Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 70 of 632
CVE-2024-58087P3HIGHCVSS 8.1fixed in linux 6.1.123-1 (bookworm)2024
CVE-2024-58087 [HIGH] CVE-2024-58087: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expire Increment the session reference count within the lock for lookup to avoid racy issue with session expire.
Scope: local
bookworm: resolved (fixed in 6.1.123-1)
bullseye: resolved
forky: resolved (fixed in 6.12.6-1)
sid: resolved (fixed in 6.12.6-1)
t
debian
CVE-2019-8956P3HIGHCVSS 7.8fixed in linux 4.19.28-1 (bookworm)2019
CVE-2019-8956 [HIGH] CVE-2019-8956: linux - In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in...
In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp/socket.c) when handling SCTP_SENDALL flag can be exploited to corrupt memory.
Scope: local
bookworm: resolved (fixed in 4.19.28-1)
bullseye: resolved (fixed in 4.19.28-1)
forky: resolved (fixed in 4.19.28-1)
sid: resolved (fixed in 4.19.28-1)
trixie:
debian
CVE-2018-18281P3HIGHCVSS 7.8fixed in linux 4.18.20-1 (bookworm)2018
CVE-2018-18281 [HIGH] CVE-2018-18281: linux - Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after ...
Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(), a stale TLB entry can remain for a short time that permits access to a physical page after it has been released back to the page allocator and reused.
debian
CVE-2022-2585P3MEDIUMCVSS 5.3fixed in linux 5.18.16-1 (bookworm)2022
CVE-2022-2585 [MEDIUM] CVE-2022-2585: linux - It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU t...
It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.
Scope: local
bookworm: resolved (fixed in 5.18.16-1)
bullseye: resolved (fixed in 5.10.136-1)
forky: resolved (fixed in 5.18.16-1)
sid: resolved (fixed in 5.18.16-1)
trixie: resolved (fixed in 5.18.16-1)
debian
CVE-2020-14356P3HIGHCVSS 7.8fixed in linux 5.7.10-1 (bookworm)2020
CVE-2020-14356 [HIGH] CVE-2020-14356: linux - A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versio...
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
Scope: local
bookworm: resolved (fixed in 5.7.10-1)
bullseye: resolved (fixed in 5.7.10-1)
forky: resolved (fixed in 5.7.10-1)
sid:
debian
CVE-2017-7518P3MEDIUMCVSS 5.5fixed in linux 4.11.11-1 (bookworm)2017
CVE-2017-7518 [MEDIUM] CVE-2017-7518: linux - A flaw was found in the Linux kernel before version 4.12 in the way the KVM modu...
A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/process inside a guest could use this flaw to potentially escalate their privileges inside the guest. Linux guests are not
debian
CVE-2022-45934P3HIGHCVSS 7.8fixed in linux 6.1.4-1 (bookworm)2022
CVE-2022-45934 [HIGH] CVE-2022-45934: linux - An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in ...
An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved (fixed in 5.10.162-1)
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
debian
CVE-2019-11487P3HIGHCVSS 7.8fixed in linux 4.19.37-1 (bookworm)2019
CVE-2019-11487 [HIGH] CVE-2019-11487: linux - The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow,...
The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It can occur with FUSE requests.
Scope: local
bookworm: resolved
debian
CVE-2019-0155P3HIGHCVSS 7.8fixed in linux 5.3.9-2 (bookworm)2019
CVE-2019-0155 [HIGH] CVE-2019-0155: linux - Insufficient access control in a subsystem for Intel (R) processor graphics in 6...
Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 an
debian
CVE-2022-3545P3MEDIUMCVSS 5.5fixed in linux 6.0.2-1 (bookworm)2022
CVE-2022-3545 [MEDIUM] CVE-2022-3545: linux - A vulnerability has been found in Linux Kernel and classified as critical. Affec...
A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function area_cache_get of the file drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211045 was assigned to th
debian
CVE-2017-1000363P3LOWCVSS 7.8fixed in linux 4.9.30-1 (bookworm)2017
CVE-2017-1000363 [HIGH] CVE-2017-1000363: linux - Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and ...
Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel command line adversary (can happen due to bootloader vulns, e.g. Google Nexus 6's CVE-2016-10277, where due to a vulnerability the adversary has partial control over the command line) can overflow the parport_nr array
debian
CVE-2020-7053P3HIGHCVSS 7.8fixed in linux 5.2.6-1 (bookworm)2020
CVE-2020-7053 [HIGH] CVE-2020-7053: linux - In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm through 4.1...
