cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 617 of 632
CVE-2019-19073P4MEDIUMCVSS 4.0fixed in linux 5.4.6-1 (bookworm)2019
CVE-2019-19073 [MEDIUM] CVE-2019-19073: linux - Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel thr... Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering wait_for_completion_timeout() failures. This affects the htc_config_pipe_credits() function, the htc_setup_complete() function, and the htc_connect_service() function, aka CID-853acf7caf10. Scope:
debian
CVE-2015-8575P4MEDIUMCVSS 4.0fixed in linux 4.3.3-3 (bookworm)2015
CVE-2015-8575 [MEDIUM] CVE-2015-8575: linux - The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3... The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted application. Scope: local bookworm: resolved (fixed in 4.3.3-3) bullseye: resolved (fixed in 4.3.3-3) forky: resolved (f
debian
CVE-2024-42156P4MEDIUMCVSS 4.1fixed in linux 6.9.9-1 (forky)2024
CVE-2024-42156 [MEDIUM] CVE-2024-42156: linux - In the Linux kernel, the following vulnerability has been resolved: s390/pkey: ... In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Wipe copies of clear-key structures on failure Wipe all sensitive data from stack for all IOCTLs, which convert a clear-key into a protected- or secure-key. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 6.9.9-1) sid: resolved (fixed in 6.9.9-1) trixie: resolved (fix
debian
CVE-2021-4001P4MEDIUMCVSS 4.1fixed in linux 5.15.5-1 (bookworm)2021
CVE-2021-4001 [MEDIUM] CVE-2021-4001: linux - A race condition was found in the Linux kernel's ebpf verifier between bpf_map_u... A race condition was found in the Linux kernel's ebpf verifier between bpf_map_update_elem and bpf_map_freeze due to a missing lock in kernel/bpf/syscall.c. In this flaw, a local user with a special privilege (cap_sys_admin or cap_bpf) can modify the frozen mapped address space. This flaw affects kernel versions prior to 5.16 rc2. Scope: local bookworm: resolved (fixe
debian
CVE-2021-39648P4MEDIUMCVSS 4.1fixed in linux 5.10.9-1 (bookworm)2021
CVE-2021-39648 [MEDIUM] CVE-2021-39648: linux - In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of ker... In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-160822094References: Upstream kernel Scope: local bookwo
debian
CVE-2021-47096P4MEDIUMCVSS 4.0fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-47096 [MEDIUM] CVE-2021-47096: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: rawmi... In the Linux kernel, the following vulnerability has been resolved: ALSA: rawmidi - fix the uninitalized user_pversion The user_pversion was uninitialized for the user space file structure in the open function, because the file private structure use kmalloc for the allocation. The kernel ALSA sequencer code clears the file structure, so no additional fixes are requi
debian
CVE-2022-3619P4LOWCVSS 3.5fixed in linux 6.0.8-1 (bookworm)2022
CVE-2022-3619 [LOW] CVE-2022-3619: linux - A vulnerability has been found in Linux Kernel and classified as problematic. Th... A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. VDB-211918 is the identifier assigned to this vulnerability. Scope: local bo
debian
CVE-2020-24587P4LOWCVSS 2.6fixed in firmware-nonfree 20210818-1 (bookworm)2020
CVE-2020-24587 [LOW] CVE-2020-24587: firmware-nonfree - The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) ... The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renew
debian
CVE-2023-7192P4MEDIUMCVSS 5.5fixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-7192 [MEDIUM] CVE-2023-7192: linux - A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/n... A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to cause a denial of service (DoS) attack due to a refcount overflow. Scope: local bookworm: resolved (fixed in 6.1.20-1) bullseye: resolved (fixed in 5.10.178-1) forky: resolved
debian
CVE-2024-40934P4MEDIUMCVSS 5.5fixed in linux 6.1.99-1 (bookworm)2024
CVE-2024-40934 [MEDIUM] CVE-2024-40934: linux - In the Linux kernel, the following vulnerability has been resolved: HID: logite... In the Linux kernel, the following vulnerability has been resolved: HID: logitech-dj: Fix memory leak in logi_dj_recv_switch_to_dj_mode() Fix a memory leak on logi_dj_recv_send_report() error path. Scope: local bookworm: resolved (fixed in 6.1.99-1) bullseye: resolved (fixed in 5.10.221-1) forky: resolved (fixed in 6.9.7-1) sid: resolved (fixed in 6.9.7-1) trixie: r
debian
CVE-2021-47052P4MEDIUMCVSS 5.5fixed in linux 5.10.38-1 (bookworm)2021
CVE-2021-47052 [MEDIUM] CVE-2021-47052: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: sa2... In the Linux kernel, the following vulnerability has been resolved: crypto: sa2ul - Fix memory leak of rxd There are two error return paths that are not freeing rxd and causing memory leaks. Fix these. Addresses-Coverity: ("Resource leak") Scope: local bookworm: resolved (fixed in 5.10.38-1) bullseye: resolved (fixed in 5.10.38-1) forky: resolved (fixed in 5.10.38-1
