cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 537 of 632
CVE-2021-4453P4MEDIUMCVSS 5.5fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-4453 [MEDIUM] CVE-2021-4453: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm:... In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix a potential gpu_metrics_table memory leak Memory is allocated for gpu_metrics_table in renoir_init_smc_tables(), but not freed in int smu_v12_0_fini_smc_tables(). Free it! Scope: local bookworm: resolved (fixed in 5.15.15-1) bullseye: resolved (fixed in 5.10.92-1) forky: resolved (fixe
debian
CVE-2023-23000P4LOWCVSS 5.5fixed in linux 5.17.3-1 (bookworm)2023
CVE-2023-23000 [MEDIUM] CVE-2023-23000: linux - In the Linux kernel before 5.17, drivers/phy/tegra/xusb.c mishandles the tegra_x... In the Linux kernel before 5.17, drivers/phy/tegra/xusb.c mishandles the tegra_xusb_find_port_node return value. Callers expect NULL in the error case, but an error pointer is used. Scope: local bookworm: resolved (fixed in 5.17.3-1) bullseye: open forky: resolved (fixed in 5.17.3-1) sid: resolved (fixed in 5.17.3-1) trixie: resolved (fixed in 5.17.3-1)
debian
CVE-2022-49354P4MEDIUMCVSS 5.5fixed in linux 5.18.5-1 (bookworm)2022
CVE-2022-49354 [MEDIUM] CVE-2022-49354: linux - In the Linux kernel, the following vulnerability has been resolved: ata: pata_o... In the Linux kernel, the following vulnerability has been resolved: ata: pata_octeon_cf: Fix refcount leak in octeon_cf_probe of_find_device_by_node() takes reference, we should use put_device() to release it when not need anymore. Add missing put_device() to avoid refcount leak. Scope: local bookworm: resolved (fixed in 5.18.5-1) bullseye: resolved (fixed in 5.10.1
debian
CVE-2022-49314P4MEDIUMCVSS 5.5fixed in linux 5.18.5-1 (bookworm)2022
CVE-2022-49314 [MEDIUM] CVE-2022-49314: linux - In the Linux kernel, the following vulnerability has been resolved: tty: Fix a ... In the Linux kernel, the following vulnerability has been resolved: tty: Fix a possible resource leak in icom_probe When pci_read_config_dword failed, call pci_release_regions() and pci_disable_device() to recycle the resource previously allocated. Scope: local bookworm: resolved (fixed in 5.18.5-1) bullseye: resolved (fixed in 5.10.127-1) forky: resolved (fixed in
debian
CVE-2023-23005P4MEDIUMCVSS 5.5fixed in linux 6.3.7-1 (forky)2023
CVE-2023-23005 [MEDIUM] CVE-2023-23005: linux - In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory... In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached. Scope: local bookworm: open bullse
debian
CVE-2022-48831P4MEDIUMCVSS 5.5fixed in linux 5.16.10-1 (bookworm)2022
CVE-2022-48831 [MEDIUM] CVE-2022-48831: linux - In the Linux kernel, the following vulnerability has been resolved: ima: fix re... In the Linux kernel, the following vulnerability has been resolved: ima: fix reference leak in asymmetric_verify() Don't leak a reference to the key if its algorithm is unknown. Scope: local bookworm: resolved (fixed in 5.16.10-1) bullseye: resolved forky: resolved (fixed in 5.16.10-1) sid: resolved (fixed in 5.16.10-1) trixie: resolved (fixed in 5.16.10-1)
debian
CVE-2024-40997P4LOWCVSS 5.5fixed in linux 6.9.7-1 (forky)2024
CVE-2024-40997 [MEDIUM] CVE-2024-40997: linux - In the Linux kernel, the following vulnerability has been resolved: cpufreq: am... In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate: fix memory leak on CPU EPP exit The cpudata memory from kzalloc() in amd_pstate_epp_cpu_init() is not freed in the analogous exit function, so fix that. [ rjw: Subject and changelog edits ] Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 6.9.7-1) sid
