Debian

Debian 11 (bullseye)

9527 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 01.05.2026 14:16:21
  • Zuletzt bearbeitet 17.05.2026 16:16:16

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io() The xfstests case "generic/107" and syzbot have both reported a NULL pointer dereference. The concurren...

  • EPSS 0.12%
  • Veröffentlicht 01.05.2026 14:16:20
  • Zuletzt bearbeitet 01.06.2026 17:16:56

In the Linux kernel, the following vulnerability has been resolved: ALSA: caiaq: take a reference on the USB device in create_card() The caiaq driver stores a pointer to the parent USB device in cdev->chip.dev but never takes a reference on it. The...

  • EPSS 0.12%
  • Veröffentlicht 01.05.2026 14:16:20
  • Zuletzt bearbeitet 01.06.2026 17:16:56

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io() In f2fs_compress_write_end_io(), dec_page_count(sbi, type) can bring the F2FS_WB_CP_DATA counter to zero, unblocking...

  • EPSS 0.31%
  • Veröffentlicht 01.05.2026 14:16:20
  • Zuletzt bearbeitet 01.06.2026 17:16:57

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path smb2_ioctl_query_info() has two response-copy branches: PASSTHRU_FSCTL and the default QUERY_INFO path. The QUER...

Medienbericht
  • EPSS 0.28%
  • Veröffentlicht 01.05.2026 14:16:19
  • Zuletzt bearbeitet 02.07.2026 15:16:59

In the Linux kernel, the following vulnerability has been resolved: fuse: reject oversized dirents in page cache fuse_add_dirent_to_cache() computes a serialized dirent size from the server-controlled namelen field and copies the dirent into a sing...

  • EPSS 0.13%
  • Veröffentlicht 01.05.2026 14:16:19
  • Zuletzt bearbeitet 01.06.2026 17:16:56

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix missing validation of ticket length in non-XDR key preparsing In rxrpc_preparse(), there are two paths for parsing key payloads: the XDR path (for large payloads) and th...

  • EPSS 0.13%
  • Veröffentlicht 01.05.2026 14:16:19
  • Zuletzt bearbeitet 01.06.2026 17:16:56

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed When retrieving the ID for the CPU, don't attempt to copy the ID blob to userspace if the firmware command ...

  • EPSS 0.13%
  • Veröffentlicht 01.05.2026 14:16:19
  • Zuletzt bearbeitet 01.06.2026 17:16:56

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed When retrieving the PDH cert, don't attempt to copy the blobs to userspace if the firmware command fa...

  • EPSS 0.13%
  • Veröffentlicht 01.05.2026 14:16:19
  • Zuletzt bearbeitet 01.06.2026 17:16:56

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed When retrieving the PEK CSR, don't attempt to copy the blob to userspace if the firmware command failed. ...

  • EPSS 0.1%
  • Veröffentlicht 01.05.2026 14:16:19
  • Zuletzt bearbeitet 08.09.2026 09:17:59

In the Linux kernel, the following vulnerability has been resolved: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() In tpacket_snd(), when PACKET_VNET_HDR is enabled, vnet_hdr points directly into the mmap'd TX ring buffer shared wi...