Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3247▲ 705 respecto a la semana anterior
Críticas / altas1522▲ 137 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
20.838 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 22/8/2026 | 23/8/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/page_table_check: skip special zero mappings page_table_check_set() and page_table_check_clear() account mappings based on PageAnon(). Shared zero-page PTEs and huge zero PMDs are special mappings, but page_table_check can still account them as… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 22/8/2026 | 23/8/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/ptdump: always stabilise against page table freeing using init_mm Previous commits have established the invariant that kernel page table freeing is performed while an mmap read lock on init_mm is held, which fixes races between ptdump and kernel… | |
| Recibida | Alta (7.5) | 0.43% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix Route Information option length validation rt6_route_rcv() validates the Route Information option (RFC 4191) length against the prefix length, but both checks are off by one. rinfo->length is the ND option length in units of 8 octets and it… | |
| Recibida | Crítica (9.8) | 0.54% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip6ip6_err() ip6ip6_err() clones an outer IPv6 ICMP error skb, pulls it to the quoted inner IPv6 packet, and then passes the clone to icmpv6_send(). The clone still carries the outer packet's inet6_skb_parm in skb->cb.… | |
| Recibida | Alta (7.8) | 0.12% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() fscrypt_ioctl_set_policy() calls inode_owner_or_capable() with &nop_mnt_idmap before allowing an encryption policy to be set, instead of the idmap of the mount the ioctl… | |
| Recibida | Alta (7.8) | 0.13% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: sched/psi: Shut down rtpoll_timer in psi_cgroup_free() psi_schedule_rtpoll_work() is called locklessly from the scheduler hotpath and can race psi_trigger_destroy() taking down the last rtpoll trigger under rtpoll_trigger_lock: The group can then be… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 22/8/2026 | 23/8/2026 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Take cgroup_lock() first in scx_cgroup_lock() scx_cgroup_lock() write-locks scx_cgroup_ops_rwsem and then takes cgroup_lock(), which can deadlock through kernfs: The enable path waits for the rmdir to release cgroup_mutex. The rmdir,… | |
| Recibida | Alta (8.1) | 0.48% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: ima: Instantiate file_truncate and path_truncate hooks Instantiate the file_truncate and path_truncate LSM hooks to reset the action cache flags (IMA_DONE_MASK) as soon as truncation is requested, so the file, based on policy, is re-collected,… | |
| Recibida | Crítica (9.8) | 0.65% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/filemap: __filemap_add_folio() restore index before retrying In __filemap_add_folio()'s split-a-conflict loop, xas_set_order() is applied repeatedly: each application modifies xas.xa_index, rounding it down according to the split_order attempted at… | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions The BPF verifier and the dynptr abstraction ensure that the memory space referenced by a dynptr remains valid. They do not, however, provide any guarantee that the contents of the memory are… | |
| Recibida | Alta (8.4) | 0.14% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix sk_redir use-after-free in send verdict sk_psock_msg_verdict() takes a socket reference for psock->sk_redir. tcp_bpf_send_verdict() copies that pointer while holding the source socket lock, but does not take a reference for the local… | |
| Recibida | Crítica (9.8) | 0.50% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: keep chunk->transport in step with the list it is queued on __sctp_outq_flush_rtx() moves a gap-acked chunk onto another transport's transmitted list without updating chunk->transport: The chunk then sits on a live transport's list while… | |
| Recibida | Crítica (9.8) | 0.50% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix use-after-free of cached ASCONF chunk addip_last_asconf caches the outstanding outbound ASCONF chunk. The normal ASCONF-ACK completion path releases the chunk and clears the pointer. However, sctp_asconf_queue_teardown() releases the cached… | |
| Recibida | Crítica (9.8) | 0.50% | 💥 PoC | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: clear new_transport when removing a peer sctp_process_asconf_param() stores a newly added peer transport in asoc->new_transport. After all parameters in the ASCONF chunk have been processed, sctp_sf_do_asconf() uses this pointer to send a… | |
| Recibida | Sin puntuar | 0.22% | — | Linux KernelAI | 22/8/2026 | 22/8/2026 | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound the DROM dual link port number before indexing sw->ports tb_drom_parse_entry_port() validates the device-supplied header->index against sw->config.max_port_number before indexing sw->ports[], but the sibling field… | |
| Recibida | Alta (7.1) | 0.18% | — | Linux KernelAI | 22/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: zero shared page before exposing to userspace bnxt_re_alloc_ucontext() allocates uctx->shpg via __get_free_page(GFP_KERNEL). The buddy allocator does not zero pages without __GFP_ZERO, so the page contains stale kernel data from whatever… | |
| Rechazada | Sin puntuar | 0.21% | — | Linux KernelAI | 22/8/2026 | 29/9/2026 | Motivo del rechazo: Este identificador CVE ha sido rechazado o retirado por su autoridad de numeración (CNA). | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 22/8/2026 | 11/10/2026 | In the Linux kernel, the following vulnerability has been resolved: fs,fsverity: remove check for fsverity being enabled in setattr_prepare() The check that fs-verity is available in the kernel is not necessary here. Filesystems could have fsverity files even without fs-verity enabled. In that case, truncate on… | |
| Recibida | Alta (7.8) | 0.12% | — | Linux KernelAI | 21/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_route: fix fastmap use-after-free on filter The route4 classifier maintains a 16-slot fastmap cache that stores raw struct route4_filter pointers indexed by (id, iif). The reader (route4_classify) populates this cache via… | |
| Recibida | Alta (7.8) | 0.12% | — | Linux KernelAI | 21/8/2026 | 27/8/2026 | In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in non-ring send paths packet_snd() reads dev->hard_header_len multiple times while allocating and constructing an skb. Device reconfiguration can change this value concurrently, for example through bonding… | |
| Recibida | Crítica (9.8) | 0.42% | — | Linux KernelAI | 21/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves res->rt6 pointing at the released rt6_info. If no later rule supplies a replacement, fib6_rule_lookup() still sees res.rt6… | |
| Recibida | Alta (8.8) | 0.18% | — | Linux KernelAI | 21/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: vhost: reset the vring metadata cache on vring reconfiguration vq->meta_iotlb[] caches the vhost_iotlb_map that backs each vring metadata region, and iotlb_access_ok() returns early on a cache hit, taking the hit as proof that the region has already… | |
| Recibida | Alta (7.1) | 0.12% | — | Linux KernelAI | 17/8/2026 | 25/8/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fix mask build for partial field offload nft_payload_offload_mask() builds the offload match mask for a payload expression that covers only part of a header field. For a partial IPv6 address match (field_len = 16, priv_len = 1)… | |
| Recibida | Alta (7.1) | 0.19% | — | Linux KernelAI | 16/8/2026 | 17/8/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous processing on trees without ctx->state The AIO/async path in skcipher_recvmsg() passes the socket-wide ctx->iv directly into the skcipher request. After io_submit() the socket lock is dropped and the request… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 15/8/2026 | 19/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net: mpls: initialize rtm_tos in mpls_getroute() mpls_getroute() builds the RTM_NEWROUTE reply to an RTM_GETROUTE request by filling a struct rtmsg allocated from an skb whose data area is not zeroed (alloc_skb(NLMSG_GOODSIZE, ...)). It sets every… |