debian
CVE-2022-49167P4MEDIUMCVSS 5.5fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-49167 [MEDIUM] CVE-2022-49167: linux - In the Linux kernel, the following vulnerability has been resolved: btrfs: do n... In the Linux kernel, the following vulnerability has been resolved: btrfs: do not double complete bio on errors during compressed reads I hit some weird panics while fixing up the error handling from btrfs_lookup_bio_sums(). Turns out the compression path will complete the bio we use if we set up any of the compression bios and then return an error, and then btrfs_s
debian
CVE-2024-27033P4LOWCVSS 5.5fixed in linux 6.7.12-1 (forky)2024
CVE-2024-27033 [MEDIUM] CVE-2024-27033: linux - In the Linux kernel, the following vulnerability has been resolved: f2fs: fix t... In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to remove unnecessary f2fs_bug_on() to avoid panic verify_blkaddr() will trigger panic once we inject fault into f2fs_is_valid_blkaddr(), fix to remove this unnecessary f2fs_bug_on(). Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 6.7.12-1) sid: resolved (fixe
debian
CVE-2022-49331P4MEDIUMCVSS 5.5fixed in linux 5.18.5-1 (bookworm)2022
CVE-2022-49331 [MEDIUM] CVE-2022-49331: linux - In the Linux kernel, the following vulnerability has been resolved: nfc: st21nf... In the Linux kernel, the following vulnerability has been resolved: nfc: st21nfca: fix memory leaks in EVT_TRANSACTION handling Error paths do not free previously allocated memory. Add devm_kfree() to those failure paths. Scope: local bookworm: resolved (fixed in 5.18.5-1) bullseye: resolved (fixed in 5.10.127-1) forky: resolved (fixed in 5.18.5-1) sid: resolved (fi
debian
CVE-2021-33135P4MEDIUMCVSS 5.5fixed in linux 5.16.18-1 (bookworm)2021
CVE-2021-33135 [MEDIUM] CVE-2021-33135: linux - Uncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX m... Uncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access. Scope: local bookworm: resolved (fixed in 5.16.18-1) bullseye: resolved forky: resolved (fixed in 5.16.18-1) sid: resolved (fixed in 5.16.18-1) trixie: resolved (fixed in 5.16.18-1)
debian
CVE-2023-22997P4MEDIUMCVSS 5.5fixed in linux 6.1.4-1 (bookworm)2023
CVE-2023-22997 [MEDIUM] CVE-2023-22997: linux - In the Linux kernel before 6.1.2, kernel/module/decompress.c misinterprets the m... In the Linux kernel before 6.1.2, kernel/module/decompress.c misinterprets the module_get_next_page return value (expects it to be NULL in the error case, whereas it is actually an error pointer). Scope: local bookworm: resolved (fixed in 6.1.4-1) bullseye: resolved forky: resolved (fixed in 6.1.4-1) sid: resolved (fixed in 6.1.4-1) trixie: resolved (fixed in 6.1.4-
debian
CVE-2024-46840P4MEDIUMCVSS 5.5fixed in linux 6.1.112-1 (bookworm)2024
CVE-2024-46840 [MEDIUM] CVE-2024-46840: linux - In the Linux kernel, the following vulnerability has been resolved: btrfs: clea... In the Linux kernel, the following vulnerability has been resolved: btrfs: clean up our handling of refs == 0 in snapshot delete In reada we BUG_ON(refs == 0), which could be unkind since we aren't holding a lock on the extent leaf and thus could get a transient incorrect answer. In walk_down_proc we also BUG_ON(refs == 0), which could happen if we have extent tree
debian
CVE-2022-49661P4MEDIUMCVSS 5.5fixed in linux 5.18.14-1 (bookworm)2022
