cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 534 of 632
CVE-2017-5551P4MEDIUMCVSS 4.4fixed in linux 4.9.6-1 (bookworm)2017
CVE-2017-5551 [MEDIUM] CVE-2017-5551: linux - The simple_set_acl function in fs/posix_acl.c in the Linux kernel before 4.9.6 p... The simple_set_acl function in fs/posix_acl.c in the Linux kernel before 4.9.6 preserves the setgid bit during a setxattr call involving a tmpfs filesystem, which allows local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016
debian
CVE-2013-6378P4LOWCVSS 4.4fixed in linux 3.11.10-1 (bookworm)2013
CVE-2013-6378 [MEDIUM] CVE-2013-6378: linux - The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the... The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service (OOPS) by leveraging root privileges for a zero-length write operation. Scope: local bookworm: resolved (fixed in 3.11.10-1) bullseye: resolved (fixed in 3.11.10-1) forky: resolved (fixed in 3.11.10-1) sid: resolv
debian
CVE-2020-10773P4MEDIUMCVSS 4.4fixed in linux 5.3.9-1 (bookworm)2020
CVE-2020-10773 [MEDIUM] CVE-2020-10773: linux - A stack information leak flaw was found in s390/s390x in the Linux kernel’s memo... A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys/vm/cmm_timeout file. This flaw allows a local user to see the kernel data. Scope: local bookworm: resolved (fixed in 5.3.9-1) bullseye: resolved (fixed in 5.3.9-1) forky: resolved (fixed in 5.3.9-1) sid: resolved (fix
debian
CVE-2015-2922P4LOWCVSS 3.3fixed in linux 3.16.7-ckt9-1 (bookworm)2015
CVE-2015-2922 [LOW] CVE-2015-2922: linux - The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discover... The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message. Scope: local bookworm: resolved (fixed in 3.16.7-ckt9-1) bullseye: resolved (fixed
debian
CVE-2013-0310P4MEDIUMCVSS 6.6fixed in linux 3.2.29-1 (bookworm)2013
CVE-2013-0310 [MEDIUM] CVE-2013-0310: linux - The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel befo... The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsockopt system call. Scope: local bookworm: resolved (fixed in 3.2.29-1) bullseye: resolved (fixed in 3.2.29-1) fo
debian
CVE-2013-0313P4MEDIUMCVSS 6.2fixed in linux 3.2.39-1 (bookworm)2013
CVE-2013-0313 [MEDIUM] CVE-2013-0313: linux - The evm_update_evmxattr function in security/integrity/evm/evm_crypto.c in the L... The evm_update_evmxattr function in security/integrity/evm/evm_crypto.c in the Linux kernel before 3.7.5, when the Extended Verification Module (EVM) is enabled, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an attempted removexattr operation on an inode of a sockfs filesystem.
debian
CVE-2021-47147P4MEDIUMCVSS 6.2fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-47147 [MEDIUM] CVE-2021-47147: linux - In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: F... In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: Fix a resource leak in an error handling path If an error occurs after a successful 'pci_ioremap_bar()' call, it must be undone by a corresponding 'pci_iounmap()' call, as already done in the remove function. Scope: local bookworm: resolved (fixed in 5.14.6-1) bullseye: resolved forky: res
debian
CVE-2022-3646P4LOWCVSS 3.1fixed in linux 6.0.2-1 (bookworm)2022
CVE-2022-3646 [LOW] CVE-2022-3646: linux - A vulnerability, which was classified as problematic, has been found in Linux Ke... A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function nilfs_attach_log_writer of the file fs/nilfs2/segment.c of the component BPF. The manipulation leads to memory leak. The attack may be initiated remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211961 was assigned to this
debian
CVE-2015-8953P4MEDIUMCVSS 5.5fixed in linux 4.2.6-1 (bookworm)2015
CVE-2015-8953 [MEDIUM] CVE-2015-8953: linux - fs/overlayfs/copy_up.c in the Linux kernel before 4.2.6 uses an incorrect cleanu... fs/overlayfs/copy_up.c in the Linux kernel before 4.2.6 uses an incorrect cleanup code path, which allows local users to cause a denial of service (dentry reference leak) via filesystem operations on a large file in a lower overlayfs layer. Scope: local bookworm: resolved (fixed in 4.2.6-1) bullseye: resolved (fixed in 4.2.6-1) forky: resolved (fixed in 4.2.6-1) sid:
debian
CVE-2019-19047P4MEDIUMCVSS 5.5fixed in linux 5.3.15-1 (bookworm)2019
CVE-2019-19047 [MEDIUM] CVE-2019-19047: linux - A memory leak in the mlx5_fw_fatal_reporter_dump() function in drivers/net/ether... A memory leak in the mlx5_fw_fatal_reporter_dump() function in drivers/net/ethernet/mellanox/mlx5/core/health.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mlx5_crdump_collect() failures, aka CID-c7ed6d0183d5. Scope: local bookworm: resolved (fixed in 5.3.15-1) bullseye: resolved (fixed in 5.3.15
debian
CVE-2017-15299P4MEDIUMCVSS 5.5fixed in linux 4.13.10-1 (bookworm)2017
