Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3246▲ 704 respecto a la semana anterior
Críticas / altas1521▲ 136 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
21.061 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.8) | 0.17% | 💥 PoC | Linux KernelAI | 26/8/2026 | 3/10/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng informó de que el GC podía liberar parcialmente un SCC muerto. El escenario es el siguiente: En 2-1), hay una pequeña ventana en la que unix_add_edges() publica una nueva arista (B <-> B) para el… | |
| Recibida | Crítica (9.8) | 0.73% | — | Linux KernelAI | 26/8/2026 | 3/10/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: macvlan: inherit needed_headroom and needed_tailroom from lowerdev Los dispositivos macvlan heredan hard_header_len de lowerdev durante macvlan_init(), pero dejan needed_headroom y needed_tailroom establecidos en 0. Cuando el lowerdev subyacente… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 26/8/2026 | 21/9/2026 | En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: l2tp: fix tunnel and session refcount leak on seq_file release En pppol2tp_proc_open() y l2tp_dfs_seq_open(), el estado de iteración (pd->tunnel y pd->session) se guarda en los datos privados de seq_file para permitir la iteración a lo largo de varias… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock Locking is disabled in the regmap config as this driver uses its own lock. This means that all calls to regmap functions (read or write) must hold the i2c_lock. The function… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Skip sub-disable teardown for never-linked sub-schedulers A sub-scheduler enable can fail before scx_link_sched() links the sched into the hierarchy, e.g. when the parent is already being disabled, and cleanup still runs the full… | |
| Recibida | Crítica (9.8) | 0.51% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call Dan Aloni reports that he was able to hit a use-after-free bug if a FREE_STATEID operation gets delayed for whatever reason. Fix this by bumping the refcount of the 'struct nfs_server' object… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read put_fifo_with_discard() acts as both producer and consumer on the kfifo: it calls kfifo_skip() (advances out) and kfifo_put() (advances in) from the IRQ handler without synchronizing… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: handle NULL b_addr in xfs_buf_free When xfs_buf_alloc_backing_mem() fails, xfs_buf_free() is called with bp->b_addr still NULL. The code falls through to the folio_put path which calls virt_to_folio(NULL), dereferencing an invalid address and… | |
| Recibida | Crítica (9.8) | 0.65% | 💥 PoC | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: ovpn: skip rehash for peers already removed from by_id ovpn_nl_peer_set_doit() resolves the target peer via ovpn_peer_get_by_id() before taking ovpn->lock. In the window between the lookup (which only takes a refcount) and the subsequent… | |
| Recibida | Alta (7.3) | 0.13% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor bond_alb_monitor() reads primary_is_promisc under RCU, then drops RCU and takes RTNL via rtnl_trylock() before undoing the promiscuity it set on the active slave. In that window… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: enic: fix tx_hang_reset use-after-free on device removal enic_remove() cancels the reset and change_mtu_work items but does not cancel tx_hang_reset. A TX timeout that fires while the device is being removed can schedule enic_tx_hang_reset() so that… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: ipvs: avoid out-of-bounds write in ip_vs_nat_icmp Sashiko warns that local attacker can modify the packet while it is processed by IPVS. Some places read the IP ihl field multiple times which can cause out-of-bounds access. One such place is… | |
| Recibida | Crítica (9.8) | 0.55% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without valid headers [BUG] For a crafted btrfs image, the following KASAN can be triggered when reading an inline lzo compressed file extent: [CAUSE] For an inline lzo compressed file extent, there should always be… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leak in btrfs_do_encoded_write() Local fuzzing of 6.12.94 has found the following memory leak: Fix this by freeing an extent changeset before returning from btrfs_do_encoded_write(). | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages() Two error paths in amdxdna_insert_pages() called vma->vm_ops->close(vma) before returning an error code to the caller. This is incorrect: amdxdna_gem_obj_mmap() registers an HMM… | |
| Recibida | Alta (7.8) | 0.13% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve pointer state for commuted arithmetic When scalar += pointer is handled in adjust_ptr_min_max_vals(), the destination register inherits the pointer state from the source pointer. Copying only selected fields is fragile because pointer… | |
| Recibida | Sin puntuar | 0.22% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() The SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT branch in smc_llc_event_handler() stores an incoming qentry into the local LLC flow without first checking… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: devlink: fix net namespace reference leak in reload devlink_nl_reload_doit() calls devlink_netns_get(), which returns a net with a held reference. When the requested namespace differs from the current one and the reload action is not DRIVER_REINIT,… | |
| Recibida | Alta (7.5) | 0.50% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, return NULL on create error Tracer creation can fail by returning either NULL or ERR_PTR. The return value is stored without a check on the device, and users treat ERR_PTR and NULL the same way. This also causes a crash in the… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages() In amdxdna_insert_pages(), vm_flags_mod() sets VM_MIXEDMAP and clears VM_PFNMAP. If an unprivileged userspace process mmaps a non-imported GEM object and then calls… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix netns reference imbalance in conntrack kfuncs The opts argument of the BPF conntrack kfuncs can point to a shared map value. __bpf_nf_ct_lookup() and __bpf_nf_ct_alloc_entry() read opts->netns_id separately when acquiring and releasing the… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() reqsk_queue_hash_req() publishes a TCP_NEW_SYN_RECV request_sock onto the ehash chain, drops the bucket lock, and only afterwards sets rsk_refcnt to 3. Lockless readers such as… | |
| Recibida | Alta (7.1) | 0.16% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: vhost_iotlb: bound map allocation in add_range vhost_iotlb_add_range_ctx() only retires an old entry when the table has a non-zero limit, has exactly reached that limit and has VHOST_IOTLB_FLAG_RETIRE set. Non-retiring tables can keep allocating… | |
| Recibida | Crítica (9.3) | 0.20% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix buffer length in create_direct_keys() So in essence we read 16 bytes beyond 4384-byte allocation. create_direct_keys calculates the pointer and length for in and out buffers. The size calculation for in includes the entire structure… | |
| Recibida | Alta (8.4) | 0.19% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus) Fix type confusion in notification logic Sashiko reports: At the start of the loop in pmbus_notify(), the code unconditionally casts every attribute to a struct sensor_device_attribute: However, data->group.attrs can contain other types… |