 (bookworm)2017
CVE-2017-14340 [MEDIUM] CVE-2017-14340: linux - The XFS_IS_REALTIME_INODE macro in fs/xfs/xfs_linux.h in the Linux kernel before... The XFS_IS_REALTIME_INODE macro in fs/xfs/xfs_linux.h in the Linux kernel before 4.13.2 does not verify that a filesystem has a realtime device, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via vectors related to setting an RHINHERIT flag on a directory. Scope: local bookworm: resolved (fixed in 4.12.13-1) bullseye: resol
debian
CVE-2019-9857P4MEDIUMCVSS 5.5fixed in linux 4.19.37-1 (bookworm)2019
CVE-2019-9857 [MEDIUM] CVE-2019-9857: linux - In the Linux kernel through 5.0.2, the function inotify_update_existing_watch() ... In the Linux kernel through 5.0.2, the function inotify_update_existing_watch() in fs/notify/inotify/inotify_user.c neglects to call fsnotify_put_mark() with IN_MASK_CREATE after fsnotify_find_mark(), which will cause a memory leak (aka refcount leak). Finally, this will cause a denial of service. Scope: local bookworm: resolved (fixed in 4.19.37-1) bullseye: resolved
debian
CVE-2017-18241P4MEDIUMCVSS 5.5fixed in linux 4.13.4-1 (bookworm)2017
CVE-2017-18241 [MEDIUM] CVE-2017-18241: linux - fs/f2fs/segment.c in the Linux kernel before 4.13 allows local users to cause a ... fs/f2fs/segment.c in the Linux kernel before 4.13 allows local users to cause a denial of service (NULL pointer dereference and panic) by using a noflush_merge option that triggers a NULL value for a flush_cmd_control data structure. Scope: local bookworm: resolved (fixed in 4.13.4-1) bullseye: resolved (fixed in 4.13.4-1) forky: resolved (fixed in 4.13.4-1) sid: re
debian
CVE-2024-35834P4LOWCVSS 5.5fixed in linux 6.7.7-1 (forky)2024
CVE-2024-35834 [MEDIUM] CVE-2024-35834: linux - In the Linux kernel, the following vulnerability has been resolved: xsk: recycl... In the Linux kernel, the following vulnerability has been resolved: xsk: recycle buffer in case Rx queue was full Add missing xsk_buff_free() call when __xsk_rcv_zc() failed to produce descriptor to XSK Rx queue. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 6.7.7-1) sid: resolved (fixed in 6.7.7-1) trixie: resolved (fixed in 6.7.7-1)
debian
CVE-2024-56632P4LOWCVSS 5.5fixed in linux 6.12.5-1 (forky)2024
CVE-2024-56632 [MEDIUM] CVE-2024-56632: linux - In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: f... In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix the memleak while create new ctrl failed Now while we create new ctrl failed, we have not free the tagset occupied by admin_q, here try to fix it. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 6.12.5-1) sid: resolved (fixed in 6.12.5-1) trixie: resolved (
debian
CVE-2019-19055P4LOWCVSS 5.5fixed in linux 5.4.6-1 (bookworm)2019
CVE-2019-19055 [MEDIUM] CVE-2019-19055: linux - A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/... A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering nl80211hdr_put() failures, aka CID-1399c59fa929. NOTE: third parties dispute the relevance of this because it occurs on a code path where a successful allocation
debian
CVE-2017-9242P4MEDIUMCVSS 5.5fixed in linux 4.9.30-1 (bookworm)2017
CVE-2017-9242 [MEDIUM] CVE-2017-9242: linux - The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel thro... The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking whether an overwrite of an skb data structure may occur, which allows local users to cause a denial of service (system crash) via crafted system calls. Scope: local bookworm: resolved (fixed in 4.9.30-1) bullseye: resolved (fixed in 4.9.30-1) forky: resol
debian
CVE-2021-4149P4MEDIUMCVSS 5.5fixed in linux 5.14.16-1 (bookworm)2021
CVE-2021-4149 [MEDIUM] CVE-2021-4149: linux - A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the... A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem. Scope: local bookworm: resolved (fixed in 5.14.16-1) bullseye: open forky: resolved (fixed in 5.14.16-1) sid: resolved (fixed
debian
CVE-2017-15121P4MEDIUMCVSS 5.5fixed in linux 3.11.5-1 (bookworm)2017
CVE-2017-15121 [MEDIUM] CVE-2017-15121: linux - A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and cras... A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary. Scope: local bookworm: resolved (fixed in 3.11.5-1) bullseye: resolved (fixed in 3.11.5-1) forky: resolved (fixed in 3.11.5-1) sid: resolved (fixed in 3.11.5-1) trixie: resolved (fixed in
debian
CVE-2017-8071P4MEDIUMCVSS 5.5fixed in linux 4.9.10-1 (bookworm)2017
CVE-2017-8071 [MEDIUM] CVE-2017-8071: linux - drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 uses a spinlock ... drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 uses a spinlock without considering that sleeping is possible in a USB HID request callback, which allows local users to cause a denial of service (deadlock) via unspecified vectors. Scope: local bookworm: resolved (fixed in 4.9.10-1) bullseye: resolved (fixed in 4.9.10-1) forky: resolved (fixed in 4.9.10
