VulnSea

debian has 6 CVEs on record between 2018 and 2026. 1 was published in the last 90 days. The median CVSS is 7.8 (high). None have a confirmed exploitation report. The most common weakness class is CWE-416 (3). Most affected products: debian_linux (4), dpkg (1), live-boot (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
1 prev 0

Products

  • debian_linux 4
  • dpkg 1
  • live-boot 1
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

debian vulnerabilities

CVEs affecting debian, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-89169Medium· 4.1
1w ago

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

SunlitDebian · live-bootEPSS 0.11%via NVD
CVE-2025-6297High· 8.2
1y ago

It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe operation even on untrusted data

It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe operation even on untrusted data. This may result in leavin…

Twilightdebian · dpkgEPSS 0.38%via NVD
CVE-2024-50063High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Prevent tail call between progs attached to different hooks bpf progs can be attached to kernel functions, and the attached functions can take different parameter…

In the Linux kernel, the following vulnerability has been resolved: bpf: Prevent tail call between progs attached to different hooks bpf progs can be attached to kernel functions, and the attached functions can take different parameter…

Twilightdebian · debian_linuxEPSS 0.23%via NVD
CVE-2024-26739High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb If we're redirecting the skb, and haven't called tcf_mirred_forward(), yet, we need to tell the…

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb If we're redirecting the skb, and haven't called tcf_mirred_forward(), yet, we need to tell the…

Twilightdebian · debian_linuxEPSS 0.28%via NVD
CVE-2023-52572High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix UAF in cifs_demultiplex_thread() There is a UAF when xfstests on cifs: BUG: KASAN: use-after-free in smb2_is_network_name_deleted+0x27/0x160 Read of siz…

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix UAF in cifs_demultiplex_thread() There is a UAF when xfstests on cifs: BUG: KASAN: use-after-free in smb2_is_network_name_deleted+0x27/0x160 Read of siz…

Twilightdebian · debian_linuxEPSS 0.23%via NVD
CVE-2018-10902High· 7.8
8y ago

It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() han…

It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() han…

Twilightdebian · debian_linuxEPSS 0.52%via NVD
debian vulnerabilities (CVEs) · VulnSea