cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 566 of 632
CVE-2025-71149P4MEDIUMCVSS 5.5fixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-71149 [MEDIUM] CVE-2025-71149: linux - In the Linux kernel, the following vulnerability has been resolved: io_uring/po... In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: correctly handle io_poll_add() return value on update When the core of io_uring was updated to handle completions consistently and with fixed return codes, the POLL_REMOVE opcode with updates got slightly broken. If a POLL_ADD is pending and then POLL_REMOVE is used to update the even
debian
CVE-2026-23169P4HIGHCVSS 7.8fixed in linux 6.1.164-1 (bookworm)2026
CVE-2026-23169 [HIGH] CVE-2026-23169: linux - In the Linux kernel, the following vulnerability has been resolved: mptcp: fix ... In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race in mptcp_pm_nl_flush_addrs_doit() syzbot and Eulgyu Kim reported crashes in mptcp_pm_nl_get_local_id() and/or mptcp_pm_nl_is_backup() Root cause is list_splice_init() in mptcp_pm_nl_flush_addrs_doit() which is not RCU ready. list_splice_init_rcu() can not be called here while holding p
debian
CVE-2016-2546P4MEDIUMCVSS 5.1fixed in linux 4.4.2-1 (bookworm)2016
CVE-2016-2546 [MEDIUM] CVE-2016-2546: linux - sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mu... sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mutex, which allows local users to cause a denial of service (race condition, use-after-free, and system crash) via a crafted ioctl call. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: resolved (fixed in 4.4.2-1) forky: resolved (fixed in 4.4.2-1) sid: resolved (fixed in 4.4.2-
debian
CVE-2020-36558P4MEDIUMCVSS 5.1fixed in linux 5.5.13-1 (bookworm)2020
CVE-2020-36558 [MEDIUM] CVE-2020-36558: linux - A race condition in the Linux kernel before 5.5.7 involving VT_RESIZEX could lea... A race condition in the Linux kernel before 5.5.7 involving VT_RESIZEX could lead to a NULL pointer dereference and general protection fault. Scope: local bookworm: resolved (fixed in 5.5.13-1) bullseye: resolved (fixed in 5.5.13-1) forky: resolved (fixed in 5.5.13-1) sid: resolved (fixed in 5.5.13-1) trixie: resolved (fixed in 5.5.13-1)
debian
CVE-2015-7833P4MEDIUMCVSS 4.9fixed in linux 4.2.6-2 (bookworm)2015
CVE-2015-7833 [MEDIUM] CVE-2015-7833: linux - The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.1... The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.10.0-229.14.1.el7 in Red Hat Enterprise Linux (RHEL) 7.1 allows physically proximate attackers to cause a denial of service (panic) via a nonzero bInterfaceNumber value in a USB device descriptor. Scope: local bookworm: resolved (fixed in 4.2.6-2) bullseye: resolved (fixed in 4.2.6-2) forky
debian
CVE-2014-3144P4MEDIUMCVSS 4.9fixed in linux 3.14.4-1 (bookworm)2014
CVE-2014-3144 [MEDIUM] CVE-2014-3144: linux - The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations... The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 do not check whether a certain length value is sufficiently large, which allows local users to cause a denial of service (integer underflow and system crash) via crafted BPF instructions. NOTE: the affec
debian
CVE-2015-5307P4MEDIUMCVSS 4.9fixed in linux 4.2.6-1 (bookworm)2015
CVE-2015-5307 [MEDIUM] CVE-2015-5307: linux - The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x... The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c. Scope: local bookworm: resolved (fixed in 4.2.6-1) bullseye: resolved (fixed in 4.2.6-1) forky: resolved (fixed in 4.2.6-1) sid:
debian
CVE-2014-4655P4MEDIUMCVSS 4.9fixed in linux 3.14.9-1 (bookworm)2014
CVE-2014-4655 [MEDIUM] CVE-2014-4655: linux - The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implem... The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local users to cause a denial of service (integer overflow and limit bypass) by leveraging /dev/snd/controlCX access for a large number of SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl calls.
debian
CVE-2019-15666P4MEDIUMCVSS 4.4fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-15666 [MEDIUM] CVE-2019-15666: linux - An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bo... An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory validation. Scope: local bookworm: resolved (fixed in 5.2.6-1) bullseye: resolved (fixed in 5.2.6-1) forky: resolved (fixed in 5.2.6-1
debian
CVE-2014-7842P4MEDIUMCVSS 4.9fixed in linux 3.16.7-ckt2-1 (bookworm)2014
CVE-2014-7842 [MEDIUM] CVE-2014-7842: linux - Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows gu... Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation error report, a similar issue to CVE-2010-5313. Scope: local bookworm: resolved (fixed in 3.16.7-ckt2-1) bullse
debian
CVE-2010-5313P4MEDIUMCVSS 4.9fixed in linux 2.6.38-1 (bookworm)2010
CVE-2010-5313 [MEDIUM] CVE-2010-5313: linux - Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2... Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842. Scope: local bookworm: resolved (fixed in 2.6.38-1) bullseye: resolved (fixed in 2.6.38-1) forky: resolved (fixed in 2.
