Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 590 of 632
CVE-2023-53430P4LOWCVSS 5.5fixed in linux 6.3.7-1 (forky)2023
CVE-2023-53430 [MEDIUM] CVE-2023-53430: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:...
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: dma: fix memory leak running mt76_dma_tx_cleanup Fix device unregister memory leak and alway cleanup all configured rx queues in mt76_dma_tx_cleanup routine.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: res
debian
CVE-2026-23190P4MEDIUMCVSS 5.5fixed in linux 6.1.164-1 (bookworm)2026
CVE-2026-23190 [MEDIUM] CVE-2026-23190: linux - In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: ...
In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: fix memory leak in acp3x pdm dma ops
Scope: local
bookworm: resolved (fixed in 6.1.164-1)
bullseye: resolved (fixed in 5.10.251-1)
forky: resolved (fixed in 6.18.10-1)
sid: resolved (fixed in 6.18.10-1)
trixie: resolved (fixed in 6.12.73-1)
debian
CVE-2025-71154P4MEDIUMCVSS 5.5fixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-71154 [MEDIUM] CVE-2025-71154: linux - In the Linux kernel, the following vulnerability has been resolved: net: usb: r...
In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix memory leak on usb_submit_urb() failure In async_set_registers(), when usb_submit_urb() fails, the allocated async_req structure and URB are not freed, causing a memory leak. The completion callback async_set_reg_cb() is responsible for freeing these allocations, but it is onl
debian
CVE-2025-71147P4MEDIUMCVSS 5.5fixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-71147 [MEDIUM] CVE-2025-71147: linux - In the Linux kernel, the following vulnerability has been resolved: KEYS: trust...
In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix a memory leak in tpm2_load_cmd 'tpm2_load_cmd' allocates a tempoary blob indirectly via 'tpm2_key_decode' but it is not freed in the failure paths. Address this by wrapping the blob into with a cleanup helper.
Scope: local
bookworm: resolved (fixed in 6.1.162-1)
bullseye: resolved
debian
CVE-2025-71227P4MEDIUMCVSS 5.5fixed in linux 6.18.10-1 (forky)2025
CVE-2025-71227 [MEDIUM] CVE-2025-71227: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80...
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't WARN for connections on invalid channels It's not clear (to me) how exactly syzbot managed to hit this, but it seems conceivable that e.g. regulatory changed and has disabled a channel between scanning (channel is checked to be usable by cfg80211_get_ies_channel_number) and con
debian
CVE-2013-0217P4MEDIUMCVSS 5.2fixed in linux 3.2.39-1 (bookworm)2013
CVE-2013-0217 [MEDIUM] CVE-2013-0217: linux - Memory leak in drivers/net/xen-netback/netback.c in the Xen netback functionalit...
Memory leak in drivers/net/xen-netback/netback.c in the Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (memory consumption) by triggering certain error conditions.
Scope: local
bookworm: resolved (fixed in 3.2.39-1)
bullseye: resolved (fixed in 3.2.39-1)
forky: resolved (fixed in 3.2.39-1)
sid: resolved (f
debian
CVE-2024-23196P4MEDIUMCVSS 5.3fixed in linux 6.1.52-1 (bookworm)2024
CVE-2024-23196 [MEDIUM] CVE-2024-23196: linux - A race condition was found in the Linux kernel's sound/hda device driver in snd...
A race condition was found in the Linux kernel's sound/hda device driver in snd_hdac_regmap_sync() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.
Scope: local
bookworm: resolved (fixed in 6.1.52-1)
bullseye: resolved (fixed in 5.10.197-1)
forky: resolved (fixed in 6.4.13-1)
sid: resolved
debian
CVE-2024-22386P4MEDIUMCVSS 5.3fixed in linux 6.1.55-1 (bookworm)2024
CVE-2024-22386 [MEDIUM] CVE-2024-22386: linux - A race condition was found in the Linux kernel's drm/exynos device driver in exy...
A race condition was found in the Linux kernel's drm/exynos device driver in exynos_drm_crtc_atomic_disable() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.
Scope: local
bookworm: resolved (fixed in 6.1.55-1)
bullseye: resolved (fixed in 5.10.197-1)
forky: resolved (fixed in 6.5.6-1)
sid:
debian
CVE-2015-8839P4MEDIUMCVSS 5.1fixed in linux 4.5.1-1 (bookworm)2015
CVE-2015-8839 [MEDIUM] CVE-2015-8839: linux - Multiple race conditions in the ext4 filesystem implementation in the Linux kern...
Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause a denial of service (disk corruption) by writing to a page that is associated with a different user's file after unsynchronized hole punching and page-fault handling.
Scope: local
bookworm: resolved (fixed in 4.5.1-1)
bullseye: resolved (fixed in 4.
debian
CVE-2016-6156P4MEDIUMCVSS 5.1fixed in linux 4.7.2-1 (bookworm)2016
CVE-2016-6156 [MEDIUM] CVE-2016-6156: linux - Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/c...
Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev.c in the Linux kernel before 4.7 allows local users to cause a denial of service (out-of-bounds array access) by changing a certain size value, aka a "double fetch" vulnerability.
