Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 627 of 632
CVE-2020-36766P4LOWCVSS 3.3fixed in linux 5.8.7-1 (bookworm)2020
CVE-2020-36766 [LOW] CVE-2020-36766: linux - An issue was discovered in the Linux kernel before 5.8.6. drivers/media/cec/core...
An issue was discovered in the Linux kernel before 5.8.6. drivers/media/cec/core/cec-api.c leaks one byte of kernel memory on specific hardware to unprivileged users, because of directly assigning log_addrs with a hole in the struct.
Scope: local
bookworm: resolved (fixed in 5.8.7-1)
bullseye: resolved (fixed in 5.8.7-1)
forky: resolved (fixed in 5.8.7-1)
sid: resolved
debian
CVE-2024-46792P4LOWCVSS 3.3fixed in linux 6.10.11-1 (forky)2024
CVE-2024-46792 [LOW] CVE-2024-46792: linux - In the Linux kernel, the following vulnerability has been resolved: riscv: misa...
In the Linux kernel, the following vulnerability has been resolved: riscv: misaligned: Restrict user access to kernel memory raw_copy_{to,from}_user() do not call access_ok(), so this code allowed userspace to access any virtual memory address.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.10.11-1)
sid: resolved (fixed in 6.10.11-1)
tri
debian
CVE-2014-0131P4LOWCVSS 2.9fixed in linux 3.13.6-1 (bookworm)2014
CVE-2014-0131 [LOW] CVE-2014-0131: linux - Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in...
Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation.
Scope: local
bookworm: resolved (fixed in 3.13.6-1)
bullseye: resolved (fixed in 3.13.6-1)
forky: resolved (fixed in 3.13.6-1)
sid:
debian
CVE-2024-26652P4LOWCVSS 4.1fixed in linux 6.7.12-1 (forky)2024
CVE-2024-26652 [MEDIUM] CVE-2024-26652: linux - In the Linux kernel, the following vulnerability has been resolved: net: pds_co...
In the Linux kernel, the following vulnerability has been resolved: net: pds_core: Fix possible double free in error handling path When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), Callback function pdsc_auxbus_dev_release calls kfree(padev) to free memory. We shouldn't call kfree(padev) again in the error handling path. Fix this by
debian
CVE-2023-52862P4LOWCVSS 4.1fixed in linux 6.6.8-1 (forky)2023
CVE-2023-52862 [MEDIUM] CVE-2023-52862: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amd/dis...
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix null pointer dereference in error message This patch fixes a null pointer dereference in the error message that is printed when the Display Core (DC) fails to initialize. The original message includes the DC version number, which is undefined if the DC is not initialized.
Scope:
debian
CVE-2012-5374P4LOWCVSS 4.0fixed in linux 3.8-1 (bookworm)2012
CVE-2012-5374 [MEDIUM] CVE-2012-5374: linux - The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc...
The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial of service (extended runtime of kernel code) by creating many different files whose names are associated with the same CRC32C hash value.
Scope: local
bookworm: resolved (fixed in 3.8-1)
bullseye: resolved (fixed in 3.8-1)
forky: resolved (fixed in 3.
debian
CVE-2020-29371P4LOWCVSS 3.3fixed in linux 5.8.7-1 (bookworm)2020
CVE-2020-29371 [LOW] CVE-2020-29371: linux - An issue was discovered in romfs_dev_read in fs/romfs/storage.c in the Linux ker...
An issue was discovered in romfs_dev_read in fs/romfs/storage.c in the Linux kernel before 5.8.4. Uninitialized memory leaks to userspace, aka CID-bcf85fcedfdd.
Scope: local
bookworm: resolved (fixed in 5.8.7-1)
bullseye: resolved (fixed in 5.8.7-1)
forky: resolved (fixed in 5.8.7-1)
sid: resolved (fixed in 5.8.7-1)
trixie: resolved (fixed in 5.8.7-1)
debian
CVE-2019-11884P4LOWCVSS 3.3fixed in linux 4.19.37-4 (bookworm)2019
CVE-2019-11884 [LOW] CVE-2019-11884: linux - The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel...
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.
Scope: local
bookworm: resolved (fixed in 4.19.37-4)
bullseye: resolved (fixed in 4.19.37-4)
forky: reso
debian
CVE-2018-18386P4LOWCVSS 3.3fixed in linux 4.14.12-1 (bookworm)2018
CVE-2018-18386 [LOW] CVE-2018-18386: linux - drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (w...
drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals) to hang/block further usage of any pseudo terminal devices due to an EXTPROC versus ICANON confusion in TIOCINQ.
Scope: local
bookworm: resolved (fixed in 4.14.12-1)
bullseye: resolved (fixed in 4.14.12-1)
forky: resolved (fixed in 4.14.12-1)
sid: res
debian
CVE-2021-38205P4LOWCVSS 3.3fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-38205 [LOW] CVE-2021-38205: linux - drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 ...
drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat an ASLR protection mechanism because it prints a kernel pointer (i.e., the real IOMEM pointer).
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.1
debian
CVE-2025-39964P4LOWCVSS 3.3fixed in linux 6.1.158-1 (bookworm)2025
CVE-2025-39964 [LOW] CVE-2025-39964: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: af_...