CVE-2017-15299 [MEDIUM] CVE-2017-15299: linux - The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key ... The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is uninstantiated, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted system call. Scope: local bookworm: resolved (fixed in 4.13.10-1) bullseye: resol
debian
CVE-2024-53073P4LOWCVSS 5.5fixed in linux 6.11.7-1 (forky)2024
CVE-2024-53073 [MEDIUM] CVE-2024-53073: linux - In the Linux kernel, the following vulnerability has been resolved: NFSD: Never... In the Linux kernel, the following vulnerability has been resolved: NFSD: Never decrement pending_async_copies on error The error flow in nfsd4_copy() calls cleanup_async_copy(), which already decrements nn->pending_async_copies. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 6.11.7-1) sid: resolved (fixed in 6.11.7-1) trixie: resolved
debian
CVE-2021-47519P4MEDIUMCVSS 5.5fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-47519 [MEDIUM] CVE-2021-47519: linux - In the Linux kernel, the following vulnerability has been resolved: can: m_can:... In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_read_fifo: fix memory leak in error branch In m_can_read_fifo(), if the second call to m_can_fifo_read() fails, the function jump to the out_fail label and returns without calling m_can_receive_skb(). This means that the skb previously allocated by alloc_can_skb() is not freed. In
debian
CVE-2024-36945P4MEDIUMCVSS 5.5fixed in linux 6.1.94-1 (bookworm)2024
CVE-2024-36945 [MEDIUM] CVE-2024-36945: linux - In the Linux kernel, the following vulnerability has been resolved: net/smc: fi... In the Linux kernel, the following vulnerability has been resolved: net/smc: fix neighbour and rtable leak in smc_ib_find_route() In smc_ib_find_route(), the neighbour found by neigh_lookup() and rtable resolved by ip_route_output_flow() are not released or put before return. It may cause the refcount leak, so fix it. Scope: local bookworm: resolved (fixed in 6.1.94
debian
CVE-2018-8087P4MEDIUMCVSS 5.5fixed in linux 4.15.11-1 (bookworm)2018
CVE-2018-8087 [MEDIUM] CVE-2018-8087: linux - Memory leak in the hwsim_new_radio_nl function in drivers/net/wireless/mac80211_... Memory leak in the hwsim_new_radio_nl function in drivers/net/wireless/mac80211_hwsim.c in the Linux kernel through 4.15.9 allows local users to cause a denial of service (memory consumption) by triggering an out-of-array error case. Scope: local bookworm: resolved (fixed in 4.15.11-1) bullseye: resolved (fixed in 4.15.11-1) forky: resolved (fixed in 4.15.11-1) sid: r
debian
CVE-2017-14106P4MEDIUMCVSS 5.5fixed in linux 4.12.6-1 (bookworm)2017
CVE-2017-14106 [MEDIUM] CVE-2017-14106: linux - The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 al... The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvmsg code path. Scope: local bookworm: resolved (fixed in 4.12.6-1) bullseye: resolved (fixed in 4.12.6-1) forky: resolved (fixed i
debian
CVE-2017-18204P4MEDIUMCVSS 5.5fixed in linux 4.14.2-1 (bookworm)2017
CVE-2017-18204 [MEDIUM] CVE-2017-18204: linux - The ocfs2_setattr function in fs/ocfs2/file.c in the Linux kernel before 4.14.2 ... The ocfs2_setattr function in fs/ocfs2/file.c in the Linux kernel before 4.14.2 allows local users to cause a denial of service (deadlock) via DIO requests. Scope: local bookworm: resolved (fixed in 4.14.2-1) bullseye: resolved (fixed in 4.14.2-1) forky: resolved (fixed in 4.14.2-1) sid: resolved (fixed in 4.14.2-1) trixie: resolved (fixed in 4.14.2-1)
debian
CVE-2022-24959P4MEDIUMCVSS 5.5fixed in linux 5.16.7-1 (bookworm)2022
CVE-2022-24959 [MEDIUM] CVE-2022-24959: linux - An issue was discovered in the Linux kernel before 5.16.5. There is a memory lea... An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevprivate in drivers/net/hamradio/yam.c. Scope: local bookworm: resolved (fixed in 5.16.7-1) bullseye: resolved (fixed in 5.10.92-2) forky: resolved (fixed in 5.16.7-1) sid: resolved (fixed in 5.16.7-1) trixie: resolved (fixed in 5.16.7-1)
debian
CVE-2020-8992P4MEDIUMCVSS 5.5fixed in linux 5.5.13-1 (bookworm)2020
CVE-2020-8992 [MEDIUM] CVE-2020-8992: linux - ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel thro... ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size. Scope: local bookworm: resolved (fixed in 5.5.13-1) bullseye: resolved (fixed in 5.5.13-1) forky: resolved (fixed in 5.5.13-1) sid: resolved (fixed in 5.5.13-1) trixie: resolved (fixed in 5.5.
debian
CVE-2025-37757P4MEDIUMCVSS 5.5fixed in linux 6.1.135-1 (bookworm)2025
CVE-2025-37757 [MEDIUM] CVE-2025-37757: linux - In the Linux kernel, the following vulnerability has been resolved: tipc: fix m... In the Linux kernel, the following vulnerability has been resolved: tipc: fix memory leak in tipc_link_xmit In case the backlog transmit queue for system-importance messages is overloaded, tipc_link_xmit() returns -ENOBUFS but the skb list is not purged. This leads to memory leak and failure when a skb is allocated. This commit fixes this issue by purging the skb li
debian
Debian Linux vulnerabilities | cvebase