Scope: local
bookworm: resolved (fixed in 4.7.2-1)
bullseye: resolved (fixed in 4.7.2-1)
forky: res
debian
CVE-2020-28974P4MEDIUMCVSS 5.0fixed in linux 5.9.9-1 (bookworm)2020
CVE-2020-28974 [MEDIUM] CVE-2020-28974: linux - A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be use...
A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged information or potentially crash the kernel, aka CID-3c4e0dff2095. This occurs because KD_FONT_OP_COPY in drivers/tty/vt/vt.c can be used for manipulations such as font height.
Scope: local
bookworm: resolved (fixed in 5.9.9-1)
bullseye: resolved (
debian
CVE-2014-3145P4MEDIUMCVSS 4.9fixed in linux 3.14.4-1 (bookworm)2014
CVE-2014-3145 [MEDIUM] CVE-2014-3145: linux - The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function...
The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and system crash) via crafted BPF instructions. NOTE: the affected code was moved to the __skb_get_nlattr_nest function
debian
CVE-2015-7799P4MEDIUMCVSS 4.9fixed in linux 4.2.6-2 (bookworm)2015
CVE-2015-7799 [MEDIUM] CVE-2015-7799: linux - The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4....
The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call.
Scope: local
bookworm: resolved (fixed in 4.2.6-2)
bullseye: resolved (fixed in 4.2.6-2)
forky:
debian
CVE-2014-1874P4MEDIUMCVSS 4.9fixed in linux 3.13.4-1 (bookworm)2014
CVE-2014-1874 [MEDIUM] CVE-2014-1874: linux - The security_context_to_sid_core function in security/selinux/ss/services.c in t...
The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows local users to cause a denial of service (system crash) by leveraging the CAP_MAC_ADMIN capability to set a zero-length security context.
Scope: local
bookworm: resolved (fixed in 3.13.4-1)
bullseye: resolved (fixed in 3.13.4-1)
forky: resolved (fixed i
debian
CVE-2014-7283P4MEDIUMCVSS 4.9fixed in linux 3.16.2-1 (bookworm)2014
CVE-2014-7283 [MEDIUM] CVE-2014-7283: linux - The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementat...
The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) via operations on directories that have hash collisions, as demonstrated by rmdir operations.
Scope: local
boo
debian
CVE-2013-7263P4LOWCVSS 4.9fixed in linux 3.12.6-1 (bookworm)2013
CVE-2013-7263 [MEDIUM] CVE-2013-7263: linux - The Linux kernel before 3.12.4 updates certain length values before ensuring tha...
The Linux kernel before 3.12.4 updates certain length values before ensuring that associated data structures have been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call, related to net/ipv4/ping.c, net/ipv4/raw.c, net/ipv4/udp.c, net/ipv6/raw.c, and net/ipv6/udp.c
debian
CVE-2014-2039P4MEDIUMCVSS 4.9fixed in linux 3.13.5-1 (bookworm)2014
CVE-2014-2039 [MEDIUM] CVE-2014-2039: linux - arch/s390/kernel/head64.S in the Linux kernel before 3.13.5 on the s390 platform...
arch/s390/kernel/head64.S in the Linux kernel before 3.13.5 on the s390 platform does not properly handle attempted use of the linkage stack, which allows local users to cause a denial of service (system crash) by executing a crafted instruction.
Scope: local
bookworm: resolved (fixed in 3.13.5-1)
bullseye: resolved (fixed in 3.13.5-1)
forky: resolved (fixed in 3.13.5
debian
CVE-2015-4692P4MEDIUMCVSS 4.9fixed in linux 4.0.8-1 (bookworm)2015
CVE-2015-4692 [MEDIUM] CVE-2015-4692: linux - The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel thr...
The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging /dev/kvm access for an ioctl call.
Scope: local
bookworm: resolved (fixed in 4.0.8-1)
bullseye: resolved (fixed in 4.0.8-1)
forky:
debian
CVE-2014-9728P4MEDIUMCVSS 4.9fixed in linux 3.16.7-ckt4-1 (bookworm)2014
CVE-2014-9728 [MEDIUM] CVE-2014-9728: linux - The UDF filesystem implementation in the Linux kernel before 3.18.2 does not val...
The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows local users to cause a denial of service (buffer over-read and system crash) via a crafted filesystem image, related to fs/udf/inode.c and fs/udf/symlink.c.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt4-1)
bullseye: resolved (fixed in 3.16.7-ckt4
debian
CVE-2015-5257P4MEDIUMCVSS 4.9fixed in linux 4.2.1-1 (bookworm)2015
CVE-2015-5257 [MEDIUM] CVE-2015-5257: linux - drivers/usb/serial/whiteheat.c in the Linux kernel before 4.2.4 allows physicall...
drivers/usb/serial/whiteheat.c in the Linux kernel before 4.2.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted USB device. NOTE: this ID was incorrectly used for an Apache Cordova issue that has the correct ID of CVE-2015-8320.
Scope: local
bookworm: resolve
debian