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->wri
debian
CVE-2024-26764P4LOWCVSS 3.3fixed in linux 6.1.82-1 (bookworm)2024
CVE-2024-26764 [LOW] CVE-2024-26764: linux - In the Linux kernel, the following vulnerability has been resolved: fs/aio: Res...
In the Linux kernel, the following vulnerability has been resolved: fs/aio: Restrict kiocb_set_cancel_fn() to I/O submitted via libaio If kiocb_set_cancel_fn() is called for I/O submitted via io_uring, the following kernel warning appears: WARNING: CPU: 3 PID: 368 at fs/aio.c:598 kiocb_set_cancel_fn+0x9c/0xa8 Call trace: kiocb_set_cancel_fn+0x9c/0xa8 ffs_epfile_read_it
debian
CVE-2021-46934P4LOWCVSS 3.3fixed in linux 5.15.15-1 (bookworm)2021
CVE-2021-46934 [LOW] CVE-2021-46934: linux - In the Linux kernel, the following vulnerability has been resolved: i2c: valida...
In the Linux kernel, the following vulnerability has been resolved: i2c: validate user data in compat ioctl Wrong user data may cause warning in i2c_transfer(), ex: zero msgs. Userspace should not be able to trigger warnings, so this patch adds validation checks for user data in compact ioctl to prevent reported warnings
Scope: local
bookworm: resolved (fixed in 5.15.1
debian
CVE-2021-46971P4LOWCVSS 3.3fixed in linux 5.10.38-1 (bookworm)2021
CVE-2021-46971 [LOW] CVE-2021-46971: linux - In the Linux kernel, the following vulnerability has been resolved: perf/core: ...
In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix unconditional security_locked_down() call Currently, the lockdown state is queried unconditionally, even though its result is used only if the PERF_SAMPLE_REGS_INTR bit is set in attr.sample_type. While that doesn't matter in case of the Lockdown LSM, it causes trouble with the SELinux's
debian
CVE-2023-1513P4LOWCVSS 3.3fixed in linux 6.1.15-1 (bookworm)2023
CVE-2023-1513 [LOW] CVE-2023-1513: linux - A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit sys...
A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be some uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak.
Scope: local
bookworm: resolved (fixed in 6.1.15-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.15-1)
sid: resolved (fixed
debian
CVE-2023-1075P4LOWCVSS 3.3fixed in linux 6.1.11-1 (bookworm)2023
CVE-2023-1075 [LOW] CVE-2023-1075: linux - A flaw was found in the Linux Kernel. The tls_is_tx_ready() incorrectly checks f...
A flaw was found in the Linux Kernel. The tls_is_tx_ready() incorrectly checks for list emptiness, potentially accessing a type confused entry to the list_head, leaking the last byte of the confused field that overlaps with rec->tx_ready.
Scope: local
bookworm: resolved (fixed in 6.1.11-1)
bullseye: open
forky: resolved (fixed in 6.1.11-1)
sid: resolved (fixed in 6.1.11-
debian
CVE-2021-47430P4LOWCVSS 3.3fixed in linux 5.14.12-1 (bookworm)2021
CVE-2021-47430 [LOW] CVE-2021-47430: linux - In the Linux kernel, the following vulnerability has been resolved: x86/entry: ...
In the Linux kernel, the following vulnerability has been resolved: x86/entry: Clear X86_FEATURE_SMAP when CONFIG_X86_SMAP=n Commit 3c73b81a9164 ("x86/entry, selftests: Further improve user entry sanity checks") added a warning if AC is set when in the kernel. Commit 662a0221893a3d ("x86/entry: Fix AC assertion") changed the warning to only fire if the CPU supports SMA
debian
CVE-2024-43841P4LOWCVSS 3.3fixed in linux 6.1.106-1 (bookworm)2024
CVE-2024-43841 [LOW] CVE-2024-43841: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: virt_...
In the Linux kernel, the following vulnerability has been resolved: wifi: virt_wifi: avoid reporting connection success with wrong SSID When user issues a connection with a different SSID than the one virt_wifi has advertised, the __cfg80211_connect_result() will trigger the warning: WARN_ON(bss_not_found). The issue is because the connection code in virt_wifi does not
debian
CVE-2024-26911P4LOWCVSS 3.3fixed in linux 6.7.7-1 (forky)2024
CVE-2024-26911 [LOW] CVE-2024-26911: linux - In the Linux kernel, the following vulnerability has been resolved: drm/buddy: ...
In the Linux kernel, the following vulnerability has been resolved: drm/buddy: Fix alloc_range() error handling code Few users have observed display corruption when they boot the machine to KDE Plasma or playing games. We have root caused the problem that whenever alloc_range() couldn't find the required memory blocks the function was returning SUCCESS in some of the c
debian
CVE-2024-46794P4LOWCVSS 3.3fixed in linux 6.1.112-1 (bookworm)2024
CVE-2024-46794 [LOW] CVE-2024-46794: linux - In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fi...
In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix data leak in mmio_read() The mmio_read() function makes a TDVMCALL to retrieve MMIO data for an address from the VMM. Sean noticed that mmio_read() unintentionally exposes the value of an initialized variable (val) on the stack to the VMM. This variable is only needed as an output value. I
debian