Vulnerabilities > Debian

DATE CVE VULNERABILITY TITLE RISK
2024-06-03 CVE-2024-36960 In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix invalid reads in fence signaled events Correctly set the length of the drm_event to the size of the structure that's actually used. The length of the drm_event was set to the parent structure instead of to the drm_vmw_event_fence which is supposed to be read.
local
low complexity
linux debian
7.1
2024-05-30 CVE-2024-36940 Double Free vulnerability in multiple products
In the Linux kernel, the following vulnerability has been resolved: pinctrl: core: delete incorrect free in pinctrl_enable() The "pctldev" struct is allocated in devm_pinctrl_register_and_init(). It's a devm_ managed pointer that is freed by devm_pinctrl_dev_release(), so freeing it in pinctrl_enable() will lead to a double free. The devm_pinctrl_dev_release() function frees the pindescs and destroys the mutex as well.
local
low complexity
linux debian CWE-415
7.8
2024-05-30 CVE-2024-36941 NULL Pointer Dereference vulnerability in multiple products
In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: don't free NULL coalescing rule If the parsing fails, we can dereference a NULL pointer here.
local
low complexity
linux debian CWE-476
5.5
2024-05-30 CVE-2024-36954 Memory Leak vulnerability in multiple products
In the Linux kernel, the following vulnerability has been resolved: tipc: fix a possible memleak in tipc_buf_append __skb_linearize() doesn't free the skb when it fails, so move '*buf = NULL' after __skb_linearize(), so that the skb can be freed on the err path.
local
low complexity
linux debian CWE-401
5.5
2024-05-22 CVE-2024-4453 Integer Overflow or Wraparound vulnerability in multiple products
GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability.
local
low complexity
gstreamer-project debian CWE-190
7.8
2024-05-19 CVE-2024-35922 Divide By Zero vulnerability in multiple products
In the Linux kernel, the following vulnerability has been resolved: fbmon: prevent division by zero in fb_videomode_from_videomode() The expression htotal * vtotal can have a zero value on overflow.
local
low complexity
linux debian CWE-369
5.5
2024-05-19 CVE-2024-35925 Divide By Zero vulnerability in multiple products
In the Linux kernel, the following vulnerability has been resolved: block: prevent division by zero in blk_rq_stat_sum() The expression dst->nr_samples + src->nr_samples may have zero value on overflow.
local
low complexity
linux debian CWE-369
5.5
2024-05-19 CVE-2024-35930 Memory Leak vulnerability in multiple products
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix possible memory leak in lpfc_rcv_padisc() The call to lpfc_sli4_resume_rpi() in lpfc_rcv_padisc() may return an unsuccessful status.
local
low complexity
linux debian CWE-401
5.5
2024-05-19 CVE-2024-35933 NULL Pointer Dereference vulnerability in multiple products
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Fix null ptr deref in btintel_read_version If hci_cmd_sync_complete() is triggered and skb is NULL, then hdev->req_skb is NULL, which will cause this issue.
local
low complexity
linux debian CWE-476
5.5
2024-05-19 CVE-2024-35895 Improper Locking vulnerability in multiple products
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Prevent lock inversion deadlock in map delete elem syzkaller started using corpuses where a BPF tracing program deletes elements from a sockmap/sockhash map.
local
low complexity
linux debian CWE-667
5.5