VendorsDebiandebian_linux11.0
Vulnerabilities

Debian Debian Linux 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2060CVEs
CVE-2025-37938
tracing: Verify event formats that have "%*p.."
Published 2025-05-20 · Modified
7.1EPSS 0.002
CVE-2025-38103
HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse()
Published 2025-07-03 · Analyzed
7.1EPSS 0.002
CVE-2025-38027
regulator: max20086: fix invalid memory access
Published 2025-06-18 · Analyzed
7.1EPSS 0.002
CVE-2024-58054
staging: media: max96712: fix kernel oops when removing module
Published 2025-03-06 · Analyzed
7.1EPSS 0.002
CVE-2025-38286
pinctrl: at91: Fix possible out-of-boundary access
Published 2025-07-10 · Analyzed
7.1EPSS 0.002
CVE-2025-38320
arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth()
Published 2025-07-10 · Analyzed
7.1EPSS 0.002
CVE-2025-38153
net: usb: aqc111: fix error handling of usbnet read calls
Published 2025-07-03 · Analyzed
7.1EPSS 0.002
CVE-2025-38639
netfilter: xt_nfacct: don't assume acct name is null-terminated
Published 2025-08-22 · Modified
7.1EPSS 0.002
CVE-2025-39687
iio: light: as73211: Ensure buffer holes are zeroed
Published 2025-09-05 · Modified
7.1EPSS 0.002
CVE-2025-38529
comedi: aio_iiro_16: Fix bit shift out of bounds
Published 2025-08-16 · Analyzed
7.1EPSS 0.002
CVE-2025-38530
comedi: pcl812: Fix bit shift out of bounds
Published 2025-08-16 · Analyzed
7.1EPSS 0.002
CVE-2025-38680
media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format()
Published 2025-09-04 · Modified
7.1EPSS 0.002
CVE-2025-38445
md/raid1: Fix stack memory use after return in raid1_reshape
Published 2025-07-25 · Analyzed
7.1EPSS 0.002
CVE-2025-39760
usb: core: config: Prevent OOB read in SS endpoint companion parsing
Published 2025-09-11 · Modified
7.1EPSS 0.002
CVE-2025-39757
ALSA: usb-audio: Validate UAC3 cluster segment descriptors
Published 2025-09-11 · Modified
7.1EPSS 0.002
CVE-2025-38482
comedi: das6402: Fix bit shift out of bounds
Published 2025-07-28 · Analyzed
7.1EPSS 0.002
CVE-2025-38342
software node: Correct a OOB check in software_node_get_reference_args()
Published 2025-07-10 · Modified
7.1EPSS 0.002
CVE-2025-38483
comedi: das16m1: Fix bit shift out of bounds
Published 2025-07-28 · Analyzed
7.1EPSS 0.002
CVE-2025-38736
net: usb: asix_devices: Fix PHY address mask in MDIO bus initialization
Published 2025-09-05 · Modified
7.1EPSS 0.002
CVE-2025-38713
hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
Published 2025-09-04 · Modified
7.1EPSS 0.002
CVE-2025-38528
bpf: Reject %p% format string in bprintf-like helpers
Published 2025-08-16 · Modified
7.1EPSS 0.002
CVE-2025-39685
comedi: pcl726: Prevent invalid irq number
Published 2025-09-05 · Modified
7.1EPSS 0.002
CVE-2025-38249
ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3()
Published 2025-07-09 · Analyzed
7.1EPSS 0.002
CVE-2025-39891
wifi: mwifiex: Initialize the chan_stats array to zero
Published 2025-10-01 · Analyzed
7.1EPSS 0.002
CVE-2025-39902
mm/slub: avoid accessing metadata when pointer is invalid in object_err()
Published 2025-10-01 · Modified
7.1EPSS 0.002
CVE-2025-39817
efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
Published 2025-09-16 · Modified
7.1EPSS 0.002
CVE-2025-39853
i40e: Fix potential invalid access when MAC list is empty
Published 2025-09-19 · Modified
7.1EPSS 0.002
CVE-2025-38497
usb: gadget: configfs: Fix OOB read on empty string write
Published 2025-07-28 · Analyzed
7.1EPSS 0.002
CVE-2025-38159
wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds
Published 2025-07-03 · Analyzed
7.1EPSS 0.002
CVE-2025-38088
powerpc/powernv/memtrace: Fix out of bounds issue in memtrace mmap
Published 2025-06-30 · Analyzed
7.1EPSS 0.002
CVE-2025-39883
mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory
Published 2025-09-23 · Analyzed
7.1EPSS 0.002
CVE-2025-39719
iio: imu: bno055: fix OOB access of hw_xlate array
Published 2025-09-05 · Modified
7.1EPSS 0.002
CVE-2023-53259
VMCI: check context->notify_page after call to get_user_pages_fast() to avoid GPF
Published 2025-09-15 · Analyzed
7.1EPSS 0.001
CVE-2022-29582
In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.
Published 2022-04-22 · Analyzed
7.0EPSS 0.008
CVE-2021-3864
A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a result, if the descendant process crashes and core_pattern is set to a relative value, its core dump is stored in the current directory with uid:gid permissions. An unprivileged local user with eligible root SUID binary could use this flaw to place core dumps into root-owned directories, potentially resulting in escalation of privileges.
Published 2022-08-26 · Modified
7.0EPSS 0.008
CVE-2021-44733
A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.
Published 2021-12-22 · Analyzed
7.0EPSS 0.007
CVE-2022-23181
Local privilege escalation with FileStore
Published 2022-01-27 · Modified
7.0EPSS 0.007
CVE-2021-40490
A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.
Published 2021-09-03 · Analyzed
7.0EPSS 0.003
CVE-2022-42320
Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, there might be Xenstore nodes left with access rights containing the domid of the removed domain. This is normally no problem, as those access right entries will be corrected when such a node is written later. There is a small time window when a new domain is created, where the access rights of a past domain with the same domid as the new one will be regarded to be still valid, leading to the new domain being able to get access to a node which was meant to be accessible by the removed domain. For this to happen another domain needs to write the node before the newly created domain is being introduced to Xenstore by dom0.
Published 2022-11-01 · Modified
7.0EPSS 0.003
CVE-2022-26357
race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the smaller value range. The cleaning up of the housekeeping structures has a race, allowing for VT-d domain IDs to be leaked and flushes to be bypassed.
Published 2022-04-05 · Modified
7.0EPSS 0.003
← Prev31 / 52Next →