cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 526 of 632
CVE-2026-23409P4UNKNOWNfixed in linux 6.1.164-1 (bookworm)2026
CVE-2026-23409 CVE-2026-23409: linux - In the Linux kernel, the following vulnerability has been resolved: apparmor: f... In the Linux kernel, the following vulnerability has been resolved: apparmor: fix differential encoding verification Differential encoding allows loops to be created if it is abused. To prevent this the unpack should verify that a diff-encode chain terminates. Unfortunately the differential encode verification had two bugs. 1. it conflated states that had gone through check
debian
CVE-2025-68323P4LOWfixed in linux 6.17.13-1 (forky)2025
CVE-2025-68323 [LOW] CVE-2025-68323: linux - In the Linux kernel, the following vulnerability has been resolved: usb: typec:... In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: fix use-after-free caused by uec->work The delayed work uec->work is scheduled in gaokun_ucsi_probe() but never properly canceled in gaokun_ucsi_remove(). This creates use-after-free scenarios where the ucsi and gaokun_ucsi structure are freed after ucsi_destroy() completes execution,
debian
CVE-2025-71064P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-71064 CVE-2025-71064: linux - In the Linux kernel, the following vulnerability has been resolved: net: hns3: ... In the Linux kernel, the following vulnerability has been resolved: net: hns3: using the num_tqps in the vf driver to apply for resources Currently, hdev->htqp is allocated using hdev->num_tqps, and kinfo->tqp is allocated using kinfo->num_tqps. However, kinfo->num_tqps is set to min(new_tqps, hdev->num_tqps); Therefore, kinfo->num_tqps may be smaller than hdev->num_tqps, wh
debian
CVE-2026-23046P4LOWfixed in linux 6.18.8-1 (forky)2026
CVE-2026-23046 [LOW] CVE-2026-23046: linux - In the Linux kernel, the following vulnerability has been resolved: virtio_net:... In the Linux kernel, the following vulnerability has been resolved: virtio_net: fix device mismatch in devm_kzalloc/devm_kfree Initial rss_hdr allocation uses virtio_device->device, but virtnet_set_queues() frees using net_device->device. This device mismatch causing below devres warning [ 3788.514041] ------------[ cut here ]------------ [ 3788.514044] WARNING: driver
debian
CVE-2025-68199P4LOWfixed in linux 6.17.9-1 (forky)2025
CVE-2025-68199 [LOW] CVE-2025-68199: linux - In the Linux kernel, the following vulnerability has been resolved: codetag: de... In the Linux kernel, the following vulnerability has been resolved: codetag: debug: handle existing CODETAG_EMPTY in mark_objexts_empty for slabobj_ext When alloc_slab_obj_exts() fails and then later succeeds in allocating a slab extension vector, it calls handle_failed_objexts_alloc() to mark all objects in the vector as empty. As a result all objects in this slab (sl
debian
CVE-2025-68210P4LOWfixed in linux 6.17.9-1 (forky)2025
CVE-2025-68210 [LOW] CVE-2025-68210: linux - In the Linux kernel, the following vulnerability has been resolved: erofs: avoi... In the Linux kernel, the following vulnerability has been resolved: erofs: avoid infinite loop due to incomplete zstd-compressed data Currently, the decompression logic incorrectly spins if compressed data is truncated in crafted (deliberately corrupted) images. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 6.17.9-1) sid: resolved (fixed
debian
CVE-2025-40357P4LOWfixed in linux 6.17.6-1 (forky)2025
CVE-2025-40357 [LOW] CVE-2025-40357: linux - In the Linux kernel, the following vulnerability has been resolved: net/smc: fi... In the Linux kernel, the following vulnerability has been resolved: net/smc: fix general protection fault in __smc_diag_dump The syzbot report a crash: Oops: general protection fault, probably for non-canonical address 0xfbd5a5d5a0000003: 0000 [#1] SMP KASAN NOPTI KASAN: maybe wild-memory-access in range [0xdead4ead00000018-0xdead4ead0000001f] CPU: 1 UID: 0 PID: 6949 C
debian
CVE-2025-68188P4UNKNOWNfixed in linux 6.17.8-1 (forky)2025
CVE-2025-68188 CVE-2025-68188: linux - In the Linux kernel, the following vulnerability has been resolved: tcp: use ds... In the Linux kernel, the following vulnerability has been resolved: tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check() Use RCU to avoid a pair of atomic operations and a potential UAF on dst_dev()->flags. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 6.17.8-1) sid: resolved (fixed in 6.17.8-1) trixie: resolved (fixed in 6.12.63-1)
debian
CVE-2026-23419P4UNKNOWNfixed in linux 6.19.8-1 (forky)2026
CVE-2026-23419 CVE-2026-23419: linux - In the Linux kernel, the following vulnerability has been resolved: net/rds: Fi... In the Linux kernel, the following vulnerability has been resolved: net/rds: Fix circular locking dependency in rds_tcp_tune syzbot reported a circular locking dependency in rds_tcp_tune() where sk_net_refcnt_upgrade() is called while holding the socket lock: ====================================================== WARNING: possible circular locking dependency detected =======
debian
CVE-2025-68325P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-68325 CVE-2025-68325: linux - In the Linux kernel, the following vulnerability has been resolved: net/sched: ... In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop In cake_drop(), qdisc_tree_reduce_backlog() is used to update the qlen and backlog of the qdisc hierarchy. Its caller, cake_enqueue(), assumes that the parent qdisc will enqueue the current packet. However, this assumption breaks when cake_enqueu
