Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 618 of 632
CVE-2015-1333P4MEDIUMCVSS 4.9fixed in linux 4.1.3-1 (bookworm)2015
CVE-2015-1333 [MEDIUM] CVE-2015-1333: linux - Memory leak in the __key_link_end function in security/keys/keyring.c in the Lin...
Memory leak in the __key_link_end function in security/keys/keyring.c in the Linux kernel before 4.1.4 allows local users to cause a denial of service (memory consumption) via many add_key system calls that refer to existing keys.
Scope: local
bookworm: resolved (fixed in 4.1.3-1)
bullseye: resolved (fixed in 4.1.3-1)
forky: resolved (fixed in 4.1.3-1)
sid: resolved (
debian
CVE-2013-7268P4MEDIUMCVSS 4.9fixed in linux 3.12.6-1 (bookworm)2013
CVE-2013-7268 [MEDIUM] CVE-2013-7268: linux - The ipx_recvmsg function in net/ipx/af_ipx.c in the Linux kernel before 3.12.4 u...
The ipx_recvmsg function in net/ipx/af_ipx.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.
Scope: local
bookworm: resolved (fixed in 3.12.6-
debian
CVE-2014-9730P4MEDIUMCVSS 4.9fixed in linux 3.16.7-ckt4-1 (bookworm)2014
CVE-2014-9730 [MEDIUM] CVE-2014-9730: linux - The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18....
The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are unused, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt4-1)
bullseye: resolved (fixed in 3.16.7-ckt4-1)
forky: resolved (fixed in 3.16.7-ckt4
debian
CVE-2015-6526P4MEDIUMCVSS 4.9fixed in linux 4.1.3-1 (bookworm)2015
CVE-2015-6526 [MEDIUM] CVE-2015-6526: linux - The perf_callchain_user_64 function in arch/powerpc/perf/callchain.c in the Linu...
The perf_callchain_user_64 function in arch/powerpc/perf/callchain.c in the Linux kernel before 4.0.2 on ppc64 platforms allows local users to cause a denial of service (infinite loop) via a deep 64-bit userspace backtrace.
Scope: local
bookworm: resolved (fixed in 4.1.3-1)
bullseye: resolved (fixed in 4.1.3-1)
forky: resolved (fixed in 4.1.3-1)
sid: resolved (fixed i
debian
CVE-2013-3222P4LOWCVSS 4.9fixed in linux 3.8.11-1 (bookworm)2013
CVE-2013-3222 [MEDIUM] CVE-2013-3222: linux - The vcc_recvmsg function in net/atm/common.c in the Linux kernel before 3.9-rc7 ...
The vcc_recvmsg function in net/atm/common.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
Scope: local
bookworm: resolved (fixed in 3.8.11-1)
bullseye: resolved (fixed in 3.8.11-1)
forky: resolved (fixed
debian
CVE-2013-3228P4LOWCVSS 4.9fixed in linux 3.8.11-1 (bookworm)2013
CVE-2013-3228 [MEDIUM] CVE-2013-3228: linux - The irda_recvmsg_dgram function in net/irda/af_irda.c in the Linux kernel before...
The irda_recvmsg_dgram function in net/irda/af_irda.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
Scope: local
bookworm: resolved (fixed in 3.8.11-1)
bullseye: resolved (fixed in 3.8.11-1)
forky: resolve
debian
CVE-2013-3227P4LOWCVSS 4.9fixed in linux 3.8.11-1 (bookworm)2013
CVE-2013-3227 [MEDIUM] CVE-2013-3227: linux - The caif_seqpkt_recvmsg function in net/caif/caif_socket.c in the Linux kernel b...
The caif_seqpkt_recvmsg function in net/caif/caif_socket.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
Scope: local
bookworm: resolved (fixed in 3.8.11-1)
bullseye: resolved (fixed in 3.8.11-1)
forky: re
debian
CVE-2013-3229P4LOWCVSS 4.9fixed in linux 3.8.11-1 (bookworm)2013
CVE-2013-3229 [MEDIUM] CVE-2013-3229: linux - The iucv_sock_recvmsg function in net/iucv/af_iucv.c in the Linux kernel before ...
The iucv_sock_recvmsg function in net/iucv/af_iucv.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
Scope: local
bookworm: resolved (fixed in 3.8.11-1)
bullseye: resolved (fixed in 3.8.11-1)
forky: resolved
debian
CVE-2013-3225P4LOWCVSS 4.9fixed in linux 3.8.11-1 (bookworm)2013
CVE-2013-3225 [MEDIUM] CVE-2013-3225: linux - The rfcomm_sock_recvmsg function in net/bluetooth/rfcomm/sock.c in the Linux ker...
The rfcomm_sock_recvmsg function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
Scope: local
bookworm: resolved (fixed in 3.8.11-1)
bullseye: resolved (fixed in 3.8.11-1)
fork
debian
CVE-2019-19065P4MEDIUMCVSS 4.7fixed in linux 5.3.9-1 (bookworm)2019
CVE-2019-19065 [MEDIUM] CVE-2019-19065: linux - A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c i...
