« Volver al listado

Linux

Linux Kernel: vulnerabilidades y CVE

Linux Kernel tiene 20.603 vulnerabilidades publicadas, 8797 de ellas en los últimos 12 meses. 663 son críticas y 33 figuran en el catálogo de explotación activa de CISA.

CVE20.603
Últimos 12 meses8797
Críticas663
Explotadas activamente33

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-39682Crítica (9.8)2.9%⚠ Explotación activa5 sept 2025
In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) -…
CVE-2026-53266Alta (8.8)0.65%⚠ Explotación activa25 jun 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind…
CVE-2025-39964Media (5.5)1.00%⚠ Explotación activa13 oct 2025
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in…
CVE-2026-53362Alta (7.8)0.71%⚠ Explotación activa4 jul 2026
In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large…
CVE-2022-0995Alta (7.8)8.8%⚠ Explotación activa25 mar 2022
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged…
CVE-2022-0492Alta (7.8)5.5%⚠ Explotación activa3 mar 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to…
CVE-2026-31431Alta (7.8)3.4%⚠ Explotación activa22 abr 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is…
CVE-2018-14634Alta (7.8)15%⚠ Explotación activa25 sept 2018
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on…
CVE-2021-22555Alta (7.8)79%⚠ Explotación activa7 jul 2021
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
CVE-2025-38352Alta (7.8)1.3%⚠ Explotación activa22 jul 2025
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed…
CVE-2023-0386Alta (7.8)7.9%⚠ Explotación activa22 mar 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid…
CVE-2024-53150Alta (7.1)1.4%⚠ Explotación activa24 dic 2024
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at…
CVE-2024-53197Alta (7.8)3.6%⚠ Explotación activa27 dic 2024
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the…
CVE-2024-50302Media (5.5)0.81%⚠ Explotación activa19 nov 2024
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during…
CVE-2024-53104Alta (7.8)3.4%⚠ Explotación activa2 dic 2024
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were…
CVE-2017-1000253Alta (7.8)11%⚠ Explotación activa5 oct 2017
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April…
CVE-2022-0185Alta (8.4)25%⚠ Explotación activa11 feb 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of…
CVE-2024-36971Alta (7.8)2.7%⚠ Explotación activa10 jun 2024
In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible…
CVE-2022-2586Alta (7.8)10%⚠ Explotación activa8 ene 2024
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
CVE-2024-1086Alta (7.8)28%⚠ Explotación activa31 ene 2024
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-98164Sin puntuar0.19%—29 sept 2026
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, but page tracking is…
CVE-2026-98163Sin puntuar0.18%—26 sept 2026
In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcount The commit 260fbcb92bbea ("cgroup: Move dying_tasks cleanup from cgroup_task_release() to…
CVE-2026-98162Sin puntuar0.14%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix tree connection leak in smb2_tree_connect() See the procedure below: Disconnect the new tree connection if ksmbd_iov_pin_rsp() fails.
CVE-2026-98161Sin puntuar0.15%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: nvdimm: pmem: keep PREFLUSH before data writes pmem_submit_bio() records a REQ_PREFLUSH error, but continues to copy the bio data and can later…
CVE-2026-98160Sin puntuar0.17%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() padapter->HalData is allocated via vzalloc(), but incorrectly freed using…
CVE-2026-100079Sin puntuar0.16%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: unregister debugfs entries on teardown ucsi_register() creates per-instance debugfs entries, but ucsi_unregister() keeps them around…
CVE-2026-100078Sin puntuar0.16%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: pass correct argument to function The first argument to iwl_mei_write_cyclic_buf() should be the cldev but the q_head pointer is…
CVE-2026-100077Sin puntuar0.15%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: drm/msm: Recover HW before retire hung submit During recovery, it is not safe to retire the hung submit before we recover the GPU. Retiring the submit…
CVE-2026-100076Sin puntuar0.15%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths issue_beacon(), issue_probersp() and issue_asocrsp() obtain a management…
CVE-2026-100075Crítica (9.8)0.42%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path…
