cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 631 of 632
CVE-2012-6547P4LOWCVSS 1.9fixed in linux 3.2.29-1 (bookworm)2012
CVE-2012-6547 [LOW] CVE-2012-6547: linux - The __tun_chr_ioctl function in drivers/net/tun.c in the Linux kernel before 3.6... The __tun_chr_ioctl function in drivers/net/tun.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted application. Scope: local bookworm: resolved (fixed in 3.2.29-1) bullseye: resolved (fixed in 3.2.29-1) forky: resolved (fixed in 3.2.29-1) sid: resolved (
debian
CVE-2012-6544P4LOWCVSS 1.9fixed in linux 3.2.30-1 (bookworm)2012
CVE-2012-6544 [LOW] CVE-2012-6544: linux - The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly in... The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that targets the (1) L2CAP or (2) HCI implementation. Scope: local bookworm: resolved (fixed in 3.2.30-1) bullseye: resolved (fixed in 3.2.30-1) forky: reso
debian
CVE-2015-1420P4LOWCVSS 1.9fixed in linux 3.16.7-ckt7-1 (bookworm)2015
CVE-2015-1420 [LOW] CVE-2015-1420: linux - Race condition in the handle_to_path function in fs/fhandle.c in the Linux kerne... Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function. Scope: local bookworm: resolved (fixed in 3.16.7-ckt7-1) bullseye: res
debian
CVE-2012-6540P4LOWCVSS 1.9fixed in linux 3.2.30-1 (bookworm)2012
CVE-2012-6540 [LOW] CVE-2012-6540: linux - The do_ip_vs_get_ctl function in net/netfilter/ipvs/ip_vs_ctl.c in the Linux ker... The do_ip_vs_get_ctl function in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 3.6 does not initialize a certain structure for IP_VS_SO_GET_TIMEOUT commands, which allows local users to obtain sensitive information from kernel stack memory via a crafted application. Scope: local bookworm: resolved (fixed in 3.2.30-1) bullseye: resolved (fixed in 3.2.30-1) for
debian
CVE-2012-6539P4LOWCVSS 1.9fixed in linux 3.2.30-1 (bookworm)2012
CVE-2012-6539 [LOW] CVE-2012-6539: linux - The dev_ifconf function in net/socket.c in the Linux kernel before 3.6 does not ... The dev_ifconf function in net/socket.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted application. Scope: local bookworm: resolved (fixed in 3.2.30-1) bullseye: resolved (fixed in 3.2.30-1) forky: resolved (fixed in 3.2.30-1) sid: resolved (fixed in 3
debian
CVE-2012-6541P4LOWCVSS 1.9fixed in linux 3.2.30-1 (bookworm)2012
CVE-2012-6541 [LOW] CVE-2012-6541: linux - The ccid3_hc_tx_getsockopt function in net/dccp/ccids/ccid3.c in the Linux kerne... The ccid3_hc_tx_getsockopt function in net/dccp/ccids/ccid3.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted application. Scope: local bookworm: resolved (fixed in 3.2.30-1) bullseye: resolved (fixed in 3.2.30-1) forky: resolved (fixed in 3.2.30-1) sid
debian
CVE-2012-6542P4LOWCVSS 1.9fixed in linux 3.2.30-1 (bookworm)2012
CVE-2012-6542 [LOW] CVE-2012-6542: linux - The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 h... The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that leverages an uninitialized pointer argument. Scope: local bookworm: resolved (fixed in 3.2.30-1) bullseye: resolved (fixed in
debian
CVE-2014-4652P4LOWCVSS 1.9fixed in linux 3.14.9-1 (bookworm)2014
CVE-2014-4652 [LOW] CVE-2014-4652: linux - Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv fun... Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users to obtain sensitive information from kernel memory by leveraging /dev/snd/controlCX access. Scope: local bookworm: resolved (fixed in 3.14.9-1) bullseye: resolved (fixed in 3.
