VendorsDebiandebian_linux11.0
Vulnerabilities

Debian Debian Linux 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2060CVEs
CVE-2021-28708
PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). The implementation of some of these hypercalls for PoD does not enforce the base page frame number to be suitably aligned for the specified order, yet some code involved in PoD handling actually makes such an assumption. These operations are XENMEM_decrease_reservation (CVE-2021-28704) and XENMEM_populate_physmap (CVE-2021-28707), the latter usable only by domains controlling the guest, i.e. a de-privileged qemu or a stub domain. (Patch 1, combining the fix to both these two issues.) In addition handling of XENMEM_decrease_reservation can also trigger a host crash when the specified page order is neither 4k nor 2M nor 1G (CVE-2021-28708, patch 2).
Published 2021-11-24 · Modified
8.8EPSS 0.004
CVE-2021-44730
snapd could be made to escalate privileges and run programs as administrator
Published 2022-02-17 · Modified
8.8EPSS 0.004
CVE-2025-37885
KVM: x86: Reset IRTE to host control if *new* route isn't postable
Published 2025-05-09 · Modified
8.8EPSS 0.003
CVE-2022-33745
insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.
Published 2022-07-26 · Modified
8.8EPSS 0.003
CVE-2025-38495
HID: core: ensure the allocated report buffer can contain the reserved report ID
Published 2025-07-28 · Modified
8.8EPSS 0.003
CVE-2022-42309
Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the error path can be controlled by the guest e.g. by exceeding the quota value of maximum nodes per domain.
Published 2022-11-01 · Modified
8.8EPSS 0.003
CVE-2025-38293
wifi: ath11k: fix node corruption in ar->arvifs list
Published 2025-07-10 · Modified
8.8EPSS 0.003
CVE-2025-37849
KVM: arm64: Tear down vGIC on failed vCPU creation
Published 2025-05-09 · Modified
8.8EPSS 0.003
CVE-2025-39839
batman-adv: fix OOB read/write in network-coding decode
Published 2025-09-19 · Modified
8.8EPSS 0.003
CVE-2025-38174
thunderbolt: Do not double dequeue a configuration request
Published 2025-07-04 · Modified
8.8EPSS 0.003
CVE-2025-38377
rose: fix dangling neighbour pointers in rose_rt_device_down()
Published 2025-07-25 · Modified
8.8EPSS 0.002
CVE-2025-38601
wifi: ath11k: clear initialized flag for deinit-ed srng lists
Published 2025-08-19 · Modified
8.8EPSS 0.002
CVE-2025-39848
ax25: properly unshare skbs in ax25_kiss_rcv()
Published 2025-09-19 · Modified
8.8EPSS 0.002
CVE-2025-39806
HID: multitouch: fix slab out-of-bounds access in mt_report_fixup()
Published 2025-09-16 · Modified
8.8EPSS 0.002
CVE-2025-37790
net: mctp: Set SOCK_RCU_FREE
Published 2025-05-01 · Modified
8.8EPSS 0.002
CVE-2025-39864
wifi: cfg80211: fix use-after-free in cmp_bss()
Published 2025-09-19 · Modified
8.8EPSS 0.002
CVE-2025-38512
wifi: prevent A-MSDU attacks in mesh networks
Published 2025-08-16 · Modified
8.8EPSS 0.002
CVE-2025-39849
wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result()
Published 2025-09-19 · Modified
8.8EPSS 0.002
CVE-2025-39827
net: rose: include node references in rose_neigh refcount
Published 2025-09-16 · Modified
8.8EPSS 0.002
CVE-2025-39826
net: rose: convert 'use' field to refcount_t
Published 2025-09-16 · Modified
8.8EPSS 0.002
CVE-2025-38074
vhost-scsi: protect vq->log_used with vq->mutex
Published 2025-06-18 · Modified
8.8EPSS 0.002
CVE-2024-52301
Laravel allows environment manipulation via query string
Published 2024-11-12 · Analyzed
8.7EPSS 0.448
CVE-2025-37936
perf/x86/intel: KVM: Mask PEBS_ENABLE loaded for guest with vCPU's value.
Published 2025-05-20 · Modified
8.7EPSS 0.002
CVE-2021-21349
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
Published 2021-03-22 · Analyzed
8.6EPSS 0.468
CVE-2021-37701
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
Published 2021-08-31 · Modified
8.6EPSS 0.033
CVE-2021-28706
guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.
Published 2021-11-24 · Modified
8.6EPSS 0.022
CVE-2021-37712
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
Published 2021-08-31 · Modified
8.6EPSS 0.019
CVE-2021-43860
Permissions granted to applications can be hidden from the user at install time
Published 2022-01-12 · Modified
8.6EPSS 0.013
CVE-2022-42333
x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would otherwise be put in place. While not exposed to the affected guests themselves, the interface specifically exists for domains controlling such guests. This interface may therefore be used by not fully privileged entities, e.g. qemu running deprivileged in Dom0 or qemu running in a so called stub-domain. With this exposure it is an issue that - the number of the such controlled regions was unbounded (CVE-2022-42333), - installation and removal of such regions was not properly serialized (CVE-2022-42334).
Published 2023-03-21 · Modified
8.6EPSS 0.012
CVE-2025-62600
eprosima Fast DDS affected by Out-of-Memory in readBinaryPropertySeq via Manipulated DATA Submessage when DDS Security is enabled
Published 2026-02-03 · Modified
8.6EPSS 0.004
CVE-2025-38608
bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls
Published 2025-08-19 · Modified
8.6EPSS 0.004
CVE-2025-62599
eprosima Fast DDS affected by Out-of-Memory in readPropertySeq via Manipulated DATA Submessage when DDS Security is enabled
Published 2026-02-03 · Modified
8.6EPSS 0.004
CVE-2025-38574
pptp: ensure minimal skb length in pptp_xmit()
Published 2025-08-19 · Modified
8.6EPSS 0.004
CVE-2025-64512
pdfminer.six vulnerable to Arbitrary Code Execution via Crafted PDF Input
Published 2025-11-10 · Modified
8.6EPSS 0.003
CVE-2021-39144
XStream is vulnerable to a Remote Command Execution attack
Published 2021-08-23 · Analyzed
8.5KEVEPSS 0.981
CVE-2021-39141
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.161
CVE-2021-39146
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.143
CVE-2021-39152
A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling
Published 2021-08-23 · Analyzed
8.5EPSS 0.114
CVE-2021-39147
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39148
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
← Prev12 / 52Next →