Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 623 of 632
CVE-2022-41849P4MEDIUMCVSS 4.2fixed in linux 6.0.3-1 (bookworm)2022
CVE-2022-41849 [MEDIUM] CVE-2022-41849: linux - drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race con...
drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and ufx_usb_disconnect.
Scope: local
bookworm: resolved (fixed in 6.0.3-1)
bullseye: resolved (fixed in 5.10.158-1)
forky: resolved
debian
CVE-2020-14416P4MEDIUMCVSS 4.2fixed in linux 5.4.19-1 (bookworm)2020
CVE-2020-14416 [MEDIUM] CVE-2020-14416: linux - In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling i...
In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline could lead to a use-after-free, aka CID-0ace17d56824. This affects drivers/net/slip/slip.c and drivers/net/can/slcan.c.
Scope: local
bookworm: resolved (fixed in 5.4.19-1)
bullseye: resolved (fixed in 5.4.19-1)
forky: resolved (fixed in 5.4.19-1)
sid:
debian
CVE-2020-12652P4MEDIUMCVSS 4.1fixed in linux 5.4.19-1 (bookworm)2020
CVE-2020-12652 [MEDIUM] CVE-2020-12652: linux - The __mptctl_ioctl function in drivers/message/fusion/mptctl.c in the Linux kern...
The __mptctl_ioctl function in drivers/message/fusion/mptctl.c in the Linux kernel before 5.4.14 allows local users to hold an incorrect lock during the ioctl operation and trigger a race condition, i.e., a "double fetch" vulnerability, aka CID-28d76df18f0a. NOTE: the vendor states "The security impact of this bug is not as bad as it could have been because these op
debian
CVE-2014-5471P4MEDIUMCVSS 4.0fixed in linux 3.16.2-1 (bookworm)2014
CVE-2014-5471 [MEDIUM] CVE-2014-5471: linux - Stack consumption vulnerability in the parse_rock_ridge_inode_internal function ...
Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (uncontrolled recursion, and system crash or reboot) via a crafted iso9660 image with a CL entry referring to a directory entry that has a CL entry.
Scope: local
bookworm: resolved (fixed
debian
CVE-2024-42158P4MEDIUMCVSS 4.1fixed in linux 6.9.9-1 (forky)2024
CVE-2024-42158 [MEDIUM] CVE-2024-42158: linux - In the Linux kernel, the following vulnerability has been resolved: s390/pkey: ...
In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Use kfree_sensitive() to fix Coccinelle warnings Replace memzero_explicit() and kfree() with kfree_sensitive() to fix warnings reported by Coccinelle: WARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1506) WARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1643)
debian
CVE-2013-1772P4MEDIUMCVSS 4.0fixed in linux 3.2.39-1 (bookworm)2013
CVE-2013-1772 [MEDIUM] CVE-2013-1772: linux - The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33...
The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.
Scope: local
bookworm: resolved (fixed in 3.2.3
debian
CVE-2016-0823P4MEDIUMCVSS 4.0fixed in linux 4.0.2-1 (bookworm)2016
CVE-2016-0823 [MEDIUM] CVE-2016-0823: linux - The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19....
The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739721.
Scope: local
bookworm: resolved (fixed in 4.0.2-1)
bullseye: resolved (fixed in 4.0.2-1)
forky: resolved (fixed i
debian
CVE-2014-3940P4LOWCVSS 4.0fixed in linux 3.14.7-1 (bookworm)2014
CVE-2014-3940 [MEDIUM] CVE-2014-3940: linux - The Linux kernel through 3.14.5 does not properly consider the presence of huget...
The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a race condition via numa_maps read operations during hugepage migration, related to fs/proc/task_mmu.c and mm/mempolic
debian
CVE-2020-29374P4LOWCVSS 3.6fixed in linux 5.7.6-1 (bookworm)2020
CVE-2020-29374 [LOW] CVE-2020-29374: linux - An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c an...
An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58.
Scope: local
bookworm: resolved (fixed in 5.7.6-1)
bullseye
debian
CVE-2012-2390P4LOWCVSS 4.9fixed in linux 3.2.19-1 (bookworm)2012
CVE-2012-2390 [MEDIUM] CVE-2012-2390: linux - Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users ...
Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users to cause a denial of service (memory consumption or system crash) via invalid MAP_HUGETLB mmap operations.
Scope: local
bookworm: resolved (fixed in 3.2.19-1)
bullseye: resolved (fixed in 3.2.19-1)
forky: resolved (fixed in 3.2.19-1)
sid: resolved (fixed in 3.2.19-1)
trixie: resolved (fixe
debian
CVE-2014-7843P4MEDIUMCVSS 4.9fixed in linux 3.16.7-ckt2-1 (bookworm)2014
CVE-2014-7843 [MEDIUM] CVE-2014-7843: linux - The __clear_user function in arch/arm64/lib/clear_user.S in the Linux kernel bef...
