VendorsDebiandebian_linuxall versions
Vulnerabilities

Debian Debian Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10063CVEs
CVE-2021-3653
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "int_ctl" field, this issue could allow a malicious L1 to enable AVIC support (Advanced Virtual Interrupt Controller) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape. This flaw affects Linux kernel versions prior to 5.14-rc7.
Published 2021-09-29 · Modified
8.8EPSS 0.004
CVE-2018-19966
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.
Published 2018-12-08 · Modified
8.8EPSS 0.004
CVE-2017-12137
arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
Published 2017-08-24 · Modified
8.8EPSS 0.004
CVE-2021-41133
Sandbox bypass via recent VFS-manipulating syscalls
Published 2021-10-08 · Modified
8.8EPSS 0.004
CVE-2018-7541
An issue was discovered in Xen through 4.10.x allowing guest OS users to cause a denial of service (hypervisor crash) or gain privileges by triggering a grant-table transition from v2 to v1.
Published 2018-02-27 · Modified
8.8EPSS 0.004
CVE-2020-11741
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information about other guests, cause a denial of service, or possibly gain privileges. For guests for which "active" profiling was enabled by the administrator, the xenoprof code uses the standard Xen shared ring structure. Unfortunately, this code did not treat the guest as a potential adversary: it trusts the guest not to modify buffer size information or modify head / tail pointers in unexpected ways. This can crash the host (DoS). Privilege escalation cannot be ruled out.
Published 2020-04-14 · Modified
8.8EPSS 0.004
CVE-2020-29569
An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thread handler to reset ring->xenblkd to NULL when stopped. However, the handler may not have time to run if the frontend quickly toggles between the states connect and disconnect. As a consequence, the block backend may re-use a pointer after it was freed. A misbehaving guest can trigger a dom0 crash by continuously connecting / disconnecting a block frontend. Privilege escalation and information leaks cannot be ruled out. This only affects systems with a Linux blkback.
Published 2020-12-15 · Modified
8.8EPSS 0.004
CVE-2025-38437
ksmbd: fix potential use-after-free in oplock/lease break ack
Published 2025-07-25 · Modified
8.8EPSS 0.004
CVE-2018-16877
A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local privilege escalation.
Published 2019-04-18 · Modified
8.8EPSS 0.004
CVE-2018-6553
AppArmor cupsd Sandbox Bypass Due to Use of Hard Links
Published 2018-08-10 · Modified
8.8EPSS 0.004
CVE-2024-35969
ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr
Published 2024-05-20 · Modified
8.8EPSS 0.004
CVE-2021-28707
PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). The implementation of some of these hypercalls for PoD does not enforce the base page frame number to be suitably aligned for the specified order, yet some code involved in PoD handling actually makes such an assumption. These operations are XENMEM_decrease_reservation (CVE-2021-28704) and XENMEM_populate_physmap (CVE-2021-28707), the latter usable only by domains controlling the guest, i.e. a de-privileged qemu or a stub domain. (Patch 1, combining the fix to both these two issues.) In addition handling of XENMEM_decrease_reservation can also trigger a host crash when the specified page order is neither 4k nor 2M nor 1G (CVE-2021-28708, patch 2).
Published 2021-11-24 · Modified
8.8EPSS 0.004
CVE-2024-26931
scsi: qla2xxx: Fix command flush on cable pull
Published 2024-05-01 · Modified
8.8EPSS 0.004
CVE-2024-49950
Bluetooth: L2CAP: Fix uaf in l2cap_connect
Published 2024-10-21 · Modified
8.8EPSS 0.004
CVE-2020-15565
An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables are shared between IOMMU and CPU, changes to them require flushing of both TLBs. Furthermore, IOMMUs may be non-coherent, and hence prior to flushing IOMMU TLBs, a CPU cache also needs writing back to memory after changes were made. Such writing back of cached data was missing in particular when splitting large page mappings into smaller granularity ones. A malicious guest may be able to retain read/write DMA access to frames returned to Xen's free pool, and later reused for another purpose. Host crashes (leading to a Denial of Service) and privilege escalation cannot be ruled out. Xen versions from at least 3.2 onwards are affected. Only x86 Intel systems are affected. x86 AMD as well as Arm systems are not affected. Only x86 HVM guests using hardware assisted paging (HAP), having a passed through PCI device assigned, and having page table sharing enabled can leverage the vulnerability. Note that page table sharing will be enabled (by default) only if Xen considers IOMMU and CPU large page size support compatible.
Published 2020-07-07 · Modified
8.8EPSS 0.004
CVE-2024-27416
Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST
Published 2024-05-17 · Modified
8.8EPSS 0.004
CVE-2019-17340
An issue was discovered in Xen through 4.11.x allowing x86 guest OS users to cause a denial of service or gain privileges because grant-table transfer requests are mishandled.
