Debian

Debian 14 (forky)

13671 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 03.04.2026 13:24:23
  • Zuletzt bearbeitet 27.04.2026 14:16:31

In the Linux kernel, the following vulnerability has been resolved: net/rds: Fix circular locking dependency in rds_tcp_tune syzbot reported a circular locking dependency in rds_tcp_tune() where sk_net_refcnt_upgrade() is called while holding the s...

  • EPSS 0.02%
  • Veröffentlicht 03.04.2026 13:24:22
  • Zuletzt bearbeitet 24.04.2026 15:21:40

In the Linux kernel, the following vulnerability has been resolved: drm/xe/reg_sr: Fix leak on xa_store failure Free the newly allocated entry when xa_store() fails to avoid a memory leak on the error path. v2: use goto fail_free. (Bala) (cherry ...

  • EPSS 0.01%
  • Veröffentlicht 02.04.2026 11:40:57
  • Zuletzt bearbeitet 24.04.2026 15:21:59

In the Linux kernel, the following vulnerability has been resolved: mm/mseal: update VMA end correctly on merge Previously we stored the end of the current VMA in curr_end, and then upon iterating to the next VMA updated curr_start to curr_end to a...

  • EPSS 0.02%
  • Veröffentlicht 02.04.2026 11:40:57
  • Zuletzt bearbeitet 24.04.2026 15:21:51

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix constant blinding for PROBE_MEM32 stores BPF_ST | BPF_PROBE_MEM32 immediate stores are not handled by bpf_jit_blind_insn(), allowing user-controlled 32-bit immediates to s...

  • EPSS 0.02%
  • Veröffentlicht 02.04.2026 11:40:56
  • Zuletzt bearbeitet 27.04.2026 14:16:31

In the Linux kernel, the following vulnerability has been resolved: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() During futex_key_to_node_opt() execution, vma->vm_policy is read under speculative mmap lock and RCU. Concur...

  • EPSS 0.04%
  • Veröffentlicht 02.04.2026 11:40:55
  • Zuletzt bearbeitet 27.04.2026 14:16:31

In the Linux kernel, the following vulnerability has been resolved: tls: Purge async_hold in tls_decrypt_async_wait() The async_hold queue pins encrypted input skbs while the AEAD engine references their scatterlist data. Once tls_decrypt_async_wai...

  • EPSS 0.02%
  • Veröffentlicht 02.04.2026 11:40:54
  • Zuletzt bearbeitet 27.04.2026 14:16:31

In the Linux kernel, the following vulnerability has been resolved: clsact: Fix use-after-free in init/destroy rollback asymmetry Fix a use-after-free in the clsact qdisc upon init/destroy rollback asymmetry. The latter is achieved by first fully i...

  • EPSS 0.02%
  • Veröffentlicht 02.04.2026 11:40:53
  • Zuletzt bearbeitet 27.04.2026 14:16:31

In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: defer hook memory release until rcu readers are done Yiming Qian reports UaF when concurrent process is dumping hooks via nfnetlink_hooks: BUG: KASAN: slab-use-aft...

  • EPSS 0.01%
  • Veröffentlicht 01.04.2026 08:36:39
  • Zuletzt bearbeitet 24.04.2026 15:23:43

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is a race condition that leads to a use-after-free situation: because the rawdata inodes are not refcounted, an attacker can start o...

  • EPSS 0.01%
  • Veröffentlicht 01.04.2026 08:36:39
  • Zuletzt bearbeitet 24.04.2026 15:23:12

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs accessing it AppArmor was putting the reference to i_private data on its end after removing the original entry from the file system. ...