Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 535 of 632
CVE-2025-38057P4MEDIUMCVSS 5.5fixed in linux 6.1.159-1 (bookworm)2025
CVE-2025-38057 [MEDIUM] CVE-2025-38057: linux - In the Linux kernel, the following vulnerability has been resolved: espintcp: f...
In the Linux kernel, the following vulnerability has been resolved: espintcp: fix skb leaks A few error paths are missing a kfree_skb.
Scope: local
bookworm: resolved (fixed in 6.1.159-1)
bullseye: open
forky: resolved (fixed in 6.12.32-1)
sid: resolved (fixed in 6.12.32-1)
trixie: resolved (fixed in 6.12.32-1)
debian
CVE-2017-18232P4MEDIUMCVSS 5.5fixed in linux 4.15.17-1 (bookworm)2017
CVE-2017-18232 [MEDIUM] CVE-2017-18232: linux - The Serial Attached SCSI (SAS) implementation in the Linux kernel through 4.15.9...
The Serial Attached SCSI (SAS) implementation in the Linux kernel through 4.15.9 mishandles a mutex within libsas, which allows local users to cause a denial of service (deadlock) by triggering certain error-handling code.
Scope: local
bookworm: resolved (fixed in 4.15.17-1)
bullseye: resolved (fixed in 4.15.17-1)
forky: resolved (fixed in 4.15.17-1)
sid: resolved (
debian
CVE-2018-8043P4LOWCVSS 5.5fixed in linux 4.16.5-1 (bookworm)2018
CVE-2018-8043 [MEDIUM] CVE-2018-8043: linux - The unimac_mdio_probe function in drivers/net/phy/mdio-bcm-unimac.c in the Linux...
The unimac_mdio_probe function in drivers/net/phy/mdio-bcm-unimac.c in the Linux kernel through 4.15.8 does not validate certain resource availability, which allows local users to cause a denial of service (NULL pointer dereference).
Scope: local
bookworm: resolved (fixed in 4.16.5-1)
bullseye: resolved (fixed in 4.16.5-1)
forky: resolved (fixed in 4.16.5-1)
sid: reso
debian
CVE-2019-20095P4MEDIUMCVSS 5.5fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-20095 [MEDIUM] CVE-2019-20095: linux - mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux k...
mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux kernel before 5.1.6 has some error-handling cases that did not free allocated hostcmd memory, aka CID-003b686ace82. This will cause a memory leak and denial of service.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6
debian
CVE-2017-15306P4MEDIUMCVSS 5.5fixed in linux 4.13.13-1 (bookworm)2017
CVE-2017-15306 [MEDIUM] CVE-2017-15306: linux - The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc.c in the L...
The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc.c in the Linux kernel before 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a KVM_CHECK_EXTENSION KVM_CAP_PPC_HTM ioctl call to /dev/kvm.
Scope: local
bookworm: resolved (fixed in 4.13.13-1)
bullseye: resolved (fixed in 4.13.13-1)
forky: res
debian
CVE-2019-19043P4MEDIUMCVSS 5.5fixed in linux 5.4.19-1 (bookworm)2019
CVE-2019-19043 [MEDIUM] CVE-2019-19043: linux - A memory leak in the i40e_setup_macvlans() function in drivers/net/ethernet/inte...
A memory leak in the i40e_setup_macvlans() function in drivers/net/ethernet/intel/i40e/i40e_main.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering i40e_setup_channel() failures, aka CID-27d461333459.
Scope: local
bookworm: resolved (fixed in 5.4.19-1)
bullseye: resolved (fixed in 5.4.19-1)
forky: re
debian
CVE-2019-19077P4MEDIUMCVSS 5.5fixed in linux 5.4.6-1 (bookworm)2019
CVE-2019-19077 [MEDIUM] CVE-2019-19077: linux - A memory leak in the bnxt_re_create_srq() function in drivers/infiniband/hw/bnxt...
A memory leak in the bnxt_re_create_srq() function in drivers/infiniband/hw/bnxt_re/ib_verbs.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering copy to udata failures, aka CID-4a9d46a9fe14.