In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm through 4.19.96 (and 5.x before 5.2), there is a use-after-free (write) in the i915_ppgtt_close function in drivers/gpu/drm/i915/i915_gem_gtt.c, aka CID-7dc40713618c. This is related to i915_gem_context_destroy_ioctl in drivers/gpu/drm/i915/i915_gem_context.c.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2025-21762P3HIGHCVSS 7.8fixed in linux 6.1.129-1 (bookworm)2025
CVE-2025-21762 [HIGH] CVE-2025-21762: linux - In the Linux kernel, the following vulnerability has been resolved: arp: use RC...
In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF.
Scope: local
bookworm: resolved (fixed in 6.1.129-1)
bullseye: resolved (fixed in 5.10.237-1)
forky: resolved (fixed in 6.12.16-1)
sid: resolved (fixed in 6.12.16-1
debian
CVE-2018-25015P3HIGHCVSS 7.8fixed in linux 4.14.17-1 (bookworm)2018
CVE-2018-25015 [HIGH] CVE-2018-25015: linux - An issue was discovered in the Linux kernel before 4.14.16. There is a use-after...
An issue was discovered in the Linux kernel before 4.14.16. There is a use-after-free in net/sctp/socket.c for a held lock after a peel off, aka CID-a0ff660058b8.
Scope: local
bookworm: resolved (fixed in 4.14.17-1)
bullseye: resolved (fixed in 4.14.17-1)
forky: resolved (fixed in 4.14.17-1)
sid: resolved (fixed in 4.14.17-1)
trixie: resolved (fixed in 4.14.17-1)
debian
CVE-2019-19807P3HIGHCVSS 7.8fixed in linux 5.3.15-1 (bookworm)2019
CVE-2019-19807 [HIGH] CVE-2019-19807: linux - In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free cause...
In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly created timer instance, but was used for a different purpose after refactoring.
Scope: local
bookworm: resolved
debian
CVE-2016-9754P3HIGHCVSS 7.8fixed in linux 4.6.1-1 (bookworm)2016
CVE-2016-9754 [HIGH] CVE-2016-9754: linux - The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling s...
The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer calculations, which allows local users to gain privileges by writing to the /sys/kernel/debug/tracing/buffer_size_kb file.
Scope: local
bookworm: resolved (fixed in 4.6.1-1)
bullseye: resolved (fixed in 4.6.1-1)
forky: reso
debian
CVE-2025-37926P3HIGHCVSS 7.8fixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-37926 [HIGH] CVE-2025-37926: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_session_rpc_open A UAF issue can occur due to a race condition between ksmbd_session_rpc_open() and __session_rpc_close(). Add rpc_lock to the session to protect it.
Scope: local
bookworm: resolved (fixed in 6.1.162-1)
bullseye: resolved
forky: resolved (fixed in 6.1
debian
CVE-2017-7482P3HIGHCVSS 7.8fixed in linux 4.11.11-1 (bookworm)2017
CVE-2017-7482 [HIGH] CVE-2017-7482: linux - In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using t...
In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.
Scope: local
bookworm: resolved (fixed in 4.1
debian
CVE-2017-10662P3HIGHCVSS 7.8fixed in linux 4.9.30-1 (bookworm)2017
CVE-2017-10662 [HIGH] CVE-2017-10662: linux - The sanity_check_raw_super function in fs/f2fs/super.c in the Linux kernel befor...
The sanity_check_raw_super function in fs/f2fs/super.c in the Linux kernel before 4.11.1 does not validate the segment count, which allows local users to gain privileges via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.9.30-1)
bullseye: resolved (fixed in 4.9.30-1)
forky: resolved (fixed in 4.9.30-1)
sid: resolved (fixed in 4.9.30-1)
trixie: resolv
debian
CVE-2023-53652P3MEDIUMCVSS 5.5fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-53652 [MEDIUM] CVE-2023-53652: linux - In the Linux kernel, the following vulnerability has been resolved: vdpa: Add f...
In the Linux kernel, the following vulnerability has been resolved: vdpa: Add features attr to vdpa_nl_policy for nlattr length check The vdpa_nl_policy structure is used to validate the nlattr when parsing the incoming nlmsg. It will ensure the attribute being described produces a valid nlattr pointer in info->attrs before entering into each handler in vdpa_nl_ops.
debian