Debian Linux vulnerabilities
12,638 known vulnerabilities affecting debian/linux.
Total CVEs
12,638
CISA KEV
29
actively exploited
Public exploits
140
Exploited in wild
47
Severity breakdown
CRITICAL70HIGH2664MEDIUM6236LOW2442UNKNOWN1226
Vulnerabilities
Page 97 of 632
CVE-2016-10905P3HIGHCVSS 7.8fixed in linux 4.8.5-1 (bookworm)2016
CVE-2016-10905 [HIGH] CVE-2016-10905: linux - An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before 4.8. A use-...
An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before 4.8. A use-after-free is caused by the functions gfs2_clear_rgrpd and read_rindex_entry.
Scope: local
bookworm: resolved (fixed in 4.8.5-1)
bullseye: resolved (fixed in 4.8.5-1)
forky: resolved (fixed in 4.8.5-1)
sid: resolved (fixed in 4.8.5-1)
trixie: resolved (fixed in 4.8.5-1)
debian
CVE-2015-8962P3HIGHCVSS 7.3fixed in linux 4.4.2-1 (bookworm)2015
CVE-2015-8962 [HIGH] CVE-2015-8962: linux - Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c i...
Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (memory corruption and system crash) by detaching a device during an SG_IO ioctl call.
Scope: local
bookworm: resolved (fixed in 4.4.2-1)
bullseye: resolved (fixed in 4.4.2-1)
forky: resolved (fi
debian
CVE-2017-7541P3HIGHCVSS 7.8fixed in linux 4.12.6-1 (bookworm)2017
CVE-2017-7541 [HIGH] CVE-2017-7541: linux - The brcmf_cfg80211_mgmt_tx function in drivers/net/wireless/broadcom/brcm80211/b...
The brcmf_cfg80211_mgmt_tx function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.12.3 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges via a crafted NL80211_CMD_FRAME Netlink packet.
Scope: local
bookworm: resolved (fixed in 4.12.6-1)
bullseye: resolved (fixed in
debian
CVE-2018-18445P3HIGHCVSS 7.8fixed in linux 4.18.20-1 (bookworm)2018
CVE-2018-18445 [HIGH] CVE-2018-18445: linux - In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, f...
In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min_max_vals in kernel/bpf/verifier.c mishandles 32-bit right shifts.
Scope: local
bookworm: resolved (fixed in 4.18.20-1)
bullseye: resolved (fixed in 4.18.20-1)
forky: reso
debian
CVE-2018-25020P3HIGHCVSS 7.8fixed in linux 4.17.3-1 (bookworm)2018
CVE-2018-25020 [HIGH] CVE-2018-25020: linux - The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a l...
The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.
Scope: local
bookworm: resolved (fixed in 4.17.3-1)
bullseye: resolved (fixed in 4.17.
debian
CVE-2018-7566P3HIGHCVSS 7.8fixed in linux 4.15.11-1 (bookworm)2018
CVE-2018-7566 [HIGH] CVE-2018-7566: linux - The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_PO...
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
Scope: local
bookworm: resolved (fixed in 4.15.11-1)
bullseye: resolved (fixed in 4.15.11-1)
forky: resolved (fixed in 4.15.11-1)
sid: resolved (fixed in 4.15.11-1)
trixie: resolved (fixed in 4.15.11-1)
debian
CVE-2019-14815P3HIGHCVSS 7.8fixed in linux 5.2.17-1 (bookworm)2019
CVE-2019-14815 [HIGH] CVE-2019-14815: linux - A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mw...
A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
Scope: local
bookworm: resolved (fixed in 5.2.17-1)
bullseye: resolved (fixed in 5.2.17-1)
forky: resolved (fixed in 5.2.17-1)
sid: resolved (fixed in 5.2.17-1)
trixie: resolved (fixed in 5.2.17-1)
debian
CVE-2025-21945P3HIGHCVSS 7.8fixed in linux 6.1.133-1 (bookworm)2025
CVE-2025-21945 [HIGH] CVE-2025-21945: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_lock If smb_lock->zero_len has value, ->llist of smb_lock is not delete and flock is old one. It will cause use-after-free on error handling routine.
Scope: local
bookworm: resolved (fixed in 6.1.133-1)
bullseye: resolved
forky: resolved (fixed in 6.12.19-1)
sid: reso
debian
CVE-2018-16276P3HIGHCVSS 7.8fixed in linux 4.17.8-1 (bookworm)2018
CVE-2018-16276 [HIGH] CVE-2018-16276: linux - An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux k...
An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges.
Scope: local
bookworm: resolved (fixed in 4.17.8-1)
bullseye: resolved (fixed in 4.17.8-1)
forky: resolved (
debian
CVE-2017-10663P3HIGHCVSS 7.8fixed in linux 4.12.6-1 (bookworm)2017
CVE-2017-10663 [HIGH] CVE-2017-10663: linux - The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.1...
