Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 9 of 632
CVE-2025-68263P3CRITICALCVSS 9.8fixed in linux 6.1.162-1 (bookworm)2025
CVE-2025-68263 [CRITICAL] CVE-2025-68263: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc:...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_request ipc_msg_send_request() waits for a generic netlink reply using an ipc_msg_table_entry on the stack. The generic netlink handler (handle_generic_event()/handle_response()) fills entry->response under ipc_msg_table_lock, but ipc_msg_send_request
debian
CVE-2014-4699P4MEDIUMCVSS 6.9PoCfixed in linux 3.14.10-1 (bookworm)2014
CVE-2014-4699 [MEDIUM] CVE-2014-4699: linux - The Linux kernel before 3.15.4 on Intel processors does not properly restrict us...
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain privileges, or cause a denial of service (double fault), via a crafted application that makes ptrace and fork system call
debian
CVE-2022-27223P3HIGHCVSS 8.8fixed in linux 5.16.12-1 (bookworm)2022
CVE-2022-27223 [HIGH] CVE-2022-27223: linux - In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the e...
In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.
Scope: local
bookworm: resolved (fixed in 5.16.12-1)
bullseye: resolved (fixed in 5.10.103-1)
forky: resolved (fixed in 5.16.12-1)
sid: resolved (fixed in 5.16.12-1)
trixie: resolved (fixed in 5.16
debian
CVE-2019-11599P4HIGHCVSS 7.0PoCfixed in linux 4.19.37-1 (bookworm)2019
CVE-2019-11599 [HIGH] CVE-2019-11599: linux - The coredump implementation in the Linux kernel before 5.0.10 does not use locki...
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a race condition with mmget_not_zero or get_task_mm calls. This is r
debian
CVE-2017-5897P3CRITICALCVSS 9.8fixed in linux 4.9.13-1 (bookworm)2017
CVE-2017-5897 [CRITICAL] CVE-2017-5897: linux - The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote ...
The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.
Scope: local
bookworm: resolved (fixed in 4.9.13-1)
bullseye: resolved (fixed in 4.9.13-1)
forky: resolved (fixed in 4.9.13-1)
sid: resolved (fixed in 4.9.13-1)
debian
CVE-2021-33909P3HIGHCVSS 7.8fixed in linux 5.10.46-2 (bookworm)2021
CVE-2021-33909 [HIGH] CVE-2021-33909: linux - fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not pro...
fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.
Scope: local
bookworm: resolved (fixed in 5.10.46-2)
bullseye: resolved (fixed in 5.10.46-2)
forky: resolved (fixed in 5.10.4
debian
CVE-2024-38605P3HIGHCVSS 8.8fixed in linux 6.1.94-1 (bookworm)2024
CVE-2024-38605 [HIGH] CVE-2024-38605: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: core:...
In the Linux kernel, the following vulnerability has been resolved: ALSA: core: Fix NULL module pointer assignment at card init The commit 81033c6b584b ("ALSA: core: Warn on empty module") introduced a WARN_ON() for a NULL module pointer passed at snd_card object creation, and it also wraps the code around it with '#ifdef MODULE'. This works in most cases, but the dev
debian
CVE-2019-14897P3CRITICALCVSS 9.8fixed in linux 5.4.19-1 (bookworm)2019
CVE-2019-14897 [CRITICAL] CVE-2019-14897: linux - A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6....
A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecting stations together without the use of an AP) and connects to another STA.
Scope: local
bookworm: resolve
debian
CVE-2018-7273P4MEDIUMCVSS 5.5PoCfixed in linux 4.15.4-1 (bookworm)2018
CVE-2018-7273 [MEDIUM] CVE-2018-7273: linux - In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of k...
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the function show_floppy in drivers/block/floppy.c. An attacker can read this information from dmesg and use the addresses to find the locations of kernel code and data and bypass kernel security protections such as KASLR.
Scop
debian
CVE-2021-47274P3CRITICALCVSS 9.8fixed in linux 5.10.46-1 (bookworm)2021
CVE-2021-47274 [CRITICAL] CVE-2021-47274: linux - In the Linux kernel, the following vulnerability has been resolved: tracing: Co...
In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered from severe kernel crashes due to memory corruption on our production environment, like, Call Trace: [1640542.554277] general protection fault: 0000 [#1] SMP PTI [1640542.554856] CPU: 17 PID: 26996 Comm: python Kdump:
debian
CVE-2026-23455P3UNKNOWNfixed in linux 6.19.10-1 (forky)2026
CVE-2026-23455 CVE-2026-23455: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit length from the packet, then decrements it by 1 to skip the protocol discriminator byte before passing it to DecodeH323_UserInformation(). If the encoded length is 0, the decrement wra
debian
CVE-2024-27053P3CRITICALCVSS 9.1fixed in linux 6.1.85-1 (bookworm)2024
CVE-2024-27053 [CRITICAL] CVE-2024-27053: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1...
