Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 591 of 632
CVE-2024-24855P4MEDIUMCVSS 5.0fixed in linux 6.1.133-1 (bookworm)2024
CVE-2024-24855 [MEDIUM] CVE-2024-24855: linux - A race condition was found in the Linux kernel's scsi device driver in lpfc_unre...
A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.
Scope: local
bookworm: resolved (fixed in 6.1.133-1)
bullseye: open
forky: resolved (fixed in 6.5.3-1)
sid: resolved (fixed in 6.5.3-1)
trixie
debian
CVE-2013-7266P4MEDIUMCVSS 4.9fixed in linux 3.12.6-1 (bookworm)2013
CVE-2013-7266 [MEDIUM] CVE-2013-7266: linux - The mISDN_sock_recvmsg function in drivers/isdn/mISDN/socket.c in the Linux kern...
The mISDN_sock_recvmsg function in drivers/isdn/mISDN/socket.c in the Linux kernel before 3.12.4 does not ensure that a certain length value is consistent with the size of an associated data structure, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.
Scope: local
bookworm: resolve
debian
CVE-2014-9715P4MEDIUMCVSS 4.9fixed in linux 3.14.5-1 (bookworm)2014
CVE-2014-9715 [MEDIUM] CVE-2014-9715: linux - include/net/netfilter/nf_conntrack_extend.h in the netfilter subsystem in the Li...
include/net/netfilter/nf_conntrack_extend.h in the netfilter subsystem in the Linux kernel before 3.14.5 uses an insufficiently large data type for certain extension data, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via outbound network traffic that triggers extension loading, as demonstrated by configuring a PPTP tunnel i
debian
CVE-2014-9090P4MEDIUMCVSS 4.9fixed in linux 3.16.7-ckt2-1 (bookworm)2014
CVE-2014-9090 [MEDIUM] CVE-2014-9090: linux - The do_double_fault function in arch/x86/kernel/traps.c in the Linux kernel thro...
The do_double_fault function in arch/x86/kernel/traps.c in the Linux kernel through 3.17.4 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to cause a denial of service (panic) via a modify_ldt system call, as demonstrated by sigreturn_32 in the linux-clock-tests test suite.
Scope: local
bookworm: resolv
debian
CVE-2013-0190P4MEDIUMCVSS 4.9fixed in linux 3.2.39-1 (bookworm)2013
CVE-2013-0190 [MEDIUM] CVE-2013-0190: linux - The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other ...
The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other versions, when running a 32-bit PVOPS guest, allows local users to cause a denial of service (guest crash) by triggering an iret fault, leading to use of an incorrect stack pointer and stack corruption.
Scope: local
bookworm: resolved (fixed in 3.2.39-1)
bullseye: resolved (fixed in 3.2.39
debian
CVE-2013-3076P4LOWCVSS 4.9fixed in linux 3.8.11-1 (bookworm)2013
CVE-2013-3076 [MEDIUM] CVE-2013-3076: linux - The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain l...
The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to the hash_recvmsg function in crypto/algif_hash.c and the skcipher_recvmsg function in crypto/algif_skcipher.c.
Scope: local
bookworm:
debian
CVE-2019-19062P4MEDIUMCVSS 4.7fixed in linux 5.4.6-1 (bookworm)2019
CVE-2019-19062 [MEDIUM] CVE-2019-19062: linux - A memory leak in the crypto_report() function in crypto/crypto_user_base.c in th...
A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
Scope: local
bookworm: resolved (fixed in 5.4.6-1)
bullseye: resolved (fixed in 5.4.6-1)
forky: resolved (fixed in 5.4.6-1)
s
debian
CVE-2013-6380P4MEDIUMCVSS 4.7fixed in linux 3.11.10-1 (bookworm)2013
CVE-2013-6380 [MEDIUM] CVE-2013-6380: linux - The aac_send_raw_srb function in drivers/scsi/aacraid/commctrl.c in the Linux ke...
The aac_send_raw_srb function in drivers/scsi/aacraid/commctrl.c in the Linux kernel through 3.12.1 does not properly validate a certain size value, which allows local users to cause a denial of service (invalid pointer dereference) or possibly have unspecified other impact via an FSACTL_SEND_RAW_SRB ioctl call that triggers a crafted SRB command.
Scope: local
bookwor
debian
CVE-2024-26585P4MEDIUMCVSS 4.7fixed in linux 6.1.85-1 (bookworm)2024
CVE-2024-26585 [MEDIUM] CVE-2024-26585: linux - In the Linux kernel, the following vulnerability has been resolved: tls: fix ra...
In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the submitting thread (recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete(). Reorder scheduling the work before calling complete(). This seems more logical in the first place, as it's th
debian
CVE-2013-4514P4LOWCVSS 4.7fixed in linux 3.12-1 (bookworm)2013
CVE-2013-4514 [MEDIUM] CVE-2013-4514: linux - Multiple buffer overflows in drivers/staging/wlags49_h2/wl_priv.c in the Linux k...
Multiple buffer overflows in drivers/staging/wlags49_h2/wl_priv.c in the Linux kernel before 3.12 allow local users to cause a denial of service or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability and providing a long station-name string, related to the (1) wvlan_uil_put_info and (2) wvlan_set_station_nickname functions.
