Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 580 of 632
CVE-2020-27418P4MEDIUMCVSS 4.4fixed in linux 5.5.13-1 (bookworm)2020
CVE-2020-27418 [MEDIUM] CVE-2020-27418: linux - A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers...
A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers to obatin sensitive information via vgacon_invert_region() function.
Scope: local
bookworm: resolved (fixed in 5.5.13-1)
bullseye: resolved (fixed in 5.5.13-1)
forky: resolved (fixed in 5.5.13-1)
sid: resolved (fixed in 5.5.13-1)
trixie: resolved (fixed in 5.5.13-1)
debian
CVE-2021-39657P4MEDIUMCVSS 4.4fixed in linux 5.10.12-1 (bookworm)2021
CVE-2021-39657 [MEDIUM] CVE-2021-39657: linux - In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds...
In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194696049References: Upstream kernel
Scope: local
bookworm:
debian
CVE-2023-47233P4MEDIUMCVSS 4.3fixed in linux 6.1.85-1 (bookworm)2023
CVE-2023-47233 [MEDIUM] CVE-2023-47233: linux - The brcm80211 component in the Linux kernel through 6.5.10 has a brcmf_cfg80211_...
The brcm80211 component in the Linux kernel through 6.5.10 has a brcmf_cfg80211_detach use-after-free in the device unplugging (disconnect the USB by hotplug) code. For physically proximate attackers with local access, this "could be exploited in a real world scenario." This is related to brcmf_cfg80211_escan_timeout_worker in drivers/net/wireless/broadcom/brcm80211
debian
CVE-2022-1974P4MEDIUMCVSS 4.1fixed in linux 5.17.11-1 (bookworm)2022
CVE-2022-1974 [MEDIUM] CVE-2022-1974: linux - A use-after-free flaw was found in the Linux kernel's NFC core functionality due...
A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject creation and delete. This vulnerability allows a local attacker with CAP_NET_ADMIN privilege to leak kernel information.
Scope: local
bookworm: resolved (fixed in 5.17.11-1)
bullseye: resolved (fixed in 5.10.120-1)
forky: resolved (fixed in 5.17.11-1)
s
debian
CVE-2014-1690P4LOWCVSS 2.6fixed in linux 3.12.8-1 (bookworm)2014
CVE-2014-1690 [LOW] CVE-2014-1690: linux - The help function in net/netfilter/nf_nat_irc.c in the Linux kernel before 3.12....
The help function in net/netfilter/nf_nat_irc.c in the Linux kernel before 3.12.8 allows remote attackers to obtain sensitive information from kernel memory by establishing an IRC DCC session in which incorrect packet data is transmitted during use of the NAT mangle feature.
Scope: local
bookworm: resolved (fixed in 3.12.8-1)
bullseye: resolved (fixed in 3.12.8-1)
forky:
debian
CVE-2024-50170P4LOWCVSS 5.5fixed in linux 6.11.6-1 (forky)2024
CVE-2024-50170 [MEDIUM] CVE-2024-50170: linux - In the Linux kernel, the following vulnerability has been resolved: net: bcmasp...
In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix potential memory leak in bcmasp_xmit() The bcmasp_xmit() returns NETDEV_TX_OK without freeing skb in case of mapping fails, add dev_kfree_skb() to fix it.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.11.6-1)
sid: resolved (fixed in 6.11.6-1)
trixie:
debian
CVE-2019-18811P4MEDIUMCVSS 5.5fixed in linux 5.3.15-1 (bookworm)2019
CVE-2019-18811 [MEDIUM] CVE-2019-18811: linux - A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc...
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.
Scope: local
bookworm: resolved (fixed in 5.3.15-1)
bullseye: resolved (fixed in 5.3.15-1)
forky: resolved (fix
debian
CVE-2015-8844P4MEDIUMCVSS 5.5fixed in linux 4.4.2-1 (bookworm)2015
CVE-2015-8844 [MEDIUM] CVE-2015-8844: linux - The signal implementation in the Linux kernel before 4.3.5 on powerpc platforms ...
The signal implementation in the Linux kernel before 4.3.5 on powerpc platforms does not check for an MSR with both the S and T bits set, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application.
Scope: local
bookworm: resolved (fixed in 4.4.2-1)
bullseye: resolved (fixed in 4.4.2-1)
forky: resolved (fixed in 4
debian
CVE-2016-0617P4MEDIUMCVSS 5.5fixed in linux 4.4.2-1 (bookworm)2016
CVE-2016-0617 [MEDIUM] CVE-2016-0617: linux - Unspecified vulnerability in the kernel-uek component in Oracle Linux 6 allows l...
Unspecified vulnerability in the kernel-uek component in Oracle Linux 6 allows local users to affect availability via unknown vectors.
Scope: local
bookworm: resolved (fixed in 4.4.2-1)
bullseye: resolved (fixed in 4.4.2-1)
forky: resolved (fixed in 4.4.2-1)
sid: resolved (fixed in 4.4.2-1)
trixie: resolved (fixed in 4.4.2-1)
debian
CVE-2019-18808P4LOWCVSS 5.5fixed in linux 5.5.13-1 (bookworm)2019
CVE-2019-18808 [MEDIUM] CVE-2019-18808: linux - A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c ...