Published 2019-10-08 · Modified
8.8EPSS 0.004
CVE-2024-35811
wifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach
Published 2024-05-17 · Modified
8.8EPSS 0.004
CVE-2021-28704
PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). The implementation of some of these hypercalls for PoD does not enforce the base page frame number to be suitably aligned for the specified order, yet some code involved in PoD handling actually makes such an assumption. These operations are XENMEM_decrease_reservation (CVE-2021-28704) and XENMEM_populate_physmap (CVE-2021-28707), the latter usable only by domains controlling the guest, i.e. a de-privileged qemu or a stub domain. (Patch 1, combining the fix to both these two issues.) In addition handling of XENMEM_decrease_reservation can also trigger a host crash when the specified page order is neither 4k nor 2M nor 1G (CVE-2021-28708, patch 2).
Published 2021-11-24 · Modified
8.8EPSS 0.004
CVE-2021-28708
PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). The implementation of some of these hypercalls for PoD does not enforce the base page frame number to be suitably aligned for the specified order, yet some code involved in PoD handling actually makes such an assumption. These operations are XENMEM_decrease_reservation (CVE-2021-28704) and XENMEM_populate_physmap (CVE-2021-28707), the latter usable only by domains controlling the guest, i.e. a de-privileged qemu or a stub domain. (Patch 1, combining the fix to both these two issues.) In addition handling of XENMEM_decrease_reservation can also trigger a host crash when the specified page order is neither 4k nor 2M nor 1G (CVE-2021-28708, patch 2).
Published 2021-11-24 · Modified
8.8EPSS 0.004
CVE-2020-24489
Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2021-06-09 · Modified
8.8EPSS 0.004
CVE-2021-44730
snapd could be made to escalate privileges and run programs as administrator
Published 2022-02-17 · Modified
8.8EPSS 0.004
CVE-2020-29481
An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain created with the same domid will inherit the access rights to Xenstore nodes from the previous domain(s) with the same domid. Because all Xenstore entries of a guest below /local/domain/<domid> are being deleted by Xen tools when a guest is destroyed, only Xenstore entries of other guests still running are affected. For example, a newly created guest domain might be able to read sensitive information that had belonged to a previously existing guest domain. Both Xenstore implementations (C and Ocaml) are vulnerable.
Published 2020-12-15 · Modified
8.8EPSS 0.004
CVE-2019-17346
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatibility between Process Context Identifiers (PCID) and TLB flushes.
Published 2019-10-08 · Modified
8.8EPSS 0.003
CVE-2025-38495
HID: core: ensure the allocated report buffer can contain the reserved report ID
Published 2025-07-28 · Modified
8.8EPSS 0.003
CVE-2024-35915
nfc: nci: Fix uninit-value in nci_dev_up and nci_ntf_packet
Published 2024-05-19 · Modified
8.8EPSS 0.003
CVE-2025-38293
wifi: ath11k: fix node corruption in ar->arvifs list
Published 2025-07-10 · Modified
8.8EPSS 0.003
CVE-2020-29479
An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the tree has special cases for the root node, because this node has no parent. Unfortunately, permissions were not checked for certain operations on the root node. Unprivileged guests can get and modify permissions, list, and delete the root node. (Deleting the whole xenstore tree is a host-wide denial of service.) Achieving xenstore write access is also possible. All systems using oxenstored are vulnerable. Building and using oxenstored is the default in the upstream Xen distribution, if the Ocaml compiler is available. Systems using C xenstored are not vulnerable.
Published 2020-12-15 · Modified
8.8EPSS 0.003
CVE-2025-37885
KVM: x86: Reset IRTE to host control if *new* route isn't postable
Published 2025-05-09 · Modified
8.8EPSS 0.003
CVE-2022-33745
insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.
Published 2022-07-26 · Modified
8.8EPSS 0.003
CVE-2022-2196
Speculative execution attacks in KVM VMX
Published 2023-01-09 · Modified
8.8EPSS 0.003
CVE-2022-42309
Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the error path can be controlled by the guest e.g. by exceeding the quota value of maximum nodes per domain.
Published 2022-11-01 · Modified
8.8EPSS 0.003
CVE-2024-26779
wifi: mac80211: fix race condition on enabling fast-xmit
Published 2024-04-03 · Modified
8.8EPSS 0.003
CVE-2025-37849
KVM: arm64: Tear down vGIC on failed vCPU creation
Published 2025-05-09 · Modified
8.8EPSS 0.003
CVE-2025-39839
batman-adv: fix OOB read/write in network-coding decode
Published 2025-09-19 · Modified
8.8EPSS 0.003
CVE-2025-38174
thunderbolt: Do not double dequeue a configuration request
Published 2025-07-04 · Modified
8.8EPSS 0.003
CVE-2025-38377
rose: fix dangling neighbour pointers in rose_rt_device_down()
Published 2025-07-25 · Modified
8.8EPSS 0.002
CVE-2025-37790
net: mctp: Set SOCK_RCU_FREE
Published 2025-05-01 · Modified
8.8EPSS 0.002
CVE-2025-38601
wifi: ath11k: clear initialized flag for deinit-ed srng lists
Published 2025-08-19 · Modified
8.8EPSS 0.002
CVE-2024-26598
KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache
Published 2024-02-23 · Modified
8.8EPSS 0.002
← Prev58 / 252Next →