Debian

Debian 12 (bookworm)

14804 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 25.09.2026 10:23:28
  • Zuletzt bearbeitet 03.10.2026 11:18:23

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: cope with concurrent instance destruction Instances are refcounted. However, only memory release happens on the 1 -> 0 transition; the unlink from hashes ...

  • EPSS 0.16%
  • Veröffentlicht 25.09.2026 10:23:27
  • Zuletzt bearbeitet 25.09.2026 11:17:27

In the Linux kernel, the following vulnerability has been resolved: virtio_ring: fix stale descriptor flags after a failed packed add In a packed ring the AVAIL and USED bits sit in the descriptor itself, so writing them makes that descriptor avail...

  • EPSS 0.17%
  • Veröffentlicht 25.09.2026 10:23:26
  • Zuletzt bearbeitet 03.10.2026 11:18:23

In the Linux kernel, the following vulnerability has been resolved: virtio_console: do not free control-out buffers on remove __send_control_msg() publishes &portdev->cpkt as the control-out virtqueue cookie. remove_vqs() walks every virtqueue and ...

  • EPSS 0.2%
  • Veröffentlicht 25.09.2026 10:23:25
  • Zuletzt bearbeitet 03.10.2026 11:18:23

In the Linux kernel, the following vulnerability has been resolved: vhost/vdpa: reject VRING_NUM larger than device max vhost_vring_set_num() accepts any non-zero power-of-two queue size that fits in 16 bits. vhost-vdpa then passes that value to se...

  • EPSS 0.2%
  • Veröffentlicht 25.09.2026 10:23:25
  • Zuletzt bearbeitet 03.10.2026 11:18:22

In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx vhost_vdpa_set_config_call() swaps the eventfd_ctx_fdget() return value into v->config_ctx before checking it,...

  • EPSS 0.2%
  • Veröffentlicht 25.09.2026 10:23:24
  • Zuletzt bearbeitet 25.09.2026 11:17:27

In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: protect config_ctx from being freed under the config callback vhost_vdpa_config_cb() loads v->config_ctx and signals it without taking a reference and without holding a...

  • EPSS 0.12%
  • Veröffentlicht 25.09.2026 10:23:23
  • Zuletzt bearbeitet 03.10.2026 11:18:22

In the Linux kernel, the following vulnerability has been resolved: vdpa_sim_blk: reject out-of-range sector starts vdpasim_blk_check_range() logs an invalid start sector but continues validating the request. The subsequent unsigned capacity subtr...

  • EPSS 0.12%
  • Veröffentlicht 25.09.2026 10:23:23
  • Zuletzt bearbeitet 03.10.2026 11:18:22

In the Linux kernel, the following vulnerability has been resolved: vdpa_sim_net: check TX pull result before RX copy vringh_iov_pull_iotlb() returns a signed byte count. A failed TX pull is currently added to the unsigned byte counter and then pa...

  • EPSS 0.16%
  • Veröffentlicht 25.09.2026 10:23:22
  • Zuletzt bearbeitet 25.09.2026 11:17:27

In the Linux kernel, the following vulnerability has been resolved: vduse: validate virtqueue alignment vduse_validate_config() only checks the upper bound of vq_align. Invalid values can therefore reach vring_create_virtqueue_map(). The split-ring...

  • EPSS 0.16%
  • Veröffentlicht 25.09.2026 10:23:21
  • Zuletzt bearbeitet 25.09.2026 11:17:26

In the Linux kernel, the following vulnerability has been resolved: vhost: invalidate vring access on IOTLB transitions When VIRTIO_F_ACCESS_PLATFORM changes, cached vring pointers and IOTLB metadata are interpreted in a different address space. Ke...