debian
CVE-2023-54246P4UNKNOWNfixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-54246 CVE-2023-54246: linux - In the Linux kernel, the following vulnerability has been resolved: rcuscale: M... In the Linux kernel, the following vulnerability has been resolved: rcuscale: Move rcu_scale_writer() schedule_timeout_uninterruptible() to _idle() The rcuscale.holdoff module parameter can be used to delay the start of rcu_scale_writer() kthread. However, the hung-task timeout will trigger when the timeout specified by rcuscale.holdoff is greater than hung_task_timeout_secs
debian
CVE-2023-54224P4UNKNOWNfixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-54224 CVE-2023-54224: linux - In the Linux kernel, the following vulnerability has been resolved: btrfs: fix ... In the Linux kernel, the following vulnerability has been resolved: btrfs: fix lockdep splat and potential deadlock after failure running delayed items When running delayed items we are holding a delayed node's mutex and then we will attempt to modify a subvolume btree to insert/update/delete the delayed items. However if have an error during the insertions for example, btrf
debian
CVE-2023-54025P4UNKNOWNfixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-54025 CVE-2023-54025: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: ... In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: Do not configure WoWlan in shutdown hook if not enabled In case WoWlan was never configured during the operation of the system, the hw->wiphy->wowlan_config will be NULL. rsi_config_wowlan() checks whether wowlan_config is non-NULL and if it is not, then WARNs about it. The warning is valid, as du
debian
CVE-2023-53991P4UNKNOWNfixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-53991 CVE-2023-53991: linux - In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu... In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Disallow unallocated resources to be returned In the event that the topology requests resources that have not been created by the system (because they are typically not represented in dpu_mdss_cfg ^1), the resource(s) in global_state (in this case DSC blocks, until their allocation/assignment is
debian
CVE-2022-50710P4UNKNOWNfixed in linux 6.0.3-1 (bookworm)2022
CVE-2022-50710 CVE-2022-50710: linux - In the Linux kernel, the following vulnerability has been resolved: ice: set tx... In the Linux kernel, the following vulnerability has been resolved: ice: set tx_tstamps when creating new Tx rings via ethtool When the user changes the number of queues via ethtool, the driver allocates new rings. This allocation did not initialize tx_tstamps. This results in the tx_tstamps field being zero (due to kcalloc allocation), and would result in a NULL pointer der
debian
CVE-2023-54113P4UNKNOWNfixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-54113 CVE-2023-54113: linux - In the Linux kernel, the following vulnerability has been resolved: rcu: dump v... In the Linux kernel, the following vulnerability has been resolved: rcu: dump vmalloc memory info safely Currently, for double invoke call_rcu(), will dump rcu_head objects memory info, if the objects is not allocated from the slab allocator, the vmalloc_dump_obj() will be invoke and the vmap_area_lock spinlock need to be held, since the call_rcu() can be invoked in interrup
debian
CVE-2023-54066P4UNKNOWNfixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-54066 CVE-2023-54066: linux - In the Linux kernel, the following vulnerability has been resolved: media: dvb-... In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: gl861: Fix null-ptr-deref in gl861_i2c_master_xfer In gl861_i2c_master_xfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious data finally reach gl861_i2c_master_xfer. If accessing msg[i].buf[0] without sanity
debian
CVE-2023-54155P4UNKNOWNfixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-54155 CVE-2023-54155: linux - In the Linux kernel, the following vulnerability has been resolved: net: core: ... In the Linux kernel, the following vulnerability has been resolved: net: core: remove unnecessary frame_sz check in bpf_xdp_adjust_tail() Syzkaller reported the following issue: ======================================= Too BIG xdp->frame_sz = 131072 WARNING: CPU: 0 PID: 5020 at net/core/filter.c:4121 ____bpf_xdp_adjust_tail net/core/filter.c:4121 [inline] WARNING: CPU: 0 PID:
debian
CVE-2023-54235P4UNKNOWNfixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-54235 CVE-2023-54235: linux - In the Linux kernel, the following vulnerability has been resolved: PCI/DOE: Fi... In the Linux kernel, the following vulnerability has been resolved: PCI/DOE: Fix destroy_work_on_stack() race The following debug object splat was observed in testing: ODEBUG: free active (active state 0) object: 0000000097d23782 object type: work_struct hint: doe_statemachine_work+0x0/0x510 WARNING: CPU: 1 PID: 71 at lib/debugobjects.c:514 debug_print_object+0x7d/0xb0 ... W
debian
CVE-2023-54196P4UNKNOWNfixed in linux 6.1.82-1 (bookworm)2023
CVE-2023-54196 CVE-2023-54196: linux - In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: F... In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix NULL pointer dereference in 'ni_write_inode' Syzbot found the following issue: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000016 Mem abort info: ESR = 0x0000000096000006 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x06:
debian
Debian Linux vulnerabilities | cvebase