Debian Security Vulnerabilities (CVEs)

Track 1,362 security vulnerabilities affecting Debian products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

176 Critical
886 High
300 Medium
🔔 Get Alerts for Debian
CVE-2025-38608 5.5

This CVE describes a data corruption vulnerability in the Linux kernel's BPF subsystem when used with kTLS (Kernel TLS). When bpf_msg_pop_data() reduc...

Aug 19, 2025
CVE-2025-38609 5.5

A NULL pointer dereference vulnerability in the Linux kernel's devfreq subsystem could cause kernel panics or system crashes when accessing governor i...

Aug 19, 2025
CVE-2025-38610 5.5

A NULL pointer dereference vulnerability in the Linux kernel's powercap subsystem allows local attackers to crash the kernel when a CPU becomes unavai...

Aug 19, 2025
CVE-2025-38612 5.5

This CVE describes a memory leak vulnerability in the Linux kernel's fbtft framebuffer driver. When the fbtft_framebuffer_alloc() function encounters ...

Aug 19, 2025
CVE-2025-38601 5.5

A use-after-free vulnerability in the Linux kernel's ath11k WiFi driver allows kernel memory corruption when the driver fails to properly clear initia...

Aug 19, 2025
CVE-2025-38602 5.5

This CVE involves a missing NULL pointer check in the iwlwifi driver in the Linux kernel. If alloc_ordered_workqueue() fails and returns NULL, the dri...

Aug 19, 2025
CVE-2025-38604 5.5

A use-after-free vulnerability in the Linux kernel's RTL8187/8187B USB WiFi driver allows a NULL pointer dereference when stopping the device. This ca...

Aug 19, 2025
CVE-2025-38587 5.5

A race condition vulnerability in the Linux kernel's IPv6 routing subsystem could cause an infinite loop in the fib6_info_uses_dev() function when RCU...

Aug 19, 2025
CVE-2025-38588 5.5

A race condition vulnerability in the Linux kernel's IPv6 routing subsystem can cause an infinite loop in the rt6_nlmsg_size() function when reading R...

Aug 19, 2025
CVE-2025-38579 7.8

This CVE involves an uninitialized memory vulnerability in the Linux kernel's F2FS filesystem driver. Attackers could exploit this to cause kernel cra...

Aug 19, 2025
CVE-2025-38581 5.5

A NULL pointer dereference vulnerability in the Linux kernel's AMD Cryptographic Coprocessor (CCP) driver causes a kernel crash when rebinding the CCP...

Aug 19, 2025
CVE-2025-38572 7.8

A vulnerability in the Linux kernel's IPv6 Generic Segmentation Offload (GSO) implementation allows crafted packets with excessive IPv6 extension head...

Aug 19, 2025
CVE-2025-38574 7.8

A kernel memory disclosure vulnerability in the Linux kernel's PPTP implementation allows reading uninitialized data from kernel memory. This affects ...

Aug 19, 2025
CVE-2025-38577 5.5

A use-after-free vulnerability in the Linux kernel's F2FS filesystem can cause kernel panic when evicting inodes. This affects systems using F2FS file...

Aug 19, 2025
CVE-2025-38578 5.5

This CVE describes a use-after-free vulnerability in the Linux kernel's F2FS filesystem driver, specifically in the f2fs_sync_inode_meta() function. A...

Aug 19, 2025
CVE-2025-38565 7.8

A Linux kernel vulnerability in the perf subsystem causes a reference count leak when memory allocation fails during perf_mmap(). This can lead to res...

Aug 19, 2025
CVE-2025-38560 5.5

This CVE addresses a cache coherency vulnerability in the Linux kernel's x86 Secure Encrypted Virtualization (SEV) implementation. It affects systems ...

Aug 19, 2025
CVE-2025-38561 4.7

A race condition vulnerability exists in the Linux kernel's ksmbd (SMB server) component where multiple concurrent session setup requests could cause ...

Aug 19, 2025
CVE-2025-38562 5.5

A null pointer dereference vulnerability in the Linux kernel's ksmbd module could cause kernel crashes or denial of service when clients send multiple...

Aug 19, 2025
CVE-2025-38563 7.8

A Linux kernel vulnerability in the perf subsystem allows reference count leaks when VMA (Virtual Memory Area) splits occur on perf ringbuffer mapping...

Aug 19, 2025
CVE-2025-38553 5.5

A Linux kernel vulnerability in the netem network emulation qdisc allows a denial-of-service condition when duplicating netems exist in the same qdisc...

Aug 19, 2025
CVE-2025-38550 7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's IPv6 multicast implementation. An attacker could potentially exploit this to c...

Aug 16, 2025
CVE-2025-38552 7.8

This CVE addresses a race condition vulnerability in the Linux kernel's MPTCP (Multipath TCP) implementation where subflow failures and subflow creati...

Aug 16, 2025
CVE-2025-38542 5.5

This CVE describes a device reference count leak in the Linux kernel's Appletalk networking module. When updating route entries, the kernel fails to p...

Aug 16, 2025
CVE-2025-38543 5.5

This CVE is a NULL pointer dereference vulnerability in the Linux kernel's NVIDIA Tegra NVDEC driver. It occurs when dma_alloc_coherent fails to alloc...