debian
CVE-2012-2375P4MEDIUMCVSS 4.6fixed in linux 3.2.19-1 (bookworm)2012
CVE-2012-2375 [MEDIUM] CVE-2012-2375: linux - The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implement... The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during a copy operation, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words in an FATTR4_ACL reply. NOTE: this vulnerability exists because of an incompl
debian
CVE-2022-25258P4MEDIUMCVSS 4.6fixed in linux 5.16.10-1 (bookworm)2022
CVE-2022-25258 [MEDIUM] CVE-2022-25258: linux - An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel be... An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur. Scope: local bookworm: resolved (fixed in 5.16.10-1) bullseye: reso
debian
CVE-2019-19965P4MEDIUMCVSS 4.7fixed in linux 5.4.13-1 (bookworm)2019
CVE-2019-19965 [MEDIUM] CVE-2019-19965: linux - In the Linux kernel through 5.4.6, there is a NULL pointer dereference in driver... In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5. Scope: local bookworm: resolved (fixed in 5.4.13-1) bullseye: resolved (fixed in 5.4.13-1) forky: resolved (fixed in 5.4.13-1) sid: reso
debian
CVE-2019-15215P4MEDIUMCVSS 4.6fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-15215 [MEDIUM] CVE-2019-15215: linux - An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-f... An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2_usb.c driver. Scope: local bookworm: resolved (fixed in 5.2.6-1) bullseye: resolved (fixed in 5.2.6-1) forky: resolved (fixed in 5.2.6-1) sid: resolved (fixed in 5.2.6-1) trixie: resolved (fixed in 5.2.6-1)
debian
CVE-2014-6410P4MEDIUMCVSS 4.7fixed in linux 3.16.5-1 (bookworm)2014
CVE-2014-6410 [MEDIUM] CVE-2014-6410: linux - The __udf_read_inode function in fs/udf/inode.c in the Linux kernel through 3.16... The __udf_read_inode function in fs/udf/inode.c in the Linux kernel through 3.16.3 does not restrict the amount of ICB indirection, which allows physically proximate attackers to cause a denial of service (infinite loop or stack consumption) via a UDF filesystem with a crafted inode. Scope: local bookworm: resolved (fixed in 3.16.5-1) bullseye: resolved (fixed in 3.16
debian
CVE-2022-50761P4UNKNOWNfixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50761 CVE-2022-50761: linux - In the Linux kernel, the following vulnerability has been resolved: x86/xen: Fi... In the Linux kernel, the following vulnerability has been resolved: x86/xen: Fix memory leak in xen_init_lock_cpu() In xen_init_lock_cpu(), the @name has allocated new string by kasprintf(), if bind_ipi_to_irqhandler() fails, it should be freed, otherwise may lead to a memory leak issue, fix it. Scope: local bookworm: resolved (fixed in 6.1.4-1) bullseye: resolved (fixed in
debian
CVE-2019-19083P4LOWCVSS 4.7fixed in linux 5.3.9-1 (bookworm)2019
CVE-2019-19083 [MEDIUM] CVE-2019-19083: linux - Memory leaks in *clock_source_create() functions under drivers/gpu/drm/amd/displ... Memory leaks in *clock_source_create() functions under drivers/gpu/drm/amd/display/dc in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption). This affects the dce112_clock_source_create() function in drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, the dce100_clock_source_create() function in drivers/gpu/drm/amd/di
debian
CVE-2022-50848P4UNKNOWNfixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50848 CVE-2022-50848: linux - In the Linux kernel, the following vulnerability has been resolved: drivers: di... In the Linux kernel, the following vulnerability has been resolved: drivers: dio: fix possible memory leak in dio_init() If device_register() returns error, the 'dev' and name needs be freed. Add a release function, and then call put_device() in the error path, so the name is freed in kobject_cleanup() and to the 'dev' is freed in release function. Scope: local bookworm: res
debian
CVE-2023-54049P4UNKNOWNfixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-54049 CVE-2023-54049: linux - In the Linux kernel, the following vulnerability has been resolved: rpmsg: glin... In the Linux kernel, the following vulnerability has been resolved: rpmsg: glink: Add check for kstrdup Add check for the return value of kstrdup() and return the error if it fails in order to avoid NULL pointer dereference. Scope: local bookworm: resolved (fixed in 6.1.55-1) bullseye: resolved (fixed in 5.10.197-1) forky: resolved (fixed in 6.5.3-1) sid: resolved (fixed in
debian
Debian Linux vulnerabilities | cvebase