Multiple vulnerabilities in Debian Linux kernel allow privilege escalation, data…
Multiple vulnerabilities in Debian Linux kernel allow privilege escalation, data confidentiality breach, and denial of service on bookworm and trixie versions.
CERT-FR has issued an advisory regarding multiple security vulnerabilities discovered in the Debian Linux kernel affecting both the bookworm and trixie distributions. The vulnerabilities impact versions prior to 6.1.174-1 for Debian bookworm and versions prior to 6.12.90-2 for Debian trixie. These flaws enable attackers to perform privilege escalation, compromise data confidentiality, and cause denial of service conditions.
The advisory references five distinct CVE identifiers (CVE-2026-23171, CVE-2026-43494, CVE-2026-43503, CVE-2026-46174, CVE-2026-46300), indicating multiple discrete vulnerability classes within the kernel. Debian has released security bulletins between May 23-28, 2026, providing patches to address these issues.
Organizations running affected Debian distributions should prioritize applying the vendor-provided patches. The combination of privilege escalation and confidentiality breach capabilities makes these vulnerabilities particularly concerning for multi-tenant environments and systems processing sensitive data.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0666
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free