In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix RCU usage in connect path With lockdep enabled, calls to the connect function from cfg802.11 layer lead to the following warning: ============================= WARNING: suspicious RCU usage 6.7.0-rc1-wt+ #333 Not tainted ----------------------------- drivers/net/wireless/microc
debian
CVE-2019-15794P4HIGHCVSS 7.1PoCfixed in linux 5.16.7-1 (bookworm)2019
CVE-2019-15794 [HIGH] CVE-2019-15794: linux - Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux ker...
Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handlers. On error the original value is not restored, and the reference is put for the file to which vm_file points. On upstream kernels this is not an issue, as no callers dereference vm_file fo
debian
CVE-2014-4014P4MEDIUMCVSS 6.2PoCfixed in linux 3.14.7-1 (bookworm)2014
CVE-2014-4014 [MEDIUM] CVE-2014-4014: linux - The capabilities implementation in the Linux kernel before 3.14.8 does not prope...
The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setting the setgid bit on a file with group ownership of root.
Scope: local
bookworm: resolved (fixed in 3.14.7-1)
debian
CVE-2017-12762P3LOWCVSS 9.8fixed in linux 4.13.4-1 (bookworm)2017
CVE-2017-12762 [CRITICAL] CVE-2017-12762: linux - In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local...
In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can cause a buffer overflow. This affects the Linux kernel 4.9-stable tree, 4.12-stable tree, 3.18-stable tree, and 4.4-stable tree.
Scope: local
bookworm: resolved (fixed in 4.13.4-1)
bullseye: resolved (fixed in 4.13.
debian
CVE-2024-47659P3HIGHCVSS 8.8fixed in linux 6.1.112-1 (bookworm)2024
CVE-2024-47659 [HIGH] CVE-2024-47659: linux - In the Linux kernel, the following vulnerability has been resolved: smack: tcp:...
In the Linux kernel, the following vulnerability has been resolved: smack: tcp: ipv4, fix incorrect labeling Currently, Smack mirrors the label of incoming tcp/ipv4 connections: when a label 'foo' connects to a label 'bar' with tcp/ipv4, 'foo' always gets 'foo' in returned ipv4 packets. So, 1) returned packets are incorrectly labeled ('foo' instead of 'bar') 2) 'bar'
debian
CVE-2019-15504P3CRITICALCVSS 9.8fixed in linux 5.2.17-1 (bookworm)2019
CVE-2019-15504 [CRITICAL] CVE-2019-15504: linux - drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a D...
drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).
Scope: local
bookworm: resolved (fixed in 5.2.17-1)
bullseye: resolved (fixed in 5.2.17-1)
forky: resolved (fixed in 5.2.17-1)
sid: resolved (fixed in 5.2.17-1)
trixie: resolved (fixed in 5.2.17-1)
debian
CVE-2016-10150P3CRITICALCVSS 9.8fixed in linux 4.8.15-1 (bookworm)2016
CVE-2016-10150 [CRITICAL] CVE-2016-10150: linux - Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm...
Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to cause a denial of service (host OS crash) or possibly gain privileges via crafted ioctl calls on the /dev/kvm device.
Scope: local
bookworm: resolved (fixed in 4.8.15-1)
bullseye: resolved (fixed in 4.8.15-1)
forky:
debian
CVE-2019-15926P3CRITICALCVSS 9.1fixed in linux 5.2.6-1 (bookworm)2019
CVE-2019-15926 [CRITICAL] CVE-2019-15926: linux - An issue was discovered in the Linux kernel before 5.2.3. Out of bounds access e...
An issue was discovered in the Linux kernel before 5.2.3. Out of bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx and ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in
debian
CVE-2019-3846P3HIGHCVSS 8.8fixed in linux 4.19.37-4 (bookworm)2019
CVE-2019-3846 [HIGH] CVE-2019-3846: linux - A flaw that allowed an attacker to corrupt memory and possibly escalate privileg...
A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.
Scope: local
bookworm: resolved (fixed in 4.19.37-4)
bullseye: resolved (fixed in 4.19.37-4)
forky: resolved (fixed in 4.19.37-4)
sid: resolved (fixed in 4.19.37-4)
trixie: resolved (fixed in 4.19.37-
debian