cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 6 of 632
CVE-2019-9162P3HIGHCVSS 7.8PoCfixed in linux 4.19.28-1 (bookworm)2019
CVE-2019-9162 [HIGH] CVE-2019-9162: linux - In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c ... In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local privilege escalation. This affects snmp_version and snmp_helper. Scope: local bookworm: resolved (fixed in 4.19.28-1) b
debian
CVE-2019-19241P3HIGHCVSS 7.8PoCfixed in linux 5.3.15-1 (bookworm)2019
CVE-2019-19241 [HIGH] CVE-2019-19241: linux - In the Linux kernel before 5.4.2, the io_uring feature leads to requests that in... In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabilities, aka CID-181e448d8709. This is related to fs/io-wq.c, fs/io_uring.c, and net/socket.c. For example, an attacker can bypass intended restrictions on adding an IPv4 address to the loopback interface. This occurs because IORING_OP_SENDMSG operation
debian
CVE-2016-1576P3HIGHCVSS 7.8PoCfixed in linux 4.5.1-1 (bookworm)2016
CVE-2016-1576 [HIGH] CVE-2016-1576: linux - The overlayfs implementation in the Linux kernel through 4.5.2 does not properly... The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program. Scope: local bookworm: resolved (fixed in 4.5.1-1) bullseye: resolved (fixed in 4.5.1-1) forky: resolved (f
debian
CVE-2016-2854P3HIGHCVSS 7.8PoCfixed in linux 3.18-1~exp1 (bookworm)2016
CVE-2016-2854 [HIGH] CVE-2016-2854: linux - The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSI... The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory. Scope: local bookworm: resolved (fixed in 3.18-1~exp1) bullseye: resolved (fixed in 3.18-1~exp1) forky: resolved (fixed in 3.18-1~exp1) sid: resolved (fixed in 3.18-1~exp1) trixie:
debian
CVE-2016-1575P3HIGHCVSS 7.8PoCfixed in linux 4.5.1-1 (bookworm)2016
CVE-2016-1575 [HIGH] CVE-2016-1575: linux - The overlayfs implementation in the Linux kernel through 4.5.2 does not properly... The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory. Scope: local bookworm: resolved (fixed in 4.5.1-1) bullseye: resolved (fixed in 4.5.1-1) forky: resolved (fixed in 4.5.1-1) sid: resolved (fixed in 4.5.1-1) trixie: re
debian
CVE-2016-2853P3HIGHCVSS 7.8PoCfixed in linux 3.18-1~exp1 (bookworm)2016
CVE-2016-2853 [HIGH] CVE-2016-2853: linux - The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the ... The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program. Scope: local bookworm: resolved (fixed in 3.18-1~exp1) bullseye: resolved (fixed in 3.18-1~exp1) forky: resolved (fixed in 3.1
debian
CVE-2025-37928P3HIGHCVSS 7.8PoCfixed in linux 6.1.140-1 (bookworm)2025
CVE-2025-37928 [HIGH] CVE-2025-37928: linux - In the Linux kernel, the following vulnerability has been resolved: dm-bufio: d... In the Linux kernel, the following vulnerability has been resolved: dm-bufio: don't schedule in atomic context A BUG was reported as below when CONFIG_DEBUG_ATOMIC_SLEEP and try_verify_in_tasklet are enabled. [ 129.444685][ T934] BUG: sleeping function called from invalid context at drivers/md/dm-bufio.c:2421 [ 129.444723][ T934] in_atomic(): 1, irqs_disabled(): 0, no
debian
CVE-2018-13405P3HIGHCVSS 7.8PoCfixed in linux 4.17.6-1 (bookworm)2018
CVE-2018-13405 [HIGH] CVE-2018-13405: linux - The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 all... The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is that group. The int
debian
CVE-2017-11176P3HIGHCVSS 7.8PoCfixed in linux 4.11.11-1 (bookworm)2017
CVE-2017-11176 [HIGH] CVE-2017-11176: linux - The mq_notify function in the Linux kernel through 4.11.9 does not set the sock ... The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 4.11.11-1) bullseye: resolved (fixed in 4.1
debian
CVE-2017-5754P3MEDIUMCVSS 5.6fixed in linux 4.14.12-1 (bookworm)2017
CVE-2017-5754 [MEDIUM] CVE-2017-5754: linux - Systems with microprocessors utilizing speculative execution and indirect branch... Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache. Scope: local bookworm: resolved (fixed in 4.14.12-1) bullseye: resolved (fixed in 4.14.12-1) forky: resolved (fixed in 4.14.12-1) sid: resolved