Scope: local
b
debian
CVE-2024-26583P4MEDIUMCVSS 4.7fixed in linux 6.1.82-1 (bookworm)2024
CVE-2024-26583 [MEDIUM] CVE-2024-26583: linux - In the Linux kernel, the following vulnerability has been resolved: tls: fix ra...
In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close The submitting thread (one which called recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete() so any code past that point risks touching already freed data. Try to avoid the locking and extra flags altogether. Have the main
debian
CVE-2015-5283P4MEDIUMCVSS 4.7fixed in linux 4.2.1-2 (bookworm)2015
CVE-2015-5283 [MEDIUM] CVE-2015-5283: linux - The sctp_init function in net/sctp/protocol.c in the Linux kernel before 4.2.3 h...
The sctp_init function in net/sctp/protocol.c in the Linux kernel before 4.2.3 has an incorrect sequence of protocol-initialization steps, which allows local users to cause a denial of service (panic or memory corruption) by creating SCTP sockets before all of the steps have finished.
Scope: local
bookworm: resolved (fixed in 4.2.1-2)
bullseye: resolved (fixed in 4.2.
debian
CVE-2013-4163P4MEDIUMCVSS 4.7fixed in linux 3.10.5-1 (bookworm)2013
CVE-2013-4163 [MEDIUM] CVE-2013-4163: linux - The ip6_append_data_mtu function in net/ipv6/ip6_output.c in the IPv6 implementa...
The ip6_append_data_mtu function in net/ipv6/ip6_output.c in the IPv6 implementation in the Linux kernel through 3.10.3 does not properly maintain information about whether the IPV6_MTU setsockopt option had been specified, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsocko
debian
CVE-2019-15212P4MEDIUMCVSS 4.6fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-15212 [MEDIUM] CVE-2019-15212: linux - An issue was discovered in the Linux kernel before 5.1.8. There is a double-free...
An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c driver.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in 5.2.6-1)
trixie: resolved (fixed in 5.2.6-1)
debian
CVE-2022-50776P4UNKNOWNfixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50776 CVE-2022-50776: linux - In the Linux kernel, the following vulnerability has been resolved: clk: st: Fi...
In the Linux kernel, the following vulnerability has been resolved: clk: st: Fix memory leak in st_of_quadfs_setup() If st_clk_register_quadfs_pll() fails, @lock should be freed before goto @err_exit, otherwise will cause meory leak issue, fix it.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.4-1)
si
debian
CVE-2023-53825P4UNKNOWNfixed in linux 6.1.55-1 (bookworm)2023
CVE-2023-53825 CVE-2023-53825: linux - In the Linux kernel, the following vulnerability has been resolved: kcm: Fix er...
In the Linux kernel, the following vulnerability has been resolved: kcm: Fix error handling for SOCK_DGRAM in kcm_sendmsg(). syzkaller found a memory leak in kcm_sendmsg(), and commit c821a88bd720 ("kcm: Fix memory leak in error path of kcm_sendmsg()") suppressed it by updating kcm_tx_msg(head)->last_skb if partial data is copied so that the following sendmsg() will resume f
debian
CVE-2022-50660P4UNKNOWNfixed in linux 6.1.20-1 (bookworm)2022
CVE-2022-50660 CVE-2022-50660: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ipw22...
In the Linux kernel, the following vulnerability has been resolved: wifi: ipw2200: fix memory leak in ipw_wdev_init() In the error path of ipw_wdev_init(), exception value is returned, and the memory applied for in the function is not released. Also the memory is not released in ipw_pci_probe(). As a result, memory leakage occurs. So memory release needs to be added to the e
debian
CVE-2026-23038P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2026
CVE-2026-23038 CVE-2026-23038: linux - In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfi...
In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() In nfs4_ff_alloc_deviceid_node(), if the allocation for ds_versions fails, the function jumps to the out_scratch label without freeing the already allocated dsaddrs list, leading to a memory leak. Fix this by jumping to the out_err_drain_dsaddr
debian
CVE-2022-50644P4UNKNOWNfixed in linux 6.0.3-1 (bookworm)2022
CVE-2022-50644 CVE-2022-50644: linux - In the Linux kernel, the following vulnerability has been resolved: clk: ti: dr...
In the Linux kernel, the following vulnerability has been resolved: clk: ti: dra7-atl: Fix reference leak in of_dra7_atl_clk_probe pm_runtime_get_sync() will increment pm usage counter. Forgetting to putting operation will result in reference leak. Add missing pm_runtime_put_sync in some error paths.
Scope: local
bookworm: resolved (fixed in 6.0.3-1)
bullseye: resolved (fixe
debian
CVE-2025-71268P4UNKNOWNfixed in linux 6.1.164-1 (bookworm)2025
CVE-2025-71268 CVE-2025-71268: linux - In the Linux kernel, the following vulnerability has been resolved: btrfs: fix ...
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix reservation leak in some error paths when inserting inline extent If we fail to allocate a path or join a transaction, we return from __cow_file_range_inline() without freeing the reserved qgroup data, resulting in a leak. Fix this by ensuring we call btrfs_qgroup_free_data() in such cases.
Scope:
debian