Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
10.007 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 19/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: reject malicious packets in ipv6_gso_segment() syzbot was able to craft a packet with very long IPv6 extension headers leading to an overflow of skb->transport_header. This 16bit field has a limited range. Add… | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 19/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: benet: fix BUG when creating VFs benet crashes as soon as SRIOV VFs are created: be_cmd_set_mac_list() calls dma_free_coherent() under a spin_lock_bh. Fix it by freeing only after the lock has been released. | |
| Analizada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 19/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: perf/core: Exit early on perf_mmap() fail When perf_mmap() fails to allocate a buffer, it still invokes the event_mapped() callback of the related event. On X86 this might increase the perf_rdpmc_allowed reference counter. But nothing undoes this as… | |
| Analizada | Alta (7.8) | 0.39% | — | Linux KernelDebian Linux | 19/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: perf/core: Prevent VMA split of buffer mappings The perf mmap code is careful about mmap()'ing the user page with the ringbuffer and additionally the auxiliary buffer, when the event supports it. Once the first mapping is established, subsequent… | |
| Modificada | Media (5.5) | 9.4% | — | Linux KernelDebian Linux | 19/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference error in generate_encryptionkey If client send two session setups with krb5 authenticate to ksmbd, null pointer dereference error in generate_encryptionkey could happen. sess->Preauth_HashValue is set to NULL if… | |
| Modificada | Media (4.7) | 0.43% | 💥 PoC | Linux KernelDebian Linux | 19/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Preauh_HashValue race condition If client send multiple session setup requests to ksmbd, Preauh_HashValue race condition could happen. There is no need to free sess->Preauh_HashValue at session setup phase. It can be freed together with… | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 19/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: x86/sev: Evict cache lines during SNP memory validation An SNP cache coherency vulnerability requires a cache line eviction mitigation when validating memory after a page state change to private. The specific mitigation is to touch the first and last… | |
| Modificada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 19/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget : fix use-after-free in composite_dev_cleanup() 1. In func configfs_composite_bind() -> composite_os_desc_req_prepare(): if kmalloc fails, the pointer cdev->os_desc_req will be freed but not set to NULL. Then it will return a failure to… | |
| Modificada | Alta (7.8) | 0.32% | — | Linux KernelDebian Linux | 16/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: mptcp: plug races between subflow fail and subflow creation We have races similar to the one addressed by the previous patch between subflow failing and additional subflow creation. They are just harder to trigger. The solution is similar. Use a… | |
| Modificada | Alta (7.8) | 0.16% | — | Linux KernelDebian Linux | 16/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Delay put pmc->idev in mld_del_delrec() pmc->idev is still used in ip6_mc_clear_src(), so as mld_clear_delrec() does, the reference should be put after ip6_mc_clear_src() return. | |
| Analizada | Alta (7.8) | 0.17% | — | Linux KernelDebian Linux | 16/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Validate the size of the received input buffer Add buffer_recv_size to store the size of the received bytes. Validate buffer_recv_size in send_usb_cmd(). | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 16/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix memory leak of struct clip_vcc. ioctl(ATMARP_MKIP) allocates struct clip_vcc and set it to vcc->user_back. The code assumes that vcc_destroy_socket() passes NULL skb to vcc->push() when the socket is close()d, and then clip_push() frees… | |
| Analizada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 16/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/tegra: nvdec: Fix dma_alloc_coherent error check Check for NULL return value with dma_alloc_coherent, in line with Robin's fix for vic.c in 'drm/tegra: vic: Fix DMA API misuse'. | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 16/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net: appletalk: Fix device refcount leak in atrtr_create() When updating an existing route entry in atrtr_create(), the old device reference was not being released before assigning the new device, leading to a device refcount leak. Fix this by calling… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 16/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras The Chicony Electronics HP 5MP Cameras (USB ID 04F2:B824 & 04F2:B82C) report a HID sensor interface that is not actually implemented. Attempting to access this non-functional sensor via… | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 16/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: tracing: Add down_write(trace_event_sem) when adding trace event When a module is loaded, it adds trace events defined by the module. It may also need to modify the modules trace printk formats to replace enum names with their values. If two modules… | |
| Analizada | Alta (7.8) | 0.17% | — | Linux KernelDebian Linux | 16/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: nbpfaxi: Fix memory corruption in probe() The nbpf->chan[] array is allocated earlier in the nbpf_probe() function and it has "num_channels" elements. These three loops iterate one element farther than they should and corrupt memory. The… | |
| Analizada | Alta (7.8) | 0.17% | — | Linux KernelDebian Linux | 16/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Fix unbalanced regulator disable in UTMI PHY mode When transitioning from USB_ROLE_DEVICE to USB_ROLE_NONE, the code assumed that the regulator should be disabled. However, if the regulator is marked as always-on,… | |
| Analizada | Alta (7.1) | 0.18% | — | Linux KernelDebian Linux | 16/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: comedi: pcl812: Fix bit shift out of bounds When checking for a supported IRQ number, the following test is used: However, `it->options[i]` is an unchecked `int` value from userspace, so the shift amount could be negative or out of bounds. Fix the… | |
| Analizada | Alta (7.1) | 0.18% | — | Linux KernelDebian Linux | 16/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: comedi: aio_iiro_16: Fix bit shift out of bounds When checking for a supported IRQ number, the following test is used: However, `it->options[i]` is an unchecked `int` value from userspace, so the shift amount could be negative or out of bounds. Fix… | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 16/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject %p% format string in bprintf-like helpers The above BPF program isn't rejected and causes a kernel warning at runtime: This happens because bpf_bprintf_prepare skips over the second %, detected as punctuation, while processing %p. This… | |
| Modificada | Alta (7.8) | 0.41% | — | Linux KernelDebian Linux | 16/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_break A race condition can occur in cifs_oplock_break() leading to a use-after-free of the cinode structure when unmounting: The issue occurs when umount has already released its reference to the… | |
| Analizada | Media (5.5) | 0.12% | — | Linux KernelDebian Linux | 16/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Don't call mmput from MMU notifier callback If the process is exiting, the mmput inside mmu notifier callback from compactd or fork or numa balancing could release the last reference of mm struct to call exit_mmap and free_pgtable, this… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 16/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: qcom: msm: mark certain pins as invalid for interrupts On some platforms, the UFS-reset pin has no interrupt logic in TLMM but is nevertheless registered as a GPIO in the kernel. This enables the user-space to trigger a BUG() in the… | |
| Analizada | Media (4.7) | 0.15% | — | Linux KernelDebian Linux | 16/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/sched: Increment job count before swapping tail spsc queue A small race exists between spsc_queue_push and the run-job worker, in which spsc_queue_push may return not-first while the run-job worker has already idled due to the job count being… |