The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.12.6-1)
bullseye: resolved (fixed in 4.12.6-1)
forky: resolved (fixed in 4.12.6-1)
sid: resolved (fixed in 4.12.6-1)
trixie: r
debian
CVE-2022-26490P3HIGHCVSS 7.8fixed in linux 5.16.18-1 (bookworm)2022
CVE-2022-26490 [HIGH] CVE-2022-26490: linux - st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux k...
st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.
Scope: local
bookworm: resolved (fixed in 5.16.18-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: resolved (fixed in 5.16.18-1)
sid: resolved (fixed in 5.16.18-1)
trixie: resolved (fixed i
debian
CVE-2017-0861P3HIGHCVSS 7.8fixed in linux 4.13.4-1 (bookworm)2017
CVE-2017-0861 [HIGH] CVE-2017-0861: linux - Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem ...
Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel allows attackers to gain privileges via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.13.4-1)
bullseye: resolved (fixed in 4.13.4-1)
forky: resolved (fixed in 4.13.4-1)
sid: resolved (fixed in 4.13.4-1)
trixie: resolved (fixed in 4.13.4-1)
debian
CVE-2018-5332P3HIGHCVSS 7.8fixed in linux 4.14.17-1 (bookworm)2018
CVE-2018-5332 [HIGH] CVE-2018-5332: linux - In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not v...
In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that is used during DMA page allocation, leading to a heap-based out-of-bounds write (related to the rds_rdma_extra_size function in net/rds/rdma.c).
Scope: local
bookworm: resolved (fixed in 4.14.17-1)
bullseye: resolved (fixed in 4.14.17-1)
forky: resolved (fixed in 4.14.17
debian
CVE-2017-5669P3HIGHCVSS 7.8fixed in linux 4.9.13-1 (bookworm)2017
CVE-2017-5669 [HIGH] CVE-2017-5669: linux - The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not r...
The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and consequently bypass a protection mechanism that exists for the mmap system call, by making crafted shmget and shmat system calls in a privileged context.
Scope: local
bookworm: reso
debian
CVE-2014-9888P3HIGHCVSS 7.8fixed in linux 3.13.4-1 (bookworm)2014
CVE-2014-9888 [HIGH] CVE-2014-9888: linux - arch/arm/mm/dma-mapping.c in the Linux kernel before 3.13 on ARM platforms, as u...
arch/arm/mm/dma-mapping.c in the Linux kernel before 3.13 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not prevent executable DMA mappings, which might allow local users to gain privileges via a crafted application, aka Android internal bug 28803642 and Qualcomm internal bug CR642735.
Scope: local
bookworm: resolved (fixed
debian
CVE-2017-17450P3HIGHCVSS 7.8fixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-17450 [HIGH] CVE-2017-17450: linux - net/netfilter/xt_osf.c in the Linux kernel through 4.14.4 does not require the C...
net/netfilter/xt_osf.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for add_callback and remove_callback operations, which allows local users to bypass intended access restrictions because the xt_osf_fingers data structure is shared across all net namespaces.
Scope: local
bookworm: resolved (fixed in 4.14.7-1)
bullseye: resolved (fi
debian
CVE-2017-17448P3HIGHCVSS 7.8fixed in linux 4.14.7-1 (bookworm)2017
CVE-2017-17448 [HIGH] CVE-2017-17448: linux - net/netfilter/nfnetlink_cthelper.c in the Linux kernel through 4.14.4 does not r...
net/netfilter/nfnetlink_cthelper.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for new, get, and del operations, which allows local users to bypass intended access restrictions because the nfnl_cthelper_list data structure is shared across all net namespaces.
Scope: local
bookworm: resolved (fixed in 4.14.7-1)
bullseye: resolved (f
debian
CVE-2025-38437P3HIGHCVSS 7.8fixed in linux 6.1.147-1 (bookworm)2025
CVE-2025-38437 [HIGH] CVE-2025-38437: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potential use-after-free in oplock/lease break ack If ksmbd_iov_pin_rsp return error, use-after-free can happen by accessing opinfo->state and opinfo_put and ksmbd_fd_put could called twice.
Scope: local
bookworm: resolved (fixed in 6.1.147-1)
bullseye: resolved
forky: resolved (fixed in 6.
debian
CVE-2018-15471P3HIGHCVSS 7.8fixed in linux 4.18.10-2 (bookworm)2018
CVE-2018-15471 [HIGH] CVE-2018-15471: linux - An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/ha...
An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.x and other products. The Linux netback driver allows frontends to control mapping of requests to request queues. When processing a request to set or change this mapping, some input validation (e.g., for an integer overfl
debian
CVE-2020-15852P3HIGHCVSS 7.8fixed in linux 5.7.10-1 (bookworm)2020
CVE-2020-15852 [HIGH] CVE-2020-15852: linux - An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen th...
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
Scope: local
bookworm: resolved
debian