A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering rhashtable_init() failures, aka CID-34b3be18a04e. NOTE: This has been disputed as not a vulnerability because "rhashtable_init() can only fail if it is passed invalid values i
debian
CVE-2012-4565P4MEDIUMCVSS 4.7fixed in linux 3.2.35-1 (bookworm)2012
CVE-2012-4565 [MEDIUM] CVE-2012-4565: linux - The tcp_illinois_info function in net/ipv4/tcp_illinois.c in the Linux kernel be...
The tcp_illinois_info function in net/ipv4/tcp_illinois.c in the Linux kernel before 3.4.19, when the net.ipv4.tcp_congestion_control illinois setting is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) by reading TCP stats.
Scope: local
bookworm: resolved (fixed in 3.2.35-1)
bullseye: resolved (fixed in 3.2.35-1)
forky: resolve
debian
CVE-2013-7339P4MEDIUMCVSS 4.7fixed in linux 3.13-1 (bookworm)2013
CVE-2013-7339 [MEDIUM] CVE-2013-7339: linux - The rds_ib_laddr_check function in net/rds/ib.c in the Linux kernel before 3.12....
The rds_ib_laddr_check function in net/rds/ib.c in the Linux kernel before 3.12.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a bind system call for an RDS socket on a system that lacks RDS transports.
Scope: local
bookworm: resolved (fixed in 3.13-1)
bullseye: resolved (fixe
debian
CVE-2022-50836P4UNKNOWNfixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50836 CVE-2022-50836: linux - In the Linux kernel, the following vulnerability has been resolved: remoteproc:...
In the Linux kernel, the following vulnerability has been resolved: remoteproc: sysmon: fix memory leak in qcom_add_sysmon_subdev() The kfree() should be called when of_irq_get_byname() fails or devm_request_threaded_irq() fails in qcom_add_sysmon_subdev(), otherwise there will be a memory leak, so add kfree() to fix it.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bul
debian
CVE-2022-50629P4UNKNOWNfixed in linux 6.1.20-1 (bookworm)2022
CVE-2022-50629 CVE-2022-50629: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: ...
In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: Fix memory leak in rsi_coex_attach() The coex_cb needs to be freed when rsi_create_kthread() failed in rsi_coex_attach().
Scope: local
bookworm: resolved (fixed in 6.1.20-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.20-1)
sid: resolved (fixed in 6.1.20-1)
trixie: resol
debian
CVE-2019-16994P4MEDIUMCVSS 4.7fixed in linux 4.19.28-1 (bookworm)2019
CVE-2019-16994 [MEDIUM] CVE-2019-16994: linux - In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ip...
In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev, which may cause denial of service, aka CID-07f12b26e21a.
Scope: local
bookworm: resolved (fixed in 4.19.28-1)
bullseye: resolved (fixed in 4.19.28-1)
forky: resolved (fixed in 4.19.28-1)
sid: resolved (fixed in 4.19.2
debian
CVE-2019-19054P4LOWCVSS 4.7fixed in linux 5.5.13-1 (bookworm)2019
CVE-2019-19054 [MEDIUM] CVE-2019-19054: linux - A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx...
A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures, aka CID-a7b2df76b42b.
Scope: local
bookworm: resolved (fixed in 5.5.13-1)
bullseye: resolved (fixed in 5.5.13-1)
forky: resolved (fixed i
debian
CVE-2023-54106P4UNKNOWNfixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-54106 CVE-2023-54106: linux - In the Linux kernel, the following vulnerability has been resolved: net/mlx5: f...
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fix potential memory leak in mlx5e_init_rep_rx The memory pointed to by the priv->rx_res pointer is not freed in the error path of mlx5e_init_rep_rx, which can lead to a memory leak. Fix by freeing the memory in the error path, thereby making the error path identical to mlx5e_cleanup_rep_rx().
Scop
debian
CVE-2023-54275P4UNKNOWNfixed in linux 6.1.20-1 (bookworm)2023
CVE-2023-54275 CVE-2023-54275: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath11...
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Fix memory leak in ath11k_peer_rx_frag_setup crypto_alloc_shash() allocates resources, which should be released by crypto_free_shash(). When ath11k_peer_find() fails, there has memory leak. Add missing crypto_free_shash() to fix this.
Scope: local
bookworm: resolved (fixed in 6.1.20-1)
bullseye
debian
CVE-2023-54169P4UNKNOWNfixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-54169 CVE-2023-54169: linux - In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: ...
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix memory leak in mlx5e_ptp_open When kvzalloc_node or kvzalloc failed in mlx5e_ptp_open, the memory pointed by "c" or "cparams" is not freed, which can lead to a memory leak. Fix by freeing the array in the error path.
Scope: local
bookworm: resolved (fixed in 6.1.52-1)
bullseye: resolved
forky:
debian
CVE-2026-23058P4UNKNOWNfixed in linux 6.1.162-1 (bookworm)2026
CVE-2026-23058 CVE-2026-23058: linux - In the Linux kernel, the following vulnerability has been resolved: can: ems_us...
In the Linux kernel, the following vulnerability has been resolved: can: ems_usb: ems_usb_read_bulk_callback(): fix URB memory leak Fix similar memory leak as in commit 7352e1d5932a ("can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak"). In ems_usb_open(), the URBs for USB-in transfers are allocated, added to the dev->rx_submitted anchor and submitted. In the c
debian