cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 5 of 632
CVE-2018-11412P3MEDIUMCVSS 5.9PoCfixed in linux 4.17.3-1 (bookworm)2018
CVE-2018-11412 [MEDIUM] CVE-2018-11412: linux - In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inl... In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a dedicated inode. Scope: local bookworm: resolved (fixed in 4.17.3-1) bullseye: resolved (fixed in 4.17.3-1) forky: reso
debian
CVE-2019-14901P2CRITICALCVSS 9.8fixed in linux 5.4.13-1 (bookworm)2019
CVE-2019-14901 [CRITICAL] CVE-2019-14901: linux - A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x... A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with this vulnerability is with the availability of the system. If code execution occurs, the
debian
CVE-2017-18017P3CRITICALCVSS 9.8fixed in linux 4.11.6-1 (bookworm)2017
CVE-2017-18017 [CRITICAL] CVE-2017-18017: linux - The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kern... The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action. Scope: local bookworm: resolved (fixed in 4.11.6
debian
CVE-2017-16939P3HIGHCVSS 7.8PoCfixed in linux 4.13.13-1 (bookworm)2017
CVE-2017-16939 [HIGH] CVE-2017-16939: linux - The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel ... The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in conjunction with XFRM_MSG_GETPOLICY Netlink messages. Scope: local bookworm: resolved (fixed in 4.13.13-1) bullseye: resolved (fixed in 4.13.
debian
CVE-2016-1583P3HIGHCVSS 7.8PoCfixed in linux 4.6.2-1 (bookworm)2016
CVE-2016-1583 [HIGH] CVE-2016-1583: linux - The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kern... The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling. Scope: local bookworm: resolved (fixed in 4.6.2-1) bullseye: resolved (fixed in
debian
CVE-2018-18955P3HIGHCVSS 7.0PoCfixed in linux 4.18.20-1 (bookworm)2018
CVE-2018-18955 [HIGH] CVE-2018-18955: linux - In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/u... In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. Thi
debian
CVE-2017-1000364P3HIGHCVSS 7.4PoCfixed in linux 4.11.6-1 (bookworm)2017
CVE-2017-1000364 [HIGH] CVE-2017-1000364: linux - An issue was discovered in the size of the stack guard page on Linux, specifical... An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010). Scope: local bookworm: resolved (fixed in 4.11.6-1) bullseye: resolved (fi
debian
CVE-2016-3134P3HIGHCVSS 8.4PoCfixed in linux 4.5.1-1 (bookworm)2016
CVE-2016-3134 [HIGH] CVE-2016-3134: linux - The netfilter subsystem in the Linux kernel through 4.5.2 does not validate cert... The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call. Scope: local bookworm: resolved (fixed in 4.5.1-1) bullseye: resolved (fixed in 4.5.1-1) forky: resolved (fixed in 4.5.1-1) sid: res
debian
CVE-2017-1000371P3HIGHCVSS 7.8PoCfixed in linux 4.11.11-1 (bookworm)2017
CVE-2017-1000371 [HIGH] CVE-2017-1000371: linux - The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RL... The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then the stack will be grown down to 0x80000000, and as the PIE binary is mapped above 0x80000000 the minimum distance between the end of the PIE binary's read-write segment
debian
CVE-2017-1000370P3HIGHCVSS 7.8PoCfixed in linux 4.11.11-1 (bookworm)2017
CVE-2017-1000370 [HIGH] CVE-2017-1000370: linux - The offset2lib patch as used in the Linux Kernel contains a vulnerability that a... The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address 0x80000000 and the PIE binary is mapped above 0x40000000 nullifying the protection of the offset2lib patch. This affects Linux Kernel version 4.11.5 and earlier. This
debian
CVE-2018-5390P3HIGHCVSS 7.5fixed in linux 4.17.14-1 (bookworm)2018
CVE-2018-5390 [HIGH] CVE-2018-5390: linux - Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_col... Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. Scope: local bookworm: resolved (fixed in 4.17.14-1) bullseye: resolved (fixed in 4.17.14-1) forky: resolved (fixed in 4.17.14-1) sid: resolved (fixed in 4.17.14-1) trixie: resolved (
debian
CVE-2017-1000379P3HIGHCVSS 7.8PoCfixed in linux 4.11.6-1 (bookworm)2017
CVE-2017-1000379 [HIGH] CVE-2017-1000379: linux - The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE... The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the stack is mapped allowing attackers to more easily manipulate the stack. Linux Kernel version 4.11.5 is affected. Scope: local bookworm: resolved (fixed in 4.11.6-1) bullseye: resolved (fixed in 4.11.6-1) forky: resolved (fixed in 4.11.6-1) si
debian
CVE-2019-1999P3HIGHCVSS 7.8PoCfixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-1999 [HIGH] CVE-2019-1999: linux - In binder_alloc_free_page of binder_alloc.c, there is a possible double free due... In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-120025196. Scope: local bookworm: resolved (fixed in
debian
CVE-2017-10661P3HIGHCVSS 7.0PoCfixed in linux 4.9.30-1 (bookworm)2017
CVE-2017-10661 [HIGH] CVE-2017-10661: linux - Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local u... Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing. Scope: local bookworm: resolved (fixed in 4.9.30-1) bullseye: resolved (fixed in 4.9.30-1) forky: resolved (fix
debian
CVE-2017-13216P3LOWCVSS 7.8PoCfixed in linux 4.14.17-1 (bookworm)2017
CVE-2017-13216 [HIGH] CVE-2017-13216: linux - In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient... In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when accessing asma. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-6695409
debian
CVE-2016-10229P2CRITICALCVSS 9.8fixed in linux 4.5.1-1 (bookworm)2016
CVE-2016-10229 [CRITICAL] CVE-2016-10229: linux - udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrar... udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag. Scope: local bookworm: resolved (fixed in 4.5.1-1) bullseye: resolved (fixed in 4.5.1-1) forky: resolved (fixed in 4.5.1-1) sid: resolved (fixed in
debian
CVE-2026-23231P3HIGHCVSS 7.8PoCfixed in linux 6.18.14-1 (forky)2026
CVE-2026-23231 [HIGH] CVE-2026-23231: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ... In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table->chains via list_add_tail_rcu() (in nft_chain_add()) before registering hooks. If nf_tables_register_hook() then fails, the error path calls nft_chain_del() (list_del_rcu()) followed by n
debian
CVE-2023-5178P2HIGHCVSS 8.8fixed in linux 6.1.64-1 (bookworm)2023
CVE-2023-5178 [HIGH] CVE-2023-5178: linux - A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet... A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation. Scope: local bookworm: resolved (fixed
debian
CVE-2019-2025P3HIGHCVSS 7.8PoCfixed in linux 4.19.9-1 (bookworm)2019
CVE-2019-2025 [HIGH] CVE-2019-2025: linux - In binder_thread_read of binder.c, there is a possible use-after-free due to imp... In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-116855682References: Upstream kernel Scope: local bookworm: reso
debian
CVE-2016-7117P2CRITICALCVSS 9.8fixed in linux 4.5.2-1 (bookworm)2016
CVE-2016-7117 [CRITICAL] CVE-2016-7117: linux - Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in t... Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing. Scope: local bookworm: resolved (fixed in 4.5.2-1) bullseye: resolved (fixed in 4.5.2-1) forky: resolved (fixed in 4.5.2
debian
Debian Linux vulnerabilities | cvebase