Skip to main content

Debian Linux Kernel Multiple Vulnerabilities

Last Update Date: 9 Jul 2026 Release Date: 6 Jul 2026 9474 Views

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Debian Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, sensitive information disclosure and remote code execution on the targeted system.

 

Note:

Proof-of-concept code is publicly available for CVE-2026-46242. An elevation of privilege vulnerability ("Bad Epoll") is found in the Linux kernel. This vulnerability could allow local attackers reuse freed memory with attacker-controlled data, potentially leading to root privileges. Hence, the risk level is rated as Medium Risk.

 

Proof-of-concept code is publicly available for CVE-2026-43499. A local attacker could potentially exploit this to gain elevated privileges or execute unauthorized code. Hence, the risk level remains unchanged as Medium Risk.

Recent research indicates that CVE-2026-43499 can chain with Firefox flaws (CVE-2026-10702) to potentially allow remote attackers to gain full device control.

 

[Updated on 2026-07-07]

Updated Description and Related Links.

 

[Updated on 2026-07-09]

Updated Impact, Description and Related Links.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure
  • Elevation of Privilege

System / Technologies affected

  • Debian 11 bullseye versions prior to 5.10.259-1
  • Debian 11 bullseye versions prior to 6.1.176-1~deb11u1
  • Debian 12 bookworm versions prior to 6.1.176-1
  • Debian stable distribution (trixie) versions prior to 6.12.95-1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link