CVE-2026-100074Sin puntuar0.15%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Mark bpf_refcount field as unique BPF_REFCOUNT is not marked as a unique field, while it should be. Fix this oversight.
CVE-2026-100073Sin puntuar0.14%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: ext4: fix transaction overflow during writeback Commit 95ad8ee45cdb ("ext4: correct the reserved credits for extent conversion") was correct to note…
CVE-2026-100072Sin puntuar0.14%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: ACPI: platform: Use acpi_bus_get_primary_device() The acpi_get_first_physical_node() usage in acpi_platform_fill_resource() and…
CVE-2026-100071Sin puntuar0.16%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: net: hsr: free learned nodes on device setup failure hsr_dev_finalize() can fail after a lower-device RX handler has already been registered (slave A…
CVE-2026-100070Sin puntuar0.17%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet sashiko says: If map_addr() changes the packet length, such as when the public NAT IP…
CVE-2026-98159Sin puntuar0.16%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: validate CLC firmware records The CLC region is supplied by firmware, but the loader trusts the region count and each record…
CVE-2026-98158Sin puntuar0.16%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: ppp_async: drop the errored frame instead of resetting its headroom ppp_receive_nonmp_frame() prepends a two-byte direction tag before running the…
CVE-2026-98157Sin puntuar0.16%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation The poll_msec sysfs store file uses simple_strtoul() which accepts an unsigned…
CVE-2026-98156Alta (7.8)0.13%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: use the DMA API for resource backing on Xen On a Xen PV domain page addresses bear no relation to the real machine addresses the host would…
CVE-2026-98155Sin puntuar0.16%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Address potential out-of-bounds read in resp_worker() Although 'commit 2feec5ae5df7 ("accel/qaic: Handle DBC deactivation if the owner went…
CVE-2026-98154Alta (7)0.11%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: fix -EIO cleanup order in queue_rq On -EIO, the RDMA queue_rq path reports a host path error and then still cleans up the command and unmaps…
CVE-2026-98153Sin puntuar0.14%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: nvme: fix racy access to FDP placement id array nvme_query_fdp_info() is called per-path and therefore prone to races. It populates…
CVE-2026-98152Sin puntuar0.16%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: fix queue leak when connect backlog is exceeded When pending disconnecting queues exceed the backlog limit, the connect path only drops the…
CVE-2026-98151Sin puntuar0.16%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic Take the following unprivileged program as an example: Loading it triggers a…
CVE-2026-98150Alta (7)0.10%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix BPF_F_CPU validation for sparse CPU IDs BPF_F_CPU stores the target CPU ID in the upper 32 bits of the map operation flags.…
CVE-2026-98149Sin puntuar0.16%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix percpu map update indexing with sparse CPU IDs Per-CPU array, hash, and cgroup storage map updates without BPF_F_CPU or BPF_F_ALL_CPUS use a…
CVE-2026-98148Sin puntuar0.15%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: drm/gud: validate GUD_ROTATION_0 is present in supported rotations The rotation argument to drm_plane_create_rotation_property() is set to…
CVE-2026-98147Sin puntuar0.14%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: printk: Don't WARN on kthread_run failure. Since __kthread_create_on_node() returns -EINTR upon SIGKILL, we should not use WARN_ON() in order to catch…
CVE-2026-98146Sin puntuar0.15%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain struct amdxdna_cmd_chain contains a flexible array annotated with…
CVE-2026-98145Sin puntuar0.14%—25 sept 2026
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: reject a command chain that carries no commands A chain whose command_count is zero passes the payload length check, because…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation117
  2. T1499.004 Application or System Exploitation75
  3. T1190 Exploit Public-Facing Application21
  4. T1210 Exploitation of Remote Services20
  5. T1059 Command and Scripting Interpreter18
  6. T1005 Data from Local System14

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Linux