Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3206▲ 621 respecto a la semana anterior
Críticas / altas1515▲ 108 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
20.837 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: ipvs: avoid out-of-bounds write in ip_vs_nat_icmp Sashiko warns that local attacker can modify the packet while it is processed by IPVS. Some places read the IP ihl field multiple times which can cause out-of-bounds access. One such place is… | |
| Recibida | Crítica (9.8) | 0.55% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without valid headers [BUG] For a crafted btrfs image, the following KASAN can be triggered when reading an inline lzo compressed file extent: [CAUSE] For an inline lzo compressed file extent, there should always be… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leak in btrfs_do_encoded_write() Local fuzzing of 6.12.94 has found the following memory leak: Fix this by freeing an extent changeset before returning from btrfs_do_encoded_write(). | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages() Two error paths in amdxdna_insert_pages() called vma->vm_ops->close(vma) before returning an error code to the caller. This is incorrect: amdxdna_gem_obj_mmap() registers an HMM… | |
| Recibida | Alta (7.8) | 0.13% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve pointer state for commuted arithmetic When scalar += pointer is handled in adjust_ptr_min_max_vals(), the destination register inherits the pointer state from the source pointer. Copying only selected fields is fragile because pointer… | |
| Recibida | Sin puntuar | 0.22% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() The SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT branch in smc_llc_event_handler() stores an incoming qentry into the local LLC flow without first checking… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: devlink: fix net namespace reference leak in reload devlink_nl_reload_doit() calls devlink_netns_get(), which returns a net with a held reference. When the requested namespace differs from the current one and the reload action is not DRIVER_REINIT,… | |
| Recibida | Alta (7.5) | 0.50% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, return NULL on create error Tracer creation can fail by returning either NULL or ERR_PTR. The return value is stored without a check on the device, and users treat ERR_PTR and NULL the same way. This also causes a crash in the… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages() In amdxdna_insert_pages(), vm_flags_mod() sets VM_MIXEDMAP and clears VM_PFNMAP. If an unprivileged userspace process mmaps a non-imported GEM object and then calls… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix netns reference imbalance in conntrack kfuncs The opts argument of the BPF conntrack kfuncs can point to a shared map value. __bpf_nf_ct_lookup() and __bpf_nf_ct_alloc_entry() read opts->netns_id separately when acquiring and releasing the… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() reqsk_queue_hash_req() publishes a TCP_NEW_SYN_RECV request_sock onto the ehash chain, drops the bucket lock, and only afterwards sets rsk_refcnt to 3. Lockless readers such as… | |
| Recibida | Alta (7.1) | 0.16% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: vhost_iotlb: bound map allocation in add_range vhost_iotlb_add_range_ctx() only retires an old entry when the table has a non-zero limit, has exactly reached that limit and has VHOST_IOTLB_FLAG_RETIRE set. Non-retiring tables can keep allocating… | |
| Recibida | Crítica (9.3) | 0.20% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix buffer length in create_direct_keys() So in essence we read 16 bytes beyond 4384-byte allocation. create_direct_keys calculates the pointer and length for in and out buffers. The size calculation for in includes the entire structure… | |
| Recibida | Alta (8.4) | 0.19% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus) Fix type confusion in notification logic Sashiko reports: At the start of the loop in pmbus_notify(), the code unconditionally casts every attribute to a struct sensor_device_attribute: However, data->group.attrs can contain other types… | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: xsk: require at least 16 bytes of TX metadata AF_XDP accepts a TX metadata length as small as eight bytes, but every supported request needs the flags plus at least one eight-byte request field. Such short metadata also lets the kernel read beyond the… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: xsk: clear metadata pointer when no timestamp is requested User space can change metadata flags after request processing. Rereading them during completion can therefore make the kernel write a timestamp that was not requested when the packet was… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: xsk: validate launch-time metadata size Launch-time metadata extends beyond the first 16 bytes of struct xsk_tx_metadata. Reject the request when the registered metadata area does not contain the complete field. Snapshot the validated flags for the… | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: xsk: validate metadata when processing requests The zero-copy path validates TX metadata while obtaining the descriptor context, then reads it again later when preparing the hardware request. User space can change the metadata between those operations… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: bnge: Fix NULL pointer dereference in aux device release If allocation of auxr_dev fails during auxiliary device setup, the error path calls auxiliary_device_uninit(), which eventually invokes bnge_aux_dev_release(). The release callback… | |
| Recibida | Crítica (10) | 0.50% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segmentation __skb_udp_tunnel_segment() gets the UDP header before ensuring the tunnel header is in the skb head. If the pull reallocates skb->head, the saved UDP header pointer is no longer valid. Get the… | |
| Recibida | Alta (8.2) | 0.44% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter The sch_cake ACK filter parses packets to find the TCP header and filter duplicated ACKs if the flow is backlogged. The parsing code contains a WARN_ON(1) which can be triggered… | |
| Recibida | Alta (7.1) | 0.18% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Validate T10 PI scatterlist counts When T10 PI is negotiated, vhost-scsi splits protection bytes from the data iterator before mapping the request scatterlists. A malformed request can claim protection bytes that cover or exceed the full… | |
| Recibida | Alta (8.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: reject feature changes after endpoint vhost_scsi_setup_vq_cmds() runs from VHOST_SCSI_SET_ENDPOINT and allocates each command's protection scatterlist array (prot_sgl) according to the acknowledged VIRTIO_SCSI_F_T10_PI bit. The command… | |
| Recibida | Alta (7.8) | 0.13% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/openvswitch: check Ethernet header length in key_extract() When a packet arrives on an ARPHRD_NONE device (e.g. TUN), ovs_flow_key_extract() trusts the user-provided skb->protocol field: if it is ETH_P_TEB, the packet is classified as… | |
| Recibida | Alta (7.8) | 0.13% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers Another challenge with unlocked filters. There is a short window in tc_new_tfilter where a tcf_proto can be found and briefly referenced by a totally unrelated, unlocked… |