A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-128c66429247.
Scope: local
bookworm: resolved (fixed in 5.5.13-1)
bullseye: resolved (fixed in 5.5.13-1)
forky: resolved (fixed in 5.5.13-1)
sid: resolved (fixed in 5.5.13-1)
tri
debian
CVE-2020-24504P4MEDIUMCVSS 5.5fixed in linux 5.14.6-1 (bookworm)2020
CVE-2020-24504 [MEDIUM] CVE-2020-24504: linux - Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers...
Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: open
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.
debian
CVE-2019-0146P4MEDIUMCVSS 5.5fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-0146 [MEDIUM] CVE-2019-0146: linux - Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versio...
Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in 5.2.6-1)
trixie: resolved (fixed
debian
CVE-2019-0148P4MEDIUMCVSS 5.5fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-0148 [MEDIUM] CVE-2019-0148: linux - Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versio...
Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in 5.2.6-1)
trixie: resolved (fixed in
debian
CVE-2024-27076P4MEDIUMCVSS 5.5fixed in linux 6.1.85-1 (bookworm)2024
CVE-2024-27076 [MEDIUM] CVE-2024-27076: linux - In the Linux kernel, the following vulnerability has been resolved: media: imx:...
In the Linux kernel, the following vulnerability has been resolved: media: imx: csc/scaler: fix v4l2_ctrl_handler memory leak Free the memory allocated in v4l2_ctrl_handler_init on release.
Scope: local
bookworm: resolved (fixed in 6.1.85-1)
bullseye: resolved (fixed in 5.10.216-1)
forky: resolved (fixed in 6.7.12-1)
sid: resolved (fixed in 6.7.12-1)
trixie: resolve
debian
CVE-2022-49671P4MEDIUMCVSS 5.5fixed in linux 5.18.14-1 (bookworm)2022
CVE-2022-49671 [MEDIUM] CVE-2022-49671: linux - In the Linux kernel, the following vulnerability has been resolved: RDMA/cm: Fi...
In the Linux kernel, the following vulnerability has been resolved: RDMA/cm: Fix memory leak in ib_cm_insert_listen cm_alloc_id_priv() allocates resource for the cm_id_priv. When cm_init_listen() fails it doesn't free it, leading to memory leak. Add the missing error unwind.
Scope: local
bookworm: resolved (fixed in 5.18.14-1)
bullseye: resolved (fixed in 5.10.136-1
debian
CVE-2022-49115P4MEDIUMCVSS 5.5fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-49115 [MEDIUM] CVE-2022-49115: linux - In the Linux kernel, the following vulnerability has been resolved: PCI: endpoi...
In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Fix misused goto label Fix a misused goto label jump since that can result in a memory leak.
Scope: local
bookworm: resolved (fixed in 5.17.3-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: resolved (fixed in 5.17.3-1)
sid: resolved (fixed in 5.17.3-1)
trixie: resolved (fixed in 5.
debian
CVE-2023-52652P4MEDIUMCVSS 5.5fixed in linux 6.1.85-1 (bookworm)2023
CVE-2023-52652 [MEDIUM] CVE-2023-52652: linux - In the Linux kernel, the following vulnerability has been resolved: NTB: fix po...
In the Linux kernel, the following vulnerability has been resolved: NTB: fix possible name leak in ntb_register_device() If device_register() fails in ntb_register_device(), the device name allocated by dev_set_name() should be freed. As per the comment in device_register(), callers should use put_device() to give up the reference in the error path. So fix this by c
debian
CVE-2022-49253P4MEDIUMCVSS 5.5fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-49253 [MEDIUM] CVE-2022-49253: linux - In the Linux kernel, the following vulnerability has been resolved: media: usb:...
In the Linux kernel, the following vulnerability has been resolved: media: usb: go7007: s2250-board: fix leak in probe() Call i2c_unregister_device(audio) on this error path.
Scope: local
bookworm: resolved (fixed in 5.17.3-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: resolved (fixed in 5.17.3-1)
sid: resolved (fixed in 5.17.3-1)
trixie: resolved (fixed in 5.1
debian
CVE-2024-26655P4LOWCVSS 5.5fixed in linux 6.7.12-1 (forky)2024
CVE-2024-26655 [MEDIUM] CVE-2024-26655: linux - In the Linux kernel, the following vulnerability has been resolved: Fix memory ...
In the Linux kernel, the following vulnerability has been resolved: Fix memory leak in posix_clock_open() If the clk ops.open() function returns an error, we don't release the pccontext we allocated for this clock. Re-organize the code slightly to make it all more obvious.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.7.12-1)
sid: re
debian
CVE-2022-49119P4MEDIUMCVSS 5.5fixed in linux 5.17.3-1 (bookworm)2022
CVE-2022-49119 [MEDIUM] CVE-2022-49119: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: pm800...
In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix memory leak in pm8001_chip_fw_flash_update_req() In pm8001_chip_fw_flash_update_build(), if pm8001_chip_fw_flash_update_build() fails, the struct fw_control_ex allocated must be freed.
Scope: local
bookworm: resolved (fixed in 5.17.3-1)
bullseye: resolved (fixed in 5.10.113-1)
fork
debian