Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
34.309 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Baja (3) | — | — | Linuxfoundation BackstageAI | 6/10/2026 | 6/10/2026 | Backstage is an open framework for building developer portals. Prior to 1.54.6, cloud storage catalog providers did not sufficiently validate object paths. A principal able to create or rename objects in a configured Azure Blob Storage or AWS S3 catalog source could cause catalog descriptors to be read from outside… | |
| Recibida | Media (6.4) | — | — | Linuxfoundation BackstageAI | 6/10/2026 | 6/10/2026 | Backstage is an open framework for building developer portals. Prior to 1.54.6, scaffolder source-control actions may not consistently enforce intended credential boundaries. An authenticated user could cause an affected action to fall back to broader integration credentials and perform operations with more access… | |
| Pendiente de análisis | Media (6.8) | — | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Pendiente de análisis | Alta (7) | — | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk() iptfs_skb_reset_frag_walk() advances to the fragment containing @offset with an unbounded loop: walk->fragi is advanced and walk->frags[walk->fragi] is dereferenced without ever checking… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix runt reassembly panic from short inner tot_len When the start of an inner packet is split across two outer packets such that fewer than 4 bytes land at the end of the first one, __input_process_payload() saves those bytes as a runt… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: fix compat ALLOCSPI request use-after-free xfrm_state_netlink() builds the ALLOCSPI response with dump_one_state(), which already calls alloc_compat() with the response skb and header. xfrm_alloc_userspi() then calls alloc_compat() again, but… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() syzbot reported a suspicious RCU usage warning in ip6_pkt_drop(): When commit 4f4920669d21 ("xfrm: Reinject transport-mode packets through workqueue")… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: esp: downgrade zerocopy managed frags before mutating skb frags On the out-of-place output path (esp->inplace == false) ESP rewrites the skb frag array: esp_output_head() appends a trailer frag and esp_output_tail() replaces the frags with a… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept We need to clear cep before release state_lock as siw_qp_llp_close and siw_qp_modify->siw_qp_llp_close did. Otherwise if siw_qp_modify() fails in siw_accept(), the QP's… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: validate access flags before swapping the MR's PD rxe_rereg_user_mr() reassigns mr->ibmr.pd first and only then validates the IB_MR_REREG_ACCESS argument: Both flags pass the entry check because RXE_MR_REREG_SUPPORTED is IB_MR_REREG_PD |… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access mr_check_range() validates that [iova, iova+length) falls within the registered MR range using wraparound-prone arithmetic: A remote peer can craft an RDMA-Write/Read RETH so… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: hold net_device reference under RCU in bundle creation xfrm_bundle_create() and xfrm_create_dummy_bundle() read dst->dev into a local pointer without taking a device reference, then pass it to xfrm_fill_dst(). A concurrent RTM_DELLINK replaces… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS scpi_dvfs_get_info() already rejected a zero opp_count, but still trusted any larger value from the SCP firmware. The shared-memory reply only holds MAX_DVFS_OPPS entries in buf.opps[]; a… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate dvfs_get_idx() may return an out-of-range index if the SCP firmware is buggy or returns a stale value. Only negative indexes were rejected, so a large index walked past info->opps and could… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths Commit 0b261d7c1cd3 ("RDMA/rxe: Break endless pagefault loop for RO pages") dropped the access permission test from rxe_check_pagefault() and left only HMM_PFN_VALID. A page faulted in… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds rxe_get_mcg() publishes a newly allocated multicast group in rxe->mcg_tree before programming the backing Ethernet multicast address with rxe_mcast_add(), which runs outside… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Reject unregistering netdevs in ib_get_eth_speed ib_device_get_netdev() intentionally returns a referenced net_device even when it is unregistering, so matching and cleanup callers can still find the association. The reference keeps struct… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: IB/iser: reject a remote invalidation of an unregistered direction A write command whose data is sent entirely as immediate data is not registered. iser_reg_mem_fastreg() takes the DMA key path and leaves rdma_reg[ISER_DIR_OUT].desc at NULL, while… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: wait for deferred control PDU completions before releasing the connection isert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and ISTATE_SEND_TEXTRSP completions off to isert_comp_wq and returns. The work item then runs… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup bnxt_re_init_dcb_wq() ignores a failed allocation. The async DCB handler later calls queue_work() on the NULL pointer. | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: guard against null kobj name In the client, if `init_path()` errors, the callee tries to clean up with `rtrs_clt_close_conns()`. However, this can lead to calling the event tracing code with `clt_path->kobj->name` being `NULL` and thus… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mad: Fix receive buffer leak when PKey enforcement fails ib_mad_complete_recv() initializes mad_recv_wc->rmpp_list and then runs ib_mad_enforce_security() before linking recv_buf onto that list. On failure it calls ib_free_recv_mad(), which only… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables Locked QP and CQ lookups from EQ interrupts can deadlock with create-path XArray updates. If an interrupt arrives while the create path holds the plain xa_lock, the lookup spins forever… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted The client borrows shared CQ credits in the ADDR_RESOLVED handler via ib_cq_pool_get(), before the peer is connected. create_cm() can return -ERESTARTSYS from… |