Scope: local
bookworm: resolved (fixed in 5.4.6-1)
bullseye: resolved (fixed in 5.4.6-1)
forky: resolved (fixed
debian
CVE-2016-9685P4MEDIUMCVSS 5.5fixed in linux 4.5.1-1 (bookworm)2016
CVE-2016-9685 [MEDIUM] CVE-2016-9685: linux - Multiple memory leaks in error paths in fs/xfs/xfs_attr_list.c in the Linux kern...
Multiple memory leaks in error paths in fs/xfs/xfs_attr_list.c in the Linux kernel before 4.5.1 allow local users to cause a denial of service (memory consumption) via crafted XFS filesystem operations.
Scope: local
bookworm: resolved (fixed in 4.5.1-1)
bullseye: resolved (fixed in 4.5.1-1)
forky: resolved (fixed in 4.5.1-1)
sid: resolved (fixed in 4.5.1-1)
trixie: re
debian
CVE-2020-12768P4LOWCVSS 5.5fixed in linux 5.6.7-1 (bookworm)2020
CVE-2020-12768 [MEDIUM] CVE-2020-12768: linux - An issue was discovered in the Linux kernel before 5.6. svm_cpu_uninit in arch/x...
An issue was discovered in the Linux kernel before 5.6. svm_cpu_uninit in arch/x86/kvm/svm.c has a memory leak, aka CID-d80b64ff297e. NOTE: third parties dispute this issue because it's a one-time leak at the boot, the size is negligible, and it can't be triggered at will
Scope: local
bookworm: resolved (fixed in 5.6.7-1)
bullseye: resolved (fixed in 5.6.7-1)
forky:
debian
CVE-2017-9211P4MEDIUMCVSS 5.5fixed in linux 4.9.30-1 (bookworm)2017
CVE-2017-9211 [MEDIUM] CVE-2017-9211: linux - The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel t...
The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check, which allows local users to cause a denial of service (NULL pointer dereference) via a crafted application.
Scope: local
bookworm: resolved (fixed in 4.9.30-1)
bullseye: resolved (fixed in 4.9.30-1)
forky: resolved (fix
debian
CVE-2017-6951P4MEDIUMCVSS 5.5fixed in linux 4.0.2-1 (bookworm)2017
CVE-2017-6951 [MEDIUM] CVE-2017-6951: linux - The keyring_search_aux function in security/keys/keyring.c in the Linux kernel t...
The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.
Scope: local
bookworm: resolved (fixed in 4.0.2-1)
bullseye: resolved (fixed in 4.0.2-1)
forky: resolved (fixed in 4.0.2-1)
sid: resolved (f
debian
CVE-2017-18193P4MEDIUMCVSS 5.5fixed in linux 4.13.4-1 (bookworm)2017
CVE-2017-18193 [MEDIUM] CVE-2017-18193: linux - fs/f2fs/extent_cache.c in the Linux kernel before 4.13 mishandles extent trees, ...
fs/f2fs/extent_cache.c in the Linux kernel before 4.13 mishandles extent trees, which allows local users to cause a denial of service (BUG) via an application with multiple threads.
Scope: local
bookworm: resolved (fixed in 4.13.4-1)
bullseye: resolved (fixed in 4.13.4-1)
forky: resolved (fixed in 4.13.4-1)
sid: resolved (fixed in 4.13.4-1)
trixie: resolved (fixed i
debian
CVE-2011-5321P4MEDIUMCVSS 5.5fixed in linux 3.2.20-1 (bookworm)2011
CVE-2011-5321 [MEDIUM] CVE-2011-5321: linux - The tty_open function in drivers/tty/tty_io.c in the Linux kernel before 3.1.1 m...
The tty_open function in drivers/tty/tty_io.c in the Linux kernel before 3.1.1 mishandles a driver-lookup failure, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted access to a device file under the /dev/pts directory.