Aug 16, 2025
CVE-2025-38546 5.5

This CVE describes a memory leak vulnerability in the Linux kernel's ATM CLIP (Classical IP over ATM) subsystem. When specific ioctl commands are exec...

Aug 16, 2025
CVE-2025-38548 7.8

This CVE addresses a buffer overflow vulnerability in the Linux kernel's corsair-cpro hardware monitoring driver. Attackers could exploit this by send...

Aug 16, 2025
CVE-2025-38535 7.8

This vulnerability in the Linux kernel's Tegra XUSB PHY driver causes unbalanced regulator disable operations when transitioning USB roles. It can tri...

Aug 16, 2025
CVE-2025-38538 7.8

This CVE describes a memory corruption vulnerability in the Linux kernel's nbpfaxi DMA engine driver. The flaw allows attackers to corrupt kernel memo...

Aug 16, 2025
CVE-2025-38540 5.5

Two specific Chicony Electronics HP 5MP camera models (USB IDs 04F2:B824 and 04F2:B82C) expose a non-functional HID sensor interface in the Linux kern...

Aug 16, 2025
CVE-2025-38527 7.8

A race condition in the Linux kernel's SMB client can lead to use-after-free of memory structures during oplock break operations when unmounting. This...

Aug 16, 2025
CVE-2025-38529 7.1

This CVE describes an out-of-bounds bit shift vulnerability in the Linux kernel's comedi aio_iiro_16 driver. An attacker with local access can trigger...

Aug 16, 2025
CVE-2025-38520 5.5

A race condition in the Linux kernel's AMD GPU driver (amdkfd) can cause a deadlock when a process exits while memory management operations are in pro...

Aug 16, 2025
CVE-2025-38510 5.5

This CVE describes a potential deadlock vulnerability in the Linux kernel's KASAN (Kernel Address SANitizer) subsystem. When KASAN attempts to report ...

Aug 16, 2025
CVE-2025-38512 7.8

This CVE addresses an A-MSDU spoofing vulnerability in Linux kernel's WiFi mesh network implementation that allows attackers to inject malicious netwo...

Aug 16, 2025
CVE-2025-38514 5.5

A race condition vulnerability in the Linux kernel's AF_RXRPC subsystem can cause a kernel oops (crash) when service sockets are opened and bound but ...

Aug 16, 2025
CVE-2025-38515 4.7

A race condition in the Linux kernel's DRM scheduler can cause job scheduling to stop, leading to system hangs when waiting on DMA fences. This affect...

Aug 16, 2025
CVE-2025-38516 5.5

A vulnerability in the Linux kernel's Qualcomm pinctrl-msm driver allows user-space applications to trigger a kernel BUG() and potentially crash the s...

Aug 16, 2025
CVE-2025-38502 7.1

This vulnerability in the Linux kernel allows an attacker to perform out-of-bounds memory access via BPF programs using cgroup local storage with tail...

Aug 16, 2025
CVE-2025-38501 5.5

The Linux kernel's ksmbd SMB server component allows repeated connections from clients with the same IP address to exhaust maximum connection limits, ...

Aug 16, 2025
CVE-2025-38500 7.8

A use-after-free vulnerability in the Linux kernel's xfrm interface subsystem allows local attackers to cause a kernel panic (denial of service) or po...

Aug 12, 2025
CVE-2025-38499 5.5

This Linux kernel vulnerability allows users without proper administrative privileges in the correct user namespace to clone private mount points, pot...

Aug 11, 2025
CVE-2025-8454 9.8

CVE-2025-8454 is a critical vulnerability in the uscan tool (part of devscripts) that allows attackers to bypass OpenPGP signature verification when u...

Aug 1, 2025
CVE-2025-38494 7.8

A vulnerability in the Linux kernel's HID subsystem allows low-level transport drivers to bypass parameter validation in hid_hw_raw_request(). This co...

Jul 28, 2025
CVE-2025-38497 7.1

This vulnerability in the Linux kernel's USB gadget configfs subsystem allows an out-of-bounds read when writing empty strings to specific sysfs attri...

Jul 28, 2025
CVE-2025-38482 7.1

This CVE describes an out-of-bounds bit shift vulnerability in the Linux kernel's comedi das6402 driver. An attacker with local access can trigger a k...

Jul 28, 2025
CVE-2025-38488 7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's SMB client when using hardware crypto accelerators. The vulnerability can caus...

Jul 28, 2025
CVE-2025-38473 5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's Bluetooth L2CAP socket implementation. When exploited, it can cause ...

Jul 28, 2025
CVE-2025-38476 7.8

This is a use-after-free vulnerability in the Linux kernel's RPL (Routing Protocol for Low-Power and Lossy Networks) implementation. An attacker could...

Jul 28, 2025
CVE-2025-38478 5.5

A kernel memory initialization vulnerability in Linux Comedi subsystem allows reading uninitialized kernel memory when handling certain device instruc...

Jul 28, 2025

Why Monitor Debian Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 1,362+ known vulnerabilities affecting Debian products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Debian packages in under 60 seconds. No agents required - completely agentless scanning that works across Debian deployments.

Free vulnerability database: Access detailed information about every Debian CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Debian CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Debian CVEs Free