cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 632 of 632
CVE-2012-3520P4LOWCVSS 1.9fixed in linux 3.2.29-1 (bookworm)2012
CVE-2012-3520 [LOW] CVE-2012-3520: linux - The Netlink implementation in the Linux kernel before 3.2.30 does not properly h... The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager. Scope: local bookworm: resolved (fixed in 3.2.29-1) bullseye: resolved (fixed in 3.2.29-1) forky:
debian
CVE-2012-6545P4LOWCVSS 1.9fixed in linux 3.2.30-1 (bookworm)2012
CVE-2012-6545 [LOW] CVE-2012-6545: linux - The Bluetooth RFCOMM implementation in the Linux kernel before 3.6 does not prop... The Bluetooth RFCOMM implementation in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application. Scope: local bookworm: resolved (fixed in 3.2.30-1) bullseye: resolved (fixed in 3.2.30-1) forky: resolved (fixed in 3.2.30-1) sid: resolved (fixed in 3.2
debian
CVE-2013-1958P4LOWCVSS 1.9fixed in linux 3.8.13-1 (bookworm)2013
CVE-2013-1958 [LOW] CVE-2013-1958: linux - The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.8.6 ... The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.8.6 does not properly enforce capability requirements for controlling the PID value associated with a UNIX domain socket, which allows local users to bypass intended access restrictions by leveraging the time interval during which a user namespace has been created but a PID namespace has not been
debian
CVE-2024-42155P4LOWCVSS 1.9fixed in linux 6.9.9-1 (forky)2024
CVE-2024-42155 [LOW] CVE-2024-42155: linux - In the Linux kernel, the following vulnerability has been resolved: s390/pkey: ... In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Wipe copies of protected- and secure-keys Although the clear-key of neither protected- nor secure-keys is accessible, this key material should only be visible to the calling process. So wipe all copies of protected- or secure-keys from stack, even in case of an error. Scope: local bookworm:
debian
CVE-2013-2237P4LOWCVSS 2.1fixed in linux 3.9.4-1 (bookworm)2013
CVE-2013-2237 [LOW] CVE-2013-2237: linux - The key_notify_policy_flush function in net/key/af_key.c in the Linux kernel bef... The key_notify_policy_flush function in net/key/af_key.c in the Linux kernel before 3.9 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify_policy interface of an IPSec key_socket. Scope: local bookworm: resolved (fixed in 3.9.4-1) bullseye: resolve
debian
CVE-2013-2164P4LOWCVSS 2.1fixed in linux 3.9.8-1 (bookworm)2013
CVE-2013-2164 [LOW] CVE-2013-2164: linux - The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux ker... The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 allows local users to obtain sensitive information from kernel memory via a read operation on a malfunctioning CD-ROM drive. Scope: local bookworm: resolved (fixed in 3.9.8-1) bullseye: resolved (fixed in 3.9.8-1) forky: resolved (fixed in 3.9.8-1) sid: resolved (fixed in 3.9
debian
CVE-2012-6536P4LOWCVSS 2.1fixed in linux 3.2.32-1 (bookworm)2012
CVE-2012-6536 [LOW] CVE-2012-6536: linux - net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not verify that the act... net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not verify that the actual Netlink message length is consistent with a certain header field, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability and providing a (1) new or (2) updated state. Scope: local bookworm: resolved (fixed in 3.2.32-1) b
debian
CVE-2013-2148P4LOWCVSS 2.1fixed in linux 3.9.8-1 (bookworm)2013
CVE-2013-2148 [LOW] CVE-2013-2148: linux - The fill_event_metadata function in fs/notify/fanotify/fanotify_user.c in the Li... The fill_event_metadata function in fs/notify/fanotify/fanotify_user.c in the Linux kernel through 3.9.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a read operation on the fanotify descriptor. Scope: local bookworm: resolved (fixed in 3.9.8-1) bullseye: resolved (fixed in 3.9.8-1) forky:
debian
CVE-2012-2669P4LOWCVSS 2.1fixed in linux 3.2.23-1 (bookworm)2012