Scope: local
bookworm: resolved (fixed in 3.2.20-
debian
CVE-2017-9059P4MEDIUMCVSS 5.5fixed in linux 4.9.30-1 (bookworm)2017
CVE-2017-9059 [MEDIUM] CVE-2017-9059: linux - The NFSv4 implementation in the Linux kernel through 4.11.1 allows local users t...
The NFSv4 implementation in the Linux kernel through 4.11.1 allows local users to cause a denial of service (resource consumption) by leveraging improper channel callback shutdown when unmounting an NFSv4 filesystem, aka a "module reference and kernel daemon" leak.
Scope: local
bookworm: resolved (fixed in 4.9.30-1)
bullseye: resolved (fixed in 4.9.30-1)
forky: resolv
debian
CVE-2013-2128P4MEDIUMCVSS 5.5fixed in linux 2.6.35-1~experimental.1 (bookworm)2013
CVE-2013-2128 [MEDIUM] CVE-2013-2128: linux - The tcp_read_sock function in net/ipv4/tcp.c in the Linux kernel before 2.6.34 d...
The tcp_read_sock function in net/ipv4/tcp.c in the Linux kernel before 2.6.34 does not properly manage skb consumption, which allows local users to cause a denial of service (system crash) via a crafted splice system call for a TCP socket.
Scope: local
bookworm: resolved (fixed in 2.6.35-1~experimental.1)
bullseye: resolved (fixed in 2.6.35-1~experimental.1)
forky: r
debian
CVE-2020-36311P4MEDIUMCVSS 5.5fixed in linux 5.9.1-1 (bookworm)2020
CVE-2020-36311 [MEDIUM] CVE-2020-36311: linux - An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c a...
An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of service (soft lockup) by triggering destruction of a large SEV VM (which requires unregistering many encrypted regions), aka CID-7be74942f184.
Scope: local
bookworm: resolved (fixed in 5.9.1-1)
bullseye: resolved (fixed in 5.9.1-1)
forky: resolved (fi
debian
CVE-2024-25741P4MEDIUMCVSS 5.5fixed in linux 6.1.99-1 (bookworm)2024
CVE-2024-25741 [MEDIUM] CVE-2024-25741: linux - printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel thr...
printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact.
Scope: local
bookworm: resolved (fixed in 6.1.99-1)
bullseye: resolved (fixed in 5.10.221-1)
forky: resolved (fixed in 6.9.8-1)
sid: resolved (fixed
debian
CVE-2020-36312P4MEDIUMCVSS 5.5fixed in linux 5.8.10-1 (bookworm)2020
CVE-2020-36312 [MEDIUM] CVE-2020-36312: linux - An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c h...
An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c has a kvm_io_bus_unregister_dev memory leak upon a kmalloc failure, aka CID-f65886606c2d.
Scope: local
bookworm: resolved (fixed in 5.8.10-1)
bullseye: resolved (fixed in 5.8.10-1)
forky: resolved (fixed in 5.8.10-1)
sid: resolved (fixed in 5.8.10-1)
trixie: resolved (fixed in 5.8.10-1)
debian
CVE-2021-4148P4MEDIUMCVSS 5.5fixed in linux 5.14.16-1 (bookworm)2021
CVE-2021-4148 [MEDIUM] CVE-2021-4148: linux - A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffe...
A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity check may allow a local attacker with user privilege to cause a denial of service (DOS) problem.
Scope: local
bookworm: resolved (fixed in 5.14.16-1)
bullseye: resolved (fixed in 5.10.84-1)
forky: resolved (fixed in 5.14.16-1)
sid: resolved (fixed in
debian
CVE-2020-12364P4MEDIUMCVSS 5.5fixed in firmware-nonfree 20210208-1 (bookworm)2020
CVE-2020-12364 [MEDIUM] CVE-2020-12364: firmware-nonfree - Null pointer reference in some Intel(R) Graphics Drivers for Windows* before ver...
Null pointer reference in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before version Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access.
Scope: local
bookworm: resolved (fixed in 20210208-1)
bullseye: resolved (fixed in 20210208-1)
forky: resolved (fixed in 2021
debian