Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3135▲ 554 respecto a la semana anterior
Críticas / altas1494▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
20.837 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 26/8/2026 | 26/8/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: rseq: Prevent hard lockup on granted time slice extension __exit_to_user_mode_loop() invoca rseq_grant_timeslice_extension() con las interrupciones habilitadas. Si se concede la extensión, invoca hrtimer_rearm_deferred_tif() para garantizar que se… | |
| Recibida | Alta (7.8) | 0.14% | — | Linux KernelAI | 26/8/2026 | 27/8/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: netfilter: ipset: fix refcount race between list:set GC and swap __ip_set_put_byindex() resolvía el índice a un puntero de conjunto bajo RCU, y después tomaba ip_set_ref_lock en __ip_set_put() para decrementar set->ref. ip_set_swap() mantiene ese mismo… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 26/8/2026 | 27/8/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ipvs: revalidate ihl to prevent out-of-bounds access Aunque la cabecera IP externa ya se ha incorporado a la cabeza del skb, hay que tener cuidado y volver a validar las cabeceras incrustadas después de leerlas de los fragmentos del skb para evitar… | |
| Recibida | Crítica (9.8) | 0.54% | — | Linux KernelAI | 26/8/2026 | 27/8/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: netfilter: flowtable: publish GC-visible tuple last nf_flow_table_iterate() solo trata los nodos de tupla de dirección original como propietarios de entradas. Publicar primero el nodo original permite que el GC observe y libere un flujo mientras… | |
| Recibida | Alta (7.5) | 0.49% | — | Linux KernelAI | 26/8/2026 | 27/8/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: eth: bnxt: avoid deadlock when canceling IRQ affinity notifier Anular el registro de los notificadores de afinidad de IRQ espera a la función de retorno de forma síncrona. bnxt toma el bloqueo de instancia del netdev en el notificador (para reiniciar… | |
| Recibida | Crítica (9.8) | 0.51% | — | Linux KernelAI | 26/8/2026 | 27/8/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev Los dispositivos ipvlan heredan hard_header_len de phy_dev durante ipvlan_init(), pero dejan needed_headroom y needed_tailroom establecidos en 0. Cuando el phy_dev subyacente (o un… | |
| Recibida | Alta (7.5) | 0.63% | — | Linux KernelAI | 26/8/2026 | 27/8/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: veth: fix queue index used to wake the peer txq in veth_poll veth_poll() deriva el índice de la cola de TX del par que debe despertar a partir de rq->xdp_rxq.queue_index. Ese campo solo lo inicializa xdp_rxq_info_reg() en veth_enable_xdp_range(), que… | |
| Recibida | Alta (7.5) | 0.61% | — | Linux KernelAI | 26/8/2026 | 27/8/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling En el modo no MSI-X (como INTx heredado o MSI único), wx->msix_entry no se asigna ni se inicializa. Llamar a NGBE_INTR_MISC(wx) desreferencia wx->msix_entry->entry, lo que provoca… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 26/8/2026 | 26/8/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain tcf_action_exec() gestiona TC_ACT_GOTO_CHAIN comprobando primero rcu_access_pointer(a->goto_chain) y llamando después a tcf_action_goto_chain_exec(), que realiza una segunda lectura… | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 26/8/2026 | 27/8/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net/sched: cls_u32: skip hash tables in u32_bind_class() u32_walk() enumera tanto struct tc_u_hnode como struct tc_u_knode a través de la función de retorno del recorrido. u32_bind_class() convierte incondicionalmente el fh pasado a tc_u_knode y accede… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 26/8/2026 | 26/8/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: regmap: sdw-mbq: don't call an unset readable_reg callback regmap_sdw_mbq_poll_busy() decide si sondear el bit Function Busy llamando a ctx->readable_reg(), que es una copia directa de config->readable_reg. Esa función de retorno es opcional:… | |
| Recibida | Crítica (9.8) | 0.76% | — | Linux KernelAI | 26/8/2026 | 27/8/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG En la ruta de recepción de paquetes, el ID del puerto MAC en el que se recibió el paquete está incrustado en los metadatos del descriptor DMA de RX. El ID se extrae mediante la… | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 26/8/2026 | 27/8/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net/sched: cls_bpf: reject dev-bound programs bound to a different device cls_bpf_prog_from_efd() obtenía un programa SCHED_CLS mediante bpf_prog_get_type_dev(), pero nunca verificaba que el netdev vinculado de un programa vinculado a dispositivo… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 26/8/2026 | 26/8/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: firewire: ohci: fix NULL pointer dereference in ar_context_release Durante la ruta de gestión de errores de la función de sondeo del controlador, puede producirse una desreferencia de puntero nulo en ar_context_release(). Cuando pci_probe() falla… | |
| Recibida | Alta (7.8) | 0.17% | 💥 PoC | Linux KernelAI | 26/8/2026 | 3/10/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng informó de que el GC podía liberar parcialmente un SCC muerto. El escenario es el siguiente: En 2-1), hay una pequeña ventana en la que unix_add_edges() publica una nueva arista (B <-> B) para el… | |
| Recibida | Crítica (9.8) | 0.73% | — | Linux KernelAI | 26/8/2026 | 3/10/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: macvlan: inherit needed_headroom and needed_tailroom from lowerdev Los dispositivos macvlan heredan hard_header_len de lowerdev durante macvlan_init(), pero dejan needed_headroom y needed_tailroom establecidos en 0. Cuando el lowerdev subyacente… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 26/8/2026 | 21/9/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: l2tp: fix tunnel and session refcount leak on seq_file release En pppol2tp_proc_open() y l2tp_dfs_seq_open(), el estado de iteración (pd->tunnel y pd->session) se guarda en los datos privados de seq_file para permitir la iteración a lo largo de varias… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock Locking is disabled in the regmap config as this driver uses its own lock. This means that all calls to regmap functions (read or write) must hold the i2c_lock. The function… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Skip sub-disable teardown for never-linked sub-schedulers A sub-scheduler enable can fail before scx_link_sched() links the sched into the hierarchy, e.g. when the parent is already being disabled, and cleanup still runs the full… | |
| Recibida | Crítica (9.8) | 0.51% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call Dan Aloni reports that he was able to hit a use-after-free bug if a FREE_STATEID operation gets delayed for whatever reason. Fix this by bumping the refcount of the 'struct nfs_server' object… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read put_fifo_with_discard() acts as both producer and consumer on the kfifo: it calls kfifo_skip() (advances out) and kfifo_put() (advances in) from the IRQ handler without synchronizing… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: handle NULL b_addr in xfs_buf_free When xfs_buf_alloc_backing_mem() fails, xfs_buf_free() is called with bp->b_addr still NULL. The code falls through to the folio_put path which calls virt_to_folio(NULL), dereferencing an invalid address and… | |
| Recibida | Crítica (9.8) | 0.65% | 💥 PoC | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: ovpn: skip rehash for peers already removed from by_id ovpn_nl_peer_set_doit() resolves the target peer via ovpn_peer_get_by_id() before taking ovpn->lock. In the window between the lookup (which only takes a refcount) and the subsequent… | |
| Recibida | Alta (7.3) | 0.13% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor bond_alb_monitor() reads primary_is_promisc under RCU, then drops RCU and takes RTNL via rtnl_trylock() before undoing the promiscuity it set on the active slave. In that window… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: enic: fix tx_hang_reset use-after-free on device removal enic_remove() cancels the reset and change_mtu_work items but does not cancel tx_hang_reset. A TX timeout that fires while the device is being removed can schedule enic_tx_hang_reset() so that… |