Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 630 of 632
CVE-2013-2898P4LOWCVSS 1.9fixed in linux 3.10.11-1 (bookworm)2013
CVE-2013-2898 [LOW] CVE-2013-2898: linux - drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in th...
drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SENSOR_HUB is enabled, allows physically proximate attackers to obtain sensitive information from kernel memory via a crafted device.
Scope: local
bookworm: resolved (fixed in 3.10.11-1)
bullseye: resolved (fixed in 3.10.11-1)
forky: resolved (fixe
debian
CVE-2012-4461P4LOWCVSS 1.9fixed in linux 3.2.35-1 (bookworm)2012
CVE-2012-4461 [LOW] CVE-2012-4461: linux - The KVM subsystem in the Linux kernel before 3.6.9, when running on hosts that u...
The KVM subsystem in the Linux kernel before 3.6.9, when running on hosts that use qemu userspace without XSAVE, allows local users to cause a denial of service (kernel OOPS) by using the KVM_SET_SREGS ioctl to set the X86_CR4_OSXSAVE bit in the guest cr4 register, then calling the KVM_RUN ioctl.
Scope: local
bookworm: resolved (fixed in 3.2.35-1)
bullseye: resolved (fix
debian
CVE-2022-3633P4LOWCVSS 3.5fixed in linux 5.19.6-1 (bookworm)2022
CVE-2022-3633 [LOW] CVE-2022-3633: linux - A vulnerability classified as problematic has been found in Linux Kernel. Affect...
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211932.
Scope: local
bookworm: resolved (fixed in 5.19.6-1)
bullseye: resolv
debian
CVE-2021-47000P4LOWCVSS 3.3fixed in linux 5.10.38-1 (bookworm)2021
CVE-2021-47000 [LOW] CVE-2021-47000: linux - In the Linux kernel, the following vulnerability has been resolved: ceph: fix i...
In the Linux kernel, the following vulnerability has been resolved: ceph: fix inode leak on getattr error in __fh_to_dentry
Scope: local
bookworm: resolved (fixed in 5.10.38-1)
bullseye: resolved (fixed in 5.10.38-1)
forky: resolved (fixed in 5.10.38-1)
sid: resolved (fixed in 5.10.38-1)
trixie: resolved (fixed in 5.10.38-1)
debian
CVE-2024-50211P4LOWCVSS 3.3fixed in linux 6.11.6-1 (forky)2024
CVE-2024-50211 [LOW] CVE-2024-50211: linux - In the Linux kernel, the following vulnerability has been resolved: udf: refact...
In the Linux kernel, the following vulnerability has been resolved: udf: refactor inode_bmap() to handle error Refactor inode_bmap() to handle error since udf_next_aext() can return error now. On situations like ftruncate, udf_extend_file() can now detect errors and bail out early without resorting to checking for particular offsets and assuming internal behavior of th
debian
CVE-2022-50522P4LOWCVSS 3.3fixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-50522 [LOW] CVE-2022-50522: linux - In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-pa...
In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-parse: fix error handing in chameleon_parse_gdd() If mcb_device_register() returns error in chameleon_parse_gdd(), the refcount of bus and device name are leaked. Fix this by calling put_device() to give up the reference, so they can be released in mcb_release_dev() and kobject_cleanup().
Scop
debian
CVE-2019-19534P4LOWCVSS 2.4fixed in linux 5.3.15-1 (bookworm)2019
CVE-2019-19534 [LOW] CVE-2019-19534: linux - In the Linux kernel before 5.3.11, there is an info-leak bug that can be caused ...
In the Linux kernel before 5.3.11, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c driver, aka CID-f7a1337f0d29.
Scope: local
bookworm: resolved (fixed in 5.3.15-1)
bullseye: resolved (fixed in 5.3.15-1)
forky: resolved (fixed in 5.3.15-1)
sid: resolved (fixed in 5.3.15-1)
trixie: resolved (fixe
debian
CVE-2014-4027P4LOWCVSS 2.3fixed in linux 3.14.2-1 (bookworm)2014
CVE-2014-4027 [LOW] CVE-2014-4027: linux - The rd_build_device_space function in drivers/target/target_core_rd.c in the Lin...
The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access to a SCSI initiator.
Scope: local
bookworm: resolved (fixed in 3.14.2-1)
bullseye: resolved (fixed in 3.14.2-1)
fo
debian
CVE-2015-7885P4LOWCVSS 2.3fixed in linux 4.4.2-1 (bookworm)2015
CVE-2015-7885 [LOW] CVE-2015-7885: linux - The dgnc_mgmt_ioctl function in drivers/staging/dgnc/dgnc_mgmt.c in the Linux ke...
The dgnc_mgmt_ioctl function in drivers/staging/dgnc/dgnc_mgmt.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.
Scope: local
bookworm: resolved (fixed in 4.4.2-1)
bullseye: resolved (fixed in 4.4.2-1)
forky: resolved (fixed in 4.4.2-1)
debian
CVE-2021-47440P4LOWCVSS 2.3fixed in linux 5.14.16-1 (bookworm)2021
CVE-2021-47440 [LOW] CVE-2021-47440: linux - In the Linux kernel, the following vulnerability has been resolved: net: encx24...