CVE-2022-49661 [MEDIUM] CVE-2022-49661: linux - In the Linux kernel, the following vulnerability has been resolved: can: gs_usb... In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_open/close(): fix memory leak The gs_usb driver appears to suffer from a malady common to many USB CAN adapter drivers in that it performs usb_alloc_coherent() to allocate a number of USB request blocks (URBs) for RX, and then later relies on usb_kill_anchored_urbs() to free them
debian
CVE-2022-49396P4MEDIUMCVSS 5.5fixed in linux 5.18.5-1 (bookworm)2022
CVE-2022-49396 [MEDIUM] CVE-2022-49396: linux - In the Linux kernel, the following vulnerability has been resolved: phy: qcom-q... In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qmp: fix reset-controller leak on probe errors Make sure to release the lane reset controller in case of a late probe error (e.g. probe deferral). Note that due to the reset controller being defined in devicetree in "lane" child nodes, devm_reset_control_get_exclusive() cannot be used dire
debian
CVE-2022-49382P4MEDIUMCVSS 5.5fixed in linux 5.18.5-1 (bookworm)2022
CVE-2022-49382 [MEDIUM] CVE-2022-49382: linux - In the Linux kernel, the following vulnerability has been resolved: soc: rockch... In the Linux kernel, the following vulnerability has been resolved: soc: rockchip: Fix refcount leak in rockchip_grf_init of_find_matching_node_and_match returns a node pointer with refcount incremented, we should use of_node_put() on it when done. Add missing of_node_put() to avoid refcount leak. Scope: local bookworm: resolved (fixed in 5.18.5-1) bullseye: resolve
debian
CVE-2022-49263P4MEDIUMCVSS 5.5fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-49263 [MEDIUM] CVE-2022-49263: linux - In the Linux kernel, the following vulnerability has been resolved: brcmfmac: p... In the Linux kernel, the following vulnerability has been resolved: brcmfmac: pcie: Release firmwares in the brcmf_pcie_setup error path This avoids leaking memory if brcmf_chip_get_raminfo fails. Note that the CLM blob is released in the device remove path. Scope: local bookworm: resolved (fixed in 5.17.3-1) bullseye: resolved (fixed in 5.10.113-1) forky: resolved
debian
CVE-2024-46817P4MEDIUMCVSS 5.5fixed in linux 6.1.112-1 (bookworm)2024
CVE-2024-46817 [MEDIUM] CVE-2024-46817: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amd/dis... In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6 [Why] Coverity reports OVERRUN warning. Should abort amdgpu_dm initialize. [How] Return failure to amdgpu_dm_init. Scope: local bookworm: resolved (fixed in 6.1.112-1) bullseye: resolved (fixed in 5.10.226-1) forky: resolved
debian
CVE-2022-49463P4MEDIUMCVSS 5.5fixed in linux 5.18.5-1 (bookworm)2022
CVE-2022-49463 [MEDIUM] CVE-2022-49463: linux - In the Linux kernel, the following vulnerability has been resolved: thermal/dri... In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/imx_sc_thermal: Fix refcount leak in imx_sc_thermal_probe of_find_node_by_name() returns a node pointer with refcount incremented, we should use of_node_put() on it when done. Add missing of_node_put() to avoid refcount leak. Scope: local bookworm: resolved (fixed in 5.18.5-1) bullse
debian
CVE-2022-49242P4MEDIUMCVSS 5.5fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-49242 [MEDIUM] CVE-2022-49242: linux - In the Linux kernel, the following vulnerability has been resolved: ASoC: mxs: ... In the Linux kernel, the following vulnerability has been resolved: ASoC: mxs: Fix error handling in mxs_sgtl5000_probe This function only calls of_node_put() in the regular path. And it will cause refcount leak in error paths. For example, when codec_np is NULL, saif_np[0] and saif_np[1] are not NULL, it will cause leaks. of_node_put() will check if the node pointe
debian
Debian Linux vulnerabilities | cvebase