debian
CVE-2021-47059P4MEDIUMCVSS 5.5fixed in linux 5.10.38-1 (bookworm)2021
CVE-2021-47059 [MEDIUM] CVE-2021-47059: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: sun... In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ss - fix result memory leak on error path This patch fixes a memory leak on an error path. Scope: local bookworm: resolved (fixed in 5.10.38-1) bullseye: resolved (fixed in 5.10.38-1) forky: resolved (fixed in 5.10.38-1) sid: resolved (fixed in 5.10.38-1) trixie: resolved (fixed in 5.1
debian
CVE-2020-36786P4MEDIUMCVSS 5.5fixed in linux 5.10.38-1 (bookworm)2020
CVE-2020-36786 [MEDIUM] CVE-2020-36786: linux - In the Linux kernel, the following vulnerability has been resolved: media: [nex... In the Linux kernel, the following vulnerability has been resolved: media: [next] staging: media: atomisp: fix memory leak of object flash In the case where the call to lm3554_platform_data_func returns an error there is a memory leak on the error return path of object flash. Fix this by adding an error return path that will free flash and rename labels fail2 to fai
debian
CVE-2022-50025P4MEDIUMCVSS 5.5fixed in linux 6.0.2-1 (bookworm)2022
CVE-2022-50025 [MEDIUM] CVE-2022-50025: linux - In the Linux kernel, the following vulnerability has been resolved: cxl: Fix a ... In the Linux kernel, the following vulnerability has been resolved: cxl: Fix a memory leak in an error handling path A bitmap_zalloc() must be balanced by a corresponding bitmap_free() in the error handling path of afu_allocate_irqs(). Scope: local bookworm: resolved (fixed in 6.0.2-1) bullseye: resolved (fixed in 5.10.140-1) forky: resolved (fixed in 6.0.2-1) sid:
debian
CVE-2022-50324P4MEDIUMCVSS 5.5fixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50324 [MEDIUM] CVE-2022-50324: linux - In the Linux kernel, the following vulnerability has been resolved: mtd: maps: ... In the Linux kernel, the following vulnerability has been resolved: mtd: maps: pxa2xx-flash: fix memory leak in probe Free 'info' upon remapping error to avoid a memory leak. [: Reword the commit log] Scope: local bookworm: resolved (fixed in 6.1.4-1) bullseye: resolved (fixed in 5.10.178-1) forky: resolved (fixed in 6.1.4-1) sid: resolved (fixed in 6.1.4-1) trixie:
debian
CVE-2022-50264P4MEDIUMCVSS 5.5fixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50264 [MEDIUM] CVE-2022-50264: linux - In the Linux kernel, the following vulnerability has been resolved: clk: socfpg... In the Linux kernel, the following vulnerability has been resolved: clk: socfpga: Fix memory leak in socfpga_gate_init() Free @socfpga_clk and @ops on the error path to avoid memory leak issue. Scope: local bookworm: resolved (fixed in 6.1.4-1) bullseye: resolved (fixed in 5.10.178-1) forky: resolved (fixed in 6.1.4-1) sid: resolved (fixed in 6.1.4-1) trixie: resolv
debian
CVE-2013-2232P4MEDIUMCVSS 4.9fixed in linux 3.10.1-1 (bookworm)2013
CVE-2013-2232 [MEDIUM] CVE-2013-2232: linux - The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel befor... The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel before 3.10 allows local users to cause a denial of service (system crash) by using an AF_INET6 socket for a connection to an IPv4 interface. Scope: local bookworm: resolved (fixed in 3.10.1-1) bullseye: resolved (fixed in 3.10.1-1) forky: resolved (fixed in 3.10.1-1) sid: resolved (fixed in 3.
debian
CVE-2014-3122P4MEDIUMCVSS 4.9fixed in linux 3.14.4-1 (bookworm)2014
CVE-2014-3122 [MEDIUM] CVE-2014-3122: linux - The try_to_unmap_cluster function in mm/rmap.c in the Linux kernel before 3.14.3... The try_to_unmap_cluster function in mm/rmap.c in the Linux kernel before 3.14.3 does not properly consider which pages must be locked, which allows local users to cause a denial of service (system crash) by triggering a memory-usage pattern that requires removal of page-table mappings. Scope: local bookworm: resolved (fixed in 3.14.4-1) bullseye: resolved (fixed in 3
debian
CVE-2012-6657P4MEDIUMCVSS 4.9fixed in linux 3.6.4-1 (bookworm)2012
CVE-2012-6657 [MEDIUM] CVE-2012-6657: linux - The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7... The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket. Scope: local bookworm: resolved (fixed in 3.6.4-1) bullseye: resolved (fixed in 3.6.4-1) forky
debian
CVE-2013-4483P4LOWCVSS 4.9fixed in linux 3.11.8-1 (bookworm)2013
CVE-2013-4483 [MEDIUM] CVE-2013-4483: linux - The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does n... The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does not properly manage a reference count, which allows local users to cause a denial of service (memory consumption or system crash) via a crafted application. Scope: local bookworm: resolved (fixed in 3.11.8-1) bullseye: resolved (fixed in 3.11.8-1) forky: resolved (fixed in 3.11.8-1) sid: re
debian
Debian Linux vulnerabilities | cvebase