Debian

Debian 13 (trixie)

17738 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.16%
  • Veröffentlicht 18.07.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 08:13:32

An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read.

  • EPSS 1.18%
  • Veröffentlicht 18.07.2023 00:15:09
  • Zuletzt bearbeitet 03.01.2025 12:15:25

An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.

  • EPSS 1.16%
  • Veröffentlicht 18.07.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 08:13:33

An issue was discovered in the Linux kernel before 6.3.9. ksmbd does not validate the SMB request protocol ID, leading to an out-of-bounds read.

  • EPSS 1.16%
  • Veröffentlicht 18.07.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 08:13:33

An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/connection.c in ksmbd does not validate the relationship between the NetBIOS header's length field and the SMB header sizes, via pdu_size in ksmbd_conn_handler_loop, leading to a...

  • EPSS 2.52%
  • Veröffentlicht 18.07.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 08:13:33

An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read.

  • EPSS 0.19%
  • Veröffentlicht 17.07.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:13:30

An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc, the fbcon_registered_fb and fbcon_display arrays can be desynchronized in fbcon_mode_...

  • EPSS 0.19%
  • Veröffentlicht 13.07.2023 00:15:24
  • Zuletzt bearbeitet 13.02.2025 17:16:02

In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 13.07.2023 00:15:24
  • Zuletzt bearbeitet 13.02.2025 17:16:02

In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exp...

  • EPSS 0.29%
  • Veröffentlicht 12.07.2023 09:15:14
  • Zuletzt bearbeitet 21.11.2024 08:16:28

A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause a denial of...

  • EPSS 0.19%
  • Veröffentlicht 11.07.2023 16:15:12
  • Zuletzt bearbeitet 06.03.2025 16:15:42

A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to crash the system.