debian
CVE-2024-35998P4MEDIUMCVSS 5.5fixed in linux 6.1.90-1 (bookworm)2024
CVE-2024-35998 [MEDIUM] CVE-2024-35998: linux - In the Linux kernel, the following vulnerability has been resolved: smb3: fix l... In the Linux kernel, the following vulnerability has been resolved: smb3: fix lock ordering potential deadlock in cifs_sync_mid_result Coverity spotted that the cifs_sync_mid_result function could deadlock "Thread deadlock (ORDER_REVERSAL) lock_order: Calling spin_lock acquires lock TCP_Server_Info.srv_lock while holding lock TCP_Server_Info.mid_lock" Addresses-Cove
debian
CVE-2024-56749P4LOWCVSS 5.5fixed in linux 6.12.3-1 (forky)2024
CVE-2024-56749 [MEDIUM] CVE-2024-56749: linux - In the Linux kernel, the following vulnerability has been resolved: dlm: fix dl... In the Linux kernel, the following vulnerability has been resolved: dlm: fix dlm_recover_members refcount on error If dlm_recover_members() fails we don't drop the references of the previous created root_list that holds and keep all rsbs alive during the recovery. It might be not an unlikely event because ping_members() could run into an -EINTR if another recovery p
debian
CVE-2014-8171P4MEDIUMCVSS 5.5fixed in linux 3.12.6-1 (bookworm)2014
CVE-2014-8171 [MEDIUM] CVE-2014-8171: linux - The memory resource controller (aka memcg) in the Linux kernel allows local user... The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup. Scope: local bookworm: resolved (fixed in 3.12.6-1) bullseye: resolved (fixed in 3.12.6-1) forky: resolved (fixed in 3.12.6-1) sid: resolved (fixed in 3.12.6-1) trixie: resolved (fixed i
debian
CVE-2022-27950P4MEDIUMCVSS 5.5fixed in linux 5.16.11-1 (bookworm)2022
CVE-2022-27950 [MEDIUM] CVE-2022-27950: linux - In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exist... In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error condition. Scope: local bookworm: resolved (fixed in 5.16.11-1) bullseye: resolved forky: resolved (fixed in 5.16.11-1) sid: resolved (fixed in 5.16.11-1) trixie: resolved (fixed in 5.16.11-1)
debian
CVE-2017-15116P4MEDIUMCVSS 5.5fixed in linux 4.2.1-1 (bookworm)2017
CVE-2017-15116 [MEDIUM] CVE-2017-15116: linux - The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows ... The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference). Scope: local bookworm: resolved (fixed in 4.2.1-1) bullseye: resolved (fixed in 4.2.1-1) forky: resolved (fixed in 4.2.1-1) sid: resolved (fixed in 4.2.1-1) trixie: resolved (fixed in 4.2.1-1)
debian
CVE-2017-6353P4MEDIUMCVSS 5.5fixed in linux 4.9.13-1 (bookworm)2017
CVE-2017-6353 [MEDIUM] CVE-2017-6353: linux - net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict ... net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986. Scope: local bookworm: resolved
debian
CVE-2021-38203P4MEDIUMCVSS 5.5fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-38203 [MEDIUM] CVE-2021-38203: linux - btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of se... btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info. Scope: local bookworm: resolved (fixed in 5.14.6-1) bullseye: resolved forky: resolved (fixed in 5.14.6-1) sid: resolved (fixed in 5.1
debian
CVE-2022-50059P4MEDIUMCVSS 5.5fixed in linux 6.0.2-1 (bookworm)2022
CVE-2022-50059 [MEDIUM] CVE-2022-50059: linux - In the Linux kernel, the following vulnerability has been resolved: ceph: don't... In the Linux kernel, the following vulnerability has been resolved: ceph: don't leak snap_rwsem in handle_cap_grant When handle_cap_grant is called on an IMPORT op, then the snap_rwsem is held and the function is expected to release it before returning. It currently fails to do that in all cases which could lead to a deadlock. Scope: local bookworm: resolved (fixed
debian
CVE-2016-8630P4MEDIUMCVSS 5.5fixed in linux 4.8.7-1 (bookworm)2016
CVE-2016-8630 [MEDIUM] CVE-2016-8630: linux - The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel befor... The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel before 4.8.7, when KVM is enabled, allows local users to cause a denial of service (host OS crash) via a certain use of a ModR/M byte in an undefined instruction. Scope: local bookworm: resolved (fixed in 4.8.7-1) bullseye: resolved (fixed in 4.8.7-1) forky: resolved (fixed in 4.8.7-1) sid: res
debian
CVE-2024-44988P4MEDIUMCVSS 5.5fixed in linux 6.1.112-1 (bookworm)2024
CVE-2024-44988 [MEDIUM] CVE-2024-44988: linux - In the Linux kernel, the following vulnerability has been resolved: net: dsa: m... In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: Fix out-of-bound access If an ATU violation was caused by a CPU Load operation, the SPID could be larger than DSA_MAX_PORTS (the size of mv88e6xxx_chip.ports[] array). Scope: local bookworm: resolved (fixed in 6.1.112-1) bullseye: resolved (fixed in 5.10.226-1) forky: resolved (
debian
Debian Linux vulnerabilities | cvebase