debian
CVE-2013-0349P4LOWCVSS 1.9fixed in linux 3.2.39-1 (bookworm)2013
CVE-2013-0349 [LOW] CVE-2013-0349: linux - The hidp_setup_hid function in net/bluetooth/hidp/core.c in the Linux kernel bef... The hidp_setup_hid function in net/bluetooth/hidp/core.c in the Linux kernel before 3.7.6 does not properly copy a certain name field, which allows local users to obtain sensitive information from kernel memory by setting a long name and making an HIDPCONNADD ioctl call. Scope: local bookworm: resolved (fixed in 3.2.39-1) bullseye: resolved (fixed in 3.2.39-1) forky: res
debian
CVE-2014-1444P4LOWCVSS 1.7fixed in linux 3.12.6-1 (bookworm)2014
CVE-2014-1444 [LOW] CVE-2014-1444: linux - The fst_get_iface function in drivers/net/wan/farsync.c in the Linux kernel befo... The fst_get_iface function in drivers/net/wan/farsync.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an SIOCWANDEV ioctl call. Scope: local bookworm: resolved (fixed in 3.12.6-1) bullseye: resolved (fixed i
debian
CVE-2021-47671P4LOWCVSS 3.3fixed in linux 5.15.3-1 (bookworm)2021
CVE-2021-47671 [LOW] CVE-2021-47671: linux - In the Linux kernel, the following vulnerability has been resolved: can: etas_e... In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path In es58x_rx_err_msg(), if can->do_set_mode() fails, the function directly returns without calling netif_rx(skb). This means that the skb previously allocated by alloc_can_err_skb() is not freed. In other terms, this is a memory leak. Th
debian
CVE-2022-3521P4LOWCVSS 2.6fixed in linux 6.0.10-1 (bookworm)2022
CVE-2022-3521 [LOW] CVE-2022-3521: linux - A vulnerability has been found in Linux Kernel and classified as problematic. Th... A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function kcm_tx_work of the file net/kcm/kcmsock.c of the component kcm. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. VDB-211018 is the identifier assigned to this vulnerability. Scope: local bookworm: resolved (f
debian
CVE-2019-19533P4LOWCVSS 2.4fixed in linux 5.3.7-1 (bookworm)2019
CVE-2019-19533 [LOW] CVE-2019-19533: linux - In the Linux kernel before 5.3.4, there is an info-leak bug that can be caused b... In the Linux kernel before 5.3.4, there is an info-leak bug that can be caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusb_dec.c driver, aka CID-a10feaf8c464. Scope: local bookworm: resolved (fixed in 5.3.7-1) bullseye: resolved (fixed in 5.3.7-1) forky: resolved (fixed in 5.3.7-1) sid: resolved (fixed in 5.3.7-1) trixie: resolved (fixed in 5.3.7
debian
CVE-2015-7884P4LOWCVSS 2.3fixed in linux 4.2.6-1 (bookworm)2015
CVE-2015-7884 [LOW] CVE-2015-7884: linux - The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the L... The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application. Scope: local bookworm: resolved (fixed in 4.2.6-1) bullseye: resolved (fixed in 4.2.6-1) forky: resolved (fixed in 4
debian
CVE-2019-9455P4LOWCVSS 2.3fixed in linux 4.19.37-1 (bookworm)2019
CVE-2019-9455 [LOW] CVE-2019-9455: linux - In the Android kernel in the video driver there is a kernel pointer leak due to ... In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Scope: local bookworm: resolved (fixed in 4.19.37-1) bullseye: resolved (fixed in 4.19.37-1) forky: resolved (fixed in 4.19.37-1) sid:
debian
CVE-2013-2141P4LOWCVSS 2.1fixed in linux 3.9.4-1 (bookworm)2013
CVE-2013-2141 [LOW] CVE-2013-2141: linux - The do_tkill function in kernel/signal.c in the Linux kernel before 3.8.9 does n... The do_tkill function in kernel/signal.c in the Linux kernel before 3.8.9 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted application that makes a (1) tkill or (2) tgkill system call. Scope: local bookworm: resolved (fixed in 3.9.4-1) bullseye: resolved (fixed in 3.9.4-1) forky: resol
debian
CVE-2013-2234P4LOWCVSS 2.1fixed in linux 3.10.1-1 (bookworm)2013
CVE-2013-2234 [LOW] CVE-2013-2234: linux - The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key... The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key.c in the Linux kernel before 3.10 do not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify interface of an IPSec key_socket. Scope: local bookworm: resolved (fixed in 3.
debian
CVE-2015-5697P4LOWCVSS 2.1fixed in linux 4.1.3-1 (bookworm)2015
CVE-2015-5697 [LOW] CVE-2015-5697: linux - The get_bitmap_file function in drivers/md/md.c in the Linux kernel before 4.1.6... The get_bitmap_file function in drivers/md/md.c in the Linux kernel before 4.1.6 does not initialize a certain bitmap data structure, which allows local users to obtain sensitive information from kernel memory via a GET_BITMAP_FILE ioctl call. Scope: local bookworm: resolved (fixed in 4.1.3-1) bullseye: resolved (fixed in 4.1.3-1) forky: resolved (fixed in 4.1.3-1) sid:
debian
CVE-2014-0206P4LOWCVSS 2.1fixed in linux 3.14.10-1 (bookworm)2014
CVE-2014-0206 [LOW] CVE-2014-0206: linux - Array index error in the aio_read_events_ring function in fs/aio.c in the Linux ... Array index error in the aio_read_events_ring function in fs/aio.c in the Linux kernel through 3.15.1 allows local users to obtain sensitive information from kernel memory via a large head value. Scope: local bookworm: resolved (fixed in 3.14.10-1) bullseye: resolved (fixed in 3.14.10-1) forky: resolved (fixed in 3.14.10-1) sid: resolved (fixed in 3.14.10-1) trixie: reso
debian
CVE-2013-2547P4LOWCVSS 2.1fixed in linux 3.2.41-1 (bookworm)2013
CVE-2013-2547 [LOW] CVE-2013-2547: linux - The crypto_report_one function in crypto/crypto_user.c in the report API in the ... The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability. Scope: local bookworm: resolved (fixed in 3.2.41-1) bulls
debian
Debian Linux vulnerabilities | cvebase