Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3241▲ 698 respecto a la semana anterior
Críticas / altas1519▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
21.061 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: xsk: require at least 16 bytes of TX metadata AF_XDP accepts a TX metadata length as small as eight bytes, but every supported request needs the flags plus at least one eight-byte request field. Such short metadata also lets the kernel read beyond the… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: xsk: clear metadata pointer when no timestamp is requested User space can change metadata flags after request processing. Rereading them during completion can therefore make the kernel write a timestamp that was not requested when the packet was… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: xsk: validate launch-time metadata size Launch-time metadata extends beyond the first 16 bytes of struct xsk_tx_metadata. Reject the request when the registered metadata area does not contain the complete field. Snapshot the validated flags for the… | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: xsk: validate metadata when processing requests The zero-copy path validates TX metadata while obtaining the descriptor context, then reads it again later when preparing the hardware request. User space can change the metadata between those operations… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: bnge: Fix NULL pointer dereference in aux device release If allocation of auxr_dev fails during auxiliary device setup, the error path calls auxiliary_device_uninit(), which eventually invokes bnge_aux_dev_release(). The release callback… | |
| Recibida | Crítica (10) | 0.50% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segmentation __skb_udp_tunnel_segment() gets the UDP header before ensuring the tunnel header is in the skb head. If the pull reallocates skb->head, the saved UDP header pointer is no longer valid. Get the… | |
| Recibida | Alta (8.2) | 0.44% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter The sch_cake ACK filter parses packets to find the TCP header and filter duplicated ACKs if the flow is backlogged. The parsing code contains a WARN_ON(1) which can be triggered… | |
| Recibida | Alta (7.1) | 0.18% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Validate T10 PI scatterlist counts When T10 PI is negotiated, vhost-scsi splits protection bytes from the data iterator before mapping the request scatterlists. A malformed request can claim protection bytes that cover or exceed the full… | |
| Recibida | Alta (8.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: reject feature changes after endpoint vhost_scsi_setup_vq_cmds() runs from VHOST_SCSI_SET_ENDPOINT and allocates each command's protection scatterlist array (prot_sgl) according to the acknowledged VIRTIO_SCSI_F_T10_PI bit. The command… | |
| Recibida | Alta (7.8) | 0.13% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/openvswitch: check Ethernet header length in key_extract() When a packet arrives on an ARPHRD_NONE device (e.g. TUN), ovs_flow_key_extract() trusts the user-provided skb->protocol field: if it is ETH_P_TEB, the packet is classified as… | |
| Recibida | Alta (7.8) | 0.13% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers Another challenge with unlocked filters. There is a short window in tc_new_tfilter where a tcf_proto can be found and briefly referenced by a totally unrelated, unlocked… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix memory leak in exec_queue_set_hang_replay_state() The q->replay_state is blindly overwritten, which can potentially leak memory that was previously allocated by vmemdup_user(). Return an error if q->replay_state is not empty. Discovered… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix BQL reset on SQ re-activation mlx5e_queue_start() deactivates and re-activates all channels but closes only the queue being restarted. mlx5e_activate_txqsq() then unconditionally calls netdev_tx_reset_queue(), zeroing the BQL counters… | |
| Recibida | Alta (8.2) | 0.61% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Disable EOP for TPA on all chips to prevent data corruption EOP (End of frame padding) on the AGG ring may cause overlapping of zero padding at the end of one segment with the next segment's data. If Relaxed Ordering (RO) is enabled, the zero… | |
| Recibida | Alta (7.5) | 0.49% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: tcp: fix TFO max_qlen accounting across reuseport migration A listener's TCP_FASTOPEN max_qlen stops being accurate and lets through far more pending Fast Open requests than it was configured for. This only shows up with SO_REUSEPORT listener… | |
| Recibida | Alta (7.5) | 0.43% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() Incoming skbs passing through netfilter flowtable offload hooks (or XFRM offload path) might already carry a ref-counted dst_entry assigned during earlier RX or routing steps.… | |
| Recibida | Sin puntuar | 0.22% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length ncsi_send_cmd_nl() takes the number of bytes to copy from the attacker-controlled ncsi_pkt_hdr.length field of the in-band packet header, while the source buffer is the NCSI_ATTR_DATA… | |
| Recibida | Sin puntuar | 0.22% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net: prestera: validate firmware header length prestera_fw_hdr_parse() reads the firmware header before checking that the firmware image contains that header. Reject images shorter than struct prestera_fw_header before decoding the magic and version… | |
| Recibida | Alta (7.5) | 0.70% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix TOCTOU race between smc_listen_out() and listener close smc_listen_out() reads lsmc->sk.sk_state without the listener lock, then acquires lock_sock_nested() only after the check passes. This opens a window where smc_close_active() can… | |
| Recibida | Alta (8.8) | 0.40% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Tear down DMA paths before stopping the rings tbnet_tear_down() stops both rings and frees their frame buffers before calling tb_xdomain_disable_paths(). tb_ring_stop() zeroes the ring's descriptor base and tbnet_free_buffers()… | |
| Recibida | Alta (8.4) | 0.19% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: s390/ism: Fix UAF of sba and ieq during ism_dev_exit() A ism interrupt handler can be active in parallel with ism_dev_exit(), accessing freed data structures. No new interrupts will be generated after unregister_ieq(). Drain ongoing interrupt handlers… | |
| Recibida | Alta (7.1) | 0.18% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/atm: fix slab-out-of-bounds read in vcc_setsockopt() If __SO_LEVEL_MATCH(optname, level) evaluated to false (e.g. if the caller passed a mismatched level), the length check optlen != __SO_SIZE(optname) was short-circuited and bypassed. Execution… | |
| Recibida | Crítica (9.8) | 0.50% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: clear control chunk transport if it is being removed sctp_make_heartbeat_ack() caches the destination transport in chunk->transport without taking a reference. When src_out_of_asoc_ok is enabled, the HEARTBEAT ACK may remain queued on… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: watchdog: at91sam9_wdt: prevent timer rearm during teardown at91_ping() rearms the watchdog timer from its callback. timer_delete() neither waits for a running callback nor prevents it from rearming the timer, so probe failure or driver removal can… | |
| Recibida | Sin puntuar | 0.24% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: rqspinlock: Reset tail when preserving queue on deadlock Currently, the destruction of the waiter queue is suppressed for rqspinlock in cases where a deadlock is detected. Deadlock checks happen relatively frequently (on entry for AA, within 1ms for… |