debian
CVE-2016-3672P3HIGHCVSS 7.8PoCfixed in linux 4.5.1-1 (bookworm)2016
CVE-2016-3672 [HIGH] CVE-2016-3672: linux - The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel thr... The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and bypass the ASLR protection mechanism for a setuid or setgid program, by disabling stack-consumption resource limits. Sc
debian
CVE-2016-3135P3HIGHCVSS 7.8PoCfixed in linux 4.4.6-1 (bookworm)2016
CVE-2016-3135 [HIGH] CVE-2016-3135: linux - Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c... Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call. Scope: local bookworm: resolved (fixed in 4.4.6-1) bullseye: resolved (fixed in 4.4.6-1) forky: resolv
debian
CVE-2024-8805P2HIGHCVSS 8.8fixed in linux 6.1.115-1 (bookworm)2024
CVE-2024-8805 [HIGH] CVE-2024-8805: linux - BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulner... BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the HID over GATT Profile. The issue results from th
debian
CVE-2016-9793P3HIGHCVSS 7.8PoCfixed in linux 4.8.15-1 (bookworm)2016
CVE-2016-9793 [HIGH] CVE-2016-9793: linux - The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.1... The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability for a crafted setsockopt system call with the (1) SO_SNDBUF
debian
CVE-2024-26594P3HIGHCVSS 7.1fixed in linux 6.1.76-1 (bookworm)2024
CVE-2024-26594 [HIGH] CVE-2024-26594: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: vali... In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session setup request, ksmbd validate and make the error if it is invalid. Scope: local bookworm: resolved (fixed in 6.1.76-1) bullseye: resolved forky: resolved (fixed in 6.6.15-1) sid: resolved (fixed in 6.6.15-1) trixi
debian
CVE-2023-52755P3HIGHCVSS 8.4fixed in linux 6.1.64-1 (bookworm)2023
CVE-2023-52755 [HIGH] CVE-2023-52755: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ... In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab out of bounds write in smb_inherit_dacl() slab out-of-bounds write is caused by that offsets is bigger than pntsd allocation size. This patch add the check to validate 3 offsets using allocation size. Scope: local bookworm: resolved (fixed in 6.1.64-1) bullseye: resolved forky: resolve
debian
CVE-2015-8812P3CRITICALCVSS 9.8fixed in linux 4.4.2-1 (bookworm)2015
CVE-2015-8812 [CRITICAL] CVE-2015-8812: linux - drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not pr... drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: resolved (fixed in 4.4.2-1) forky: resolved (fixed in 4.4.2-1) sid: re
debian
CVE-2023-52440P3HIGHCVSS 7.8fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-52440 [HIGH] CVE-2023-52440: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ... In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE), slub overflow can happen in key exchange codes. cifs_arc4_crypt copy to session key array from SessionKey from client. Scope: local bookworm: resolved (fixed in 6
debian
CVE-2021-47337P4MEDIUMCVSS 5.5Exploitedfixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-47337 [MEDIUM] CVE-2021-47337: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: core:... In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix bad pointer dereference when ehandler kthread is invalid Commit 66a834d09293 ("scsi: core: Fix error handling of scsi_host_alloc()") changed the allocation logic to call put_device() to perform host cleanup with the assumption that IDA removal and stopping the kthread would properly
debian
CVE-2020-12352P3MEDIUMCVSS 6.5PoCfixed in linux 5.9.1-1 (bookworm)2020
CVE-2020-12352 [MEDIUM] CVE-2020-12352: linux - Improper access control in BlueZ may allow an unauthenticated user to potentiall... Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access. Scope: local bookworm: resolved (fixed in 5.9.1-1) bullseye: resolved (fixed in 5.9.1-1) forky: resolved (fixed in 5.9.1-1) sid: resolved (fixed in 5.9.1-1) trixie: resolved (fixed in 5.9.1-1)
debian
Debian Linux vulnerabilities | cvebase