cbcvebase.

Debian Linux vulnerabilities

12,638 known vulnerabilities affecting debian/linux.

Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226

Vulnerabilities

Page 8 of 632
CVE-2019-16746P3CRITICALCVSS 9.8fixed in linux 5.3.7-1 (bookworm)2019
CVE-2019-16746 [CRITICAL] CVE-2019-16746: linux - An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.... An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow. Scope: local bookworm: resolved (fixed in 5.3.7-1) bullseye: resolved (fixed in 5.3.7-1) forky: resolved (fixed in 5.3.7-1) sid: resolved (fixed in 5.3.7-1) trixie: resolved (fixed i
debian
CVE-2019-9213P3MEDIUMCVSS 5.5PoCfixed in linux 4.19.28-1 (bookworm)2019
CVE-2019-9213 [MEDIUM] CVE-2019-9213: linux - In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check ... In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the wrong task. Scope: local bookworm: resolved (fixed in 4.19.28-1) bullseye: resolved (fixed in 4.19.28-1) forky:
debian
CVE-2019-1125P3MEDIUMCVSS 5.6PoCfixed in linux 5.2.7-1 (bookworm)2019
CVE-2019-1125 [MEDIUM] CVE-2019-1125: linux - An information disclosure vulnerability exists when certain central processing u... An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerabil
debian
CVE-2013-4579P4MEDIUMCVSS 4.3PoCfixed in linux 3.12.8-1 (bookworm)2013
CVE-2013-4579 [MEDIUM] CVE-2013-4579: linux - The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_... The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12 uses a BSSID masking approach to determine the set of MAC addresses on which a Wi-Fi device is listening, which allows remote attackers to discover the original MAC address after spoofing by sending a series of packets to MAC addresses with certain b
debian
CVE-2023-38428P3CRITICALCVSS 9.1fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-38428 [CRITICAL] CVE-2023-38428: linux - An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ... An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read. Scope: local bookworm: resolved (fixed in 6.1.37-1) bullseye: resolved forky: resolved (fixed in 6.3.7-1) sid: resolved (fixed in 6.3.7-1) tri
debian
CVE-2022-47942P3HIGHCVSS 8.8fixed in linux 5.19.6-1 (bookworm)2022
CVE-2022-47942 [HIGH] CVE-2022-47942: linux - An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.... An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command. Scope: local bookworm: resolved (fixed in 5.19.6-1) bullseye: resolved forky: resolved (fixed in 5.19.6-1) sid: resolved (fixed in 5.19.6-1) trixi
debian
CVE-2020-0009P4MEDIUMCVSS 5.5PoCfixed in linux 5.5.13-1 (bookworm)2020
CVE-2020-0009 [MEDIUM] CVE-2020-0009: linux - In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared ... In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalation of privilege by corrupting memory shared between processes, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-14293
debian
CVE-2020-25705P3HIGHCVSS 7.4fixed in linux 5.9.6-1 (bookworm)2020
CVE-2020-25705 [HIGH] CVE-2020-25705: linux - A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan... A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port randomization are indirectly affected as well on the Linux Based Products (RUGGEDCOM RM1224: All versions between v5.0 and v6.4, SCALAN
debian
CVE-2023-32250P3CRITICALCVSS 9.0fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-32250 [CRITICAL] CVE-2023-32250: linux - A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB s... A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel. Scope: local bookwo
debian
CVE-2025-37924P3CRITICALCVSS 9.8fixed in linux 6.1.140-1 (bookworm)2025
CVE-2025-37924 [CRITICAL] CVE-2025-37924: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ... In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL was introduced to fix the dangling pointer created by ksmbd_free_user. However, it is possible another thread could be operating on the session and make use of sess->user after it has been passed to ksmbd_free_user but
debian
CVE-2014-2523P3CRITICALCVSS 10.0fixed in linux 3.13.10-1 (bookworm)2014
CVE-2014-2523 [CRITICAL] CVE-2014-2523: linux - net/netfilter/nf_conntrack_proto_dccp.c in the Linux kernel through 3.13.6 uses ... net/netfilter/nf_conntrack_proto_dccp.c in the Linux kernel through 3.13.6 uses a DCCP header pointer incorrectly, which allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a DCCP packet that triggers a call to the (1) dccp_new, (2) dccp_packet, or (3) dccp_error function. Scope: local bookworm: resolved (fixed
debian
CVE-2016-4558P4HIGHCVSS 7.0PoCfixed in linux 4.5.3-1 (bookworm)2016
CVE-2016-4558 [HIGH] CVE-2016-4558: linux - The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, ... The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted application on (1) a system with more than 32 Gb of memory, related to the program reference count or (2) a 1 Tb system, related to the map reference count. Scope: l
debian
CVE-2017-7895P3CRITICALCVSS 9.8fixed in linux 4.9.25-1 (bookworm)2017
CVE-2017-7895 [CRITICAL] CVE-2017-7895: linux - The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 l... The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted requests, related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c. Scope: local bookworm: resolved (fixed in 4.9.25-1) bullseye:
debian
CVE-2023-32258P3HIGHCVSS 8.1fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-32258 [HIGH] CVE-2023-32258: linux - A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB s... A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_LOGOFF and SMB2_CLOSE commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel. Scope: local bo
debian
CVE-2023-32257P3HIGHCVSS 8.1fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-32257 [HIGH] CVE-2023-32257: linux - A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB s... A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP and SMB2_LOGOFF commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel. Scope:
debian
CVE-2024-38541P3CRITICALCVSS 9.8fixed in linux 6.1.137-1 (bookworm)2024
CVE-2024-38541 [CRITICAL] CVE-2024-38541: linux - In the Linux kernel, the following vulnerability has been resolved: of: module:... In the Linux kernel, the following vulnerability has been resolved: of: module: add buffer overflow check in of_modalias() In of_modalias(), if the buffer happens to be too small even for the 1st snprintf() call, the len parameter will become negative and str parameter (if not NULL initially) will point beyond the buffer's end. Add the buffer overflow check after
debian
CVE-2020-14305P3HIGHCVSS 8.1fixed in linux 4.12.6-1 (bookworm)2020
CVE-2020-14305 [HIGH] CVE-2020-14305: linux - An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Ove... An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
debian
CVE-2021-20322P3HIGHCVSS 7.4fixed in linux 5.14.6-1 (bookworm)2021
CVE-2021-20322 [HIGH] CVE-2021-20322: linux - A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP ... A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integri
debian
CVE-2023-38432P3CRITICALCVSS 9.1fixed in linux 6.1.37-1 (bookworm)2023
CVE-2023-38432 [CRITICAL] CVE-2023-38432: linux - An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2mis... An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read. Scope: local bookworm: resolved (fixed in 6.1.37-1) bullseye: resolved forky: resolved (fixed in 6.3.11-1) sid: resolved (fixed in 6.
debian
CVE-2019-17133P3CRITICALCVSS 9.8fixed in linux 5.3.9-1 (bookworm)2019
CVE-2019-17133 [CRITICAL] CVE-2019-17133: linux - In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/we... In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow. Scope: local bookworm: resolved (fixed in 5.3.9-1) bullseye: resolved (fixed in 5.3.9-1) forky: resolved (fixed in 5.3.9-1) sid: resolved (fixed in 5.3.9-1) trixie: resolved (fixed in 5.3.9-1)
debian
Debian Linux vulnerabilities | cvebase