CVE-2012-2669 [LOW] CVE-2012-2669: linux - The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in t... The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message. Scope: local bookworm: resolved (fixed in 3.2.23-1) bullseye: resolved (fixed in 3.2.23-1) forky: resolved (fixed in 3.2.23-
debian
CVE-2011-4098P4LOWCVSS 1.9fixed in linux 3.2.1-1 (bookworm)2011
CVE-2011-4098 [LOW] CVE-2011-4098: linux - The fallocate implementation in the GFS2 filesystem in the Linux kernel before 3... The fallocate implementation in the GFS2 filesystem in the Linux kernel before 3.2 relies on the page cache, which might allow local users to cause a denial of service by preallocating blocks in certain situations involving insufficient memory. Scope: local bookworm: resolved (fixed in 3.2.1-1) bullseye: resolved (fixed in 3.2.1-1) forky: resolved (fixed in 3.2.1-1) sid:
debian
CVE-2012-6548P4LOWCVSS 1.9fixed in linux 3.2.41-1 (bookworm)2012
CVE-2012-6548 [LOW] CVE-2012-6548: linux - The udf_encode_fh function in fs/udf/namei.c in the Linux kernel before 3.6 does... The udf_encode_fh function in fs/udf/namei.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application. Scope: local bookworm: resolved (fixed in 3.2.41-1) bullseye: resolved (fixed in 3.2.41-1) forky: resolved (fixed in 3.2.41-1) sid: resolved
debian
CVE-2012-6549P4LOWCVSS 1.9fixed in linux 3.2.41-1 (bookworm)2012
CVE-2012-6549 [LOW] CVE-2012-6549: linux - The isofs_export_encode_fh function in fs/isofs/export.c in the Linux kernel bef... The isofs_export_encode_fh function in fs/isofs/export.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application. Scope: local bookworm: resolved (fixed in 3.2.41-1) bullseye: resolved (fixed in 3.2.41-1) forky: resolved (fixed in 3.2.41-1) si
debian
CVE-2012-6537P4LOWCVSS 1.9fixed in linux 3.2.32-1 (bookworm)2012
CVE-2012-6537 [LOW] CVE-2012-6537: linux - net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not initialize certain ... net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability. Scope: local bookworm: resolved (fixed in 3.2.32-1) bullseye: resolved (fixed in 3.2.32-1) forky: resolved (fixed in 3.2.32-1) sid: resolved (fixed in 3.2.32-1)
debian
CVE-2012-6538P4LOWCVSS 1.9fixed in linux 3.2.32-1 (bookworm)2012
CVE-2012-6538 [LOW] CVE-2012-6538: linux - The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel befor... The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability. Scope: local bookworm: resolved (fixed in 3.2.32-1) bullseye: resolved (fixed in 3.2.32-1) forky: resol
debian
CVE-2012-4508P4LOWCVSS 1.9fixed in linux 3.2.35-1 (bookworm)2012
CVE-2012-4508 [LOW] CVE-2012-4508: linux - Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows loc... Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an extent that was not properly marked as uninitialized. Scope: local bookworm: resolved (fixed in 3.2.35-1) bullseye: resolved (fixed in 3.2.35-1) forky: resolved (fixed in 3.2.35-1) sid: resolved (fixed in 3.2.35-1) tri
debian
CVE-2022-2602MEDIUMCVSS 5.3fixed in linux 6.0.3-1 (bookworm)2022
CVE-2022-2602 [MEDIUM] CVE-2022-2602: linux - io_uring UAF, Unix SCM garbage collection io_uring UAF, Unix SCM garbage collection Scope: local bookworm: resolved (fixed in 6.0.3-1) bullseye: resolved (fixed in 5.10.149-1) forky: resolved (fixed in 6.0.3-1) sid: resolved (fixed in 6.0.3-1) trixie: resolved (fixed in 6.0.3-1)
debian
CVE-2026-23471UNKNOWNfixed in linux 6.19.10-1 (forky)2026
CVE-2026-23471 CVE-2026-23471: linux - In the Linux kernel, the following vulnerability has been resolved: drm: Fix us... In the Linux kernel, the following vulnerability has been resolved: drm: Fix use-after-free on framebuffers and property blobs when calling drm_dev_unplug When trying to do a rather aggressive test of igt's "xe_module_load --r reload" with a full desktop environment and game running I noticed a few OOPSes when dereferencing freed pointers, related to framebuffers and propert
debian
CVE-2023-7122LOWfixed in linux 6.7.7-1 (forky)2023
CVE-2023-7122 [LOW] CVE-2023-7122: linux bookworm: resolved bullseye: resolved forky: resolved (fixed in 6.7.7-1) sid: resolved (fixed in 6.7.7-1) trixie: resolved (fixed in 6.7.7-1)
debian
← Previous632 / 632
Debian Linux vulnerabilities | cvebase