In the Linux kernel, the following vulnerability has been resolved: net: encx24j600: check error in devm_regmap_init_encx24j600 devm_regmap_init may return error which caused by like out of memory, this will results in null pointer dereference later when reading or writing register: general protection fault in encx24j600_spi_probe KASAN: null-ptr-deref in range [0x0000
debian
CVE-2014-1738P4LOWCVSS 2.1fixed in linux 3.14.4-1 (bookworm)2014
CVE-2014-1738 [LOW] CVE-2014-1738: linux - The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel throu...
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.
Scope: local
bookworm: resolved (fixed in 3.14.4-1)
bul
debian
CVE-2014-9584P4LOWCVSS 2.1fixed in linux 3.16.7-ckt4-1 (bookworm)2014
CVE-2014-9584 [LOW] CVE-2014-9584: linux - The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux ker...
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt4-1)
bullseye: resolved (fixed in
debian
CVE-2014-9731P4LOWCVSS 2.1fixed in linux 3.16.7-ckt4-1 (bookworm)2014
CVE-2014-9731 [LOW] CVE-2014-9731: linux - The UDF filesystem implementation in the Linux kernel before 3.18.2 does not ens...
The UDF filesystem implementation in the Linux kernel before 3.18.2 does not ensure that space is available for storing a symlink target's name along with a trailing \0 character, which allows local users to obtain sensitive information via a crafted filesystem image, related to fs/udf/symlink.c and fs/udf/unicode.c.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt4-
debian
CVE-2014-1445P4LOWCVSS 2.1fixed in linux 3.12.6-1 (bookworm)2014
CVE-2014-1445 [LOW] CVE-2014-1445: linux - The wanxl_ioctl function in drivers/net/wan/wanxl.c in the Linux kernel before 3...
The wanxl_ioctl function in drivers/net/wan/wanxl.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via an ioctl call.
Scope: local
bookworm: resolved (fixed in 3.12.6-1)
bullseye: resolved (fixed in 3.12.6-1)
forky: resolved (fixed in 3.12.6-1)
sid: resol
debian
CVE-2013-2548P4LOWCVSS 2.1fixed in linux 3.2.41-1 (bookworm)2013
CVE-2013-2548 [LOW] CVE-2013-2548: linux - The crypto_report_one function in crypto/crypto_user.c in the report API in the ...
The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect length value during a copy operation, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability.
Scope: local
bookworm: resolved (fixed in 3.2.41-1)
b
debian
CVE-2013-2546P4LOWCVSS 2.1fixed in linux 3.2.41-1 (bookworm)2013
CVE-2013-2546 [LOW] CVE-2013-2546: linux - The report API in the crypto user configuration API in the Linux kernel through ...
The report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect C library function for copying strings, which allows local users to obtain sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability.
Scope: local
bookworm: resolved (fixed in 3.2.41-1)
bullseye: resolved (fixed in 3.2.41-1)
forky: resol
debian
CVE-2014-1446P4LOWCVSS 1.9fixed in linux 3.12.8-1 (bookworm)2014
CVE-2014-1446 [LOW] CVE-2014-1446: linux - The yam_ioctl function in drivers/net/hamradio/yam.c in the Linux kernel before ...
The yam_ioctl function in drivers/net/hamradio/yam.c in the Linux kernel before 3.12.8 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an SIOCYAMGCFG ioctl call.
Scope: local
bookworm: resolved (fixed in 3.12.8-1)
bullseye: resolved (fixed in 3.12.8-
debian
CVE-2013-2634P4LOWCVSS 1.9fixed in linux 3.2.41-2 (bookworm)2013
CVE-2013-2634 [LOW] CVE-2013-2634: linux - net/dcb/dcbnl.c in the Linux kernel before 3.8.4 does not initialize certain str...
net/dcb/dcbnl.c in the Linux kernel before 3.8.4 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
Scope: local
bookworm: resolved (fixed in 3.2.41-2)
bullseye: resolved (fixed in 3.2.41-2)
forky: resolved (fixed in 3.2.41-2)
sid: resolved (fixed in 3.2.41-2)
trixie: resolv
debian
CVE-2013-2635P4LOWCVSS 1.9fixed in linux 3.2.41-2 (bookworm)2013
CVE-2013-2635 [LOW] CVE-2013-2635: linux - The rtnl_fill_ifinfo function in net/core/rtnetlink.c in the Linux kernel before...
The rtnl_fill_ifinfo function in net/core/rtnetlink.c in the Linux kernel before 3.8.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
Scope: local
bookworm: resolved (fixed in 3.2.41-2)
bullseye: resolved (fixed in 3.2.41-2)
forky: resolved (fixed in 3.2.41-2)
si
debian
CVE-2012-6546P4LOWCVSS 1.9fixed in linux 3.2.30-1 (bookworm)2012
CVE-2012-6546 [LOW] CVE-2012-6546: linux - The ATM implementation in the Linux kernel before 3.6 does not initialize certai...
The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
Scope: local
bookworm: resolved (fixed in 3.2.30-1)
bullseye: resolved (fixed in 3.2.30-1)
forky: resolved (fixed in 3.2.30-1)
sid: resolved (fixed in 3.2.30-1)
trixie: r
debian