The __clear_user function in arch/arm64/lib/clear_user.S in the Linux kernel before 3.17.4 on the ARM64 platform allows local users to cause a denial of service (system crash) by reading one byte beyond a /dev/zero page boundary.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt2-1)
bullseye: resolved (fixed in 3.16.7-ckt2-1)
forky: resolved (fixed in 3.16.7-ckt2-1
debian
CVE-2013-2146P4MEDIUMCVSS 4.7fixed in linux 3.9.4-1 (bookworm)2013
CVE-2013-2146 [MEDIUM] CVE-2013-2146: linux - arch/x86/kernel/cpu/perf_event_intel.c in the Linux kernel before 3.8.9, when th...
arch/x86/kernel/cpu/perf_event_intel.c in the Linux kernel before 3.8.9, when the Performance Events Subsystem is enabled, specifies an incorrect bitmask, which allows local users to cause a denial of service (general protection fault and system crash) by attempting to set a reserved bit.
Scope: local
bookworm: resolved (fixed in 3.9.4-1)
bullseye: resolved (fixed in
debian
CVE-2019-15921P4MEDIUMCVSS 4.7fixed in linux 4.19.37-1 (bookworm)2019
CVE-2019-15921 [MEDIUM] CVE-2019-15921: linux - An issue was discovered in the Linux kernel before 5.0.6. There is a memory leak...
An issue was discovered in the Linux kernel before 5.0.6. There is a memory leak issue when idr_alloc() fails in genl_register_family() in net/netlink/genetlink.c.
Scope: local
bookworm: resolved (fixed in 4.19.37-1)
bullseye: resolved (fixed in 4.19.37-1)
forky: resolved (fixed in 4.19.37-1)
sid: resolved (fixed in 4.19.37-1)
trixie: resolved (fixed in 4.19.37-1)
debian
CVE-2013-4205P4MEDIUMCVSS 4.7fixed in linux 3.10.7-1 (bookworm)2013
CVE-2013-4205 [MEDIUM] CVE-2013-4205: linux - Memory leak in the unshare_userns function in kernel/user_namespace.c in the Lin...
Memory leak in the unshare_userns function in kernel/user_namespace.c in the Linux kernel before 3.10.6 allows local users to cause a denial of service (memory consumption) via an invalid CLONE_NEWUSER unshare call.
Scope: local
bookworm: resolved (fixed in 3.10.7-1)
bullseye: resolved (fixed in 3.10.7-1)
forky: resolved (fixed in 3.10.7-1)
sid: resolved (fixed in 3.1
debian
CVE-2013-6431P4LOWCVSS 4.7fixed in linux 3.11.5-1 (bookworm)2013
CVE-2013-6431 [MEDIUM] CVE-2013-6431: linux - The fib6_add function in net/ipv6/ip6_fib.c in the Linux kernel before 3.11.5 do...
The fib6_add function in net/ipv6/ip6_fib.c in the Linux kernel before 3.11.5 does not properly implement error-code encoding, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for an IPv6 SIOCADDRT ioctl call.
Scope: local
bookworm: resolved (fixed in 3.11.5-1)
bullseye: resolv
debian
CVE-2022-50707P4UNKNOWNfixed in linux 6.1.7-1 (bookworm)2022
CVE-2022-50707 CVE-2022-50707: linux - In the Linux kernel, the following vulnerability has been resolved: virtio-cryp...
In the Linux kernel, the following vulnerability has been resolved: virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session() 'vc_ctrl_req' is alloced in virtio_crypto_alg_skcipher_close_session(), and should be freed in the invalid ctrl_status->status error handling case. Otherwise there is a memory leak.
Scope: local
bookworm: resolved (fixed in 6.1.7-1)
debian
CVE-2014-4508P4MEDIUMCVSS 4.7fixed in linux 3.14.9-1 (bookworm)2014
CVE-2014-4508 [MEDIUM] CVE-2014-4508: linux - arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on 32-bit x86 plat...
arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on 32-bit x86 platforms, when syscall auditing is enabled and the sep CPU feature flag is set, allows local users to cause a denial of service (OOPS and system crash) via an invalid syscall number, as demonstrated by number 1000.
Scope: local
bookworm: resolved (fixed in 3.14.9-1)
bullseye: resolved (fixed
debian
CVE-2015-7509P4MEDIUMCVSS 4.7fixed in linux 3.8-1~experimental.1 (bookworm)2015
CVE-2015-7509 [MEDIUM] CVE-2015-7509: linux - fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attac...
fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.
Scope: local
bookworm: resolved (fixed in 3.8-1~experimental.1)
bullseye: resolved (fixed in 3.8-1~experimental.1)
forky: resolved (fixed in 3.8-1~experimental.1)
sid: re
debian
CVE-2014-2678P4MEDIUMCVSS 4.7fixed in linux 3.13.10-1 (bookworm)2014
CVE-2014-2678 [MEDIUM] CVE-2014-2678: linux - The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through 3.14...
The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through 3.14 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a bind system call for an RDS socket on a system that lacks RDS transports.
Scope: local
bookworm: resolved (fixed in 3.13.10-1)
bullseye: resolved (fi
debian
CVE-2012-2745P4MEDIUMCVSS 4.7fixed in linux 3.2.15-1 (bookworm)2012
CVE-2012-2745 [MEDIUM] CVE-2012-2745: linux - The copy_creds function in kernel/cred.c in the Linux kernel before 3.3.2 provid...
The copy_creds function in kernel/cred.c in the Linux kernel before 3.3.2 provides an invalid replacement session keyring to a child process, which allows local users to cause a denial of service (panic) via a crafted application that uses the fork system call.
Scope: local
bookworm: resolved (fixed in 3.2.15-1)
bullseye: resolved (fixed in 3.2.15-1)
forky: resolved (
debian