Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

10.164 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.18%—Linux KernelDebian Linux16/8/202517/6/2026
In the Linux kernel, the following vulnerability has been resolved: comedi: pcl812: Fix bit shift out of bounds When checking for a supported IRQ number, the following test is used: However, `it->options[i]` is an unchecked `int` value from userspace, so the shift amount could be negative or out of bounds. Fix the…
AnalizadaAlta (7.1)0.18%—Linux KernelDebian Linux16/8/202517/6/2026
In the Linux kernel, the following vulnerability has been resolved: comedi: aio_iiro_16: Fix bit shift out of bounds When checking for a supported IRQ number, the following test is used: However, `it->options[i]` is an unchecked `int` value from userspace, so the shift amount could be negative or out of bounds. Fix…
ModificadaMedia (5.5)0.17%—Linux KernelDebian Linux16/8/202530/7/2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject %p% format string in bprintf-like helpers The above BPF program isn't rejected and causes a kernel warning at runtime: This happens because bpf_bprintf_prepare skips over the second %, detected as punctuation, while processing %p. This…
ModificadaAlta (7.8)0.41%—Linux KernelDebian Linux16/8/202530/7/2026
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_break A race condition can occur in cifs_oplock_break() leading to a use-after-free of the cinode structure when unmounting: The issue occurs when umount has already released its reference to the…
AnalizadaMedia (5.5)0.12%—Linux KernelDebian Linux16/8/202517/6/2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Don't call mmput from MMU notifier callback If the process is exiting, the mmput inside mmu notifier callback from compactd or fork or numa balancing could release the last reference of mm struct to call exit_mmap and free_pgtable, this…
AnalizadaMedia (5.5)0.16%—Linux KernelDebian Linux16/8/202517/6/2026
In the Linux kernel, the following vulnerability has been resolved: pinctrl: qcom: msm: mark certain pins as invalid for interrupts On some platforms, the UFS-reset pin has no interrupt logic in TLMM but is nevertheless registered as a GPIO in the kernel. This enables the user-space to trigger a BUG() in the…
AnalizadaMedia (4.7)0.15%—Linux KernelDebian Linux16/8/202517/6/2026
In the Linux kernel, the following vulnerability has been resolved: drm/sched: Increment job count before swapping tail spsc queue A small race exists between spsc_queue_push and the run-job worker, in which spsc_queue_push may return not-first while the run-job worker has already idled due to the job count being…
ModificadaMedia (5.5)0.36%—Linux KernelDebian Linux16/8/202530/7/2026
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix oops due to non-existence of prealloc backlog struct If an AF_RXRPC service socket is opened and bound, but calls are preallocated, then rxrpc_alloc_incoming_call() will oops because the rxrpc_backlog struct doesn't get allocated until the…
AnalizadaMedia (5.5)0.16%—Linux KernelDebian Linux16/8/202517/6/2026
In the Linux kernel, the following vulnerability has been resolved: wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev() There is a potential NULL pointer dereference in zd_mac_tx_to_dev(). For example, the following is possible: filter_ack() spin_lock_irqsave(&q->lock, flags); /* position ==…
ModificadaAlta (7.8)0.23%—Linux KernelDebian Linux16/8/202530/7/2026
In the Linux kernel, the following vulnerability has been resolved: wifi: prevent A-MSDU attacks in mesh networks This patch is a mitigation to prevent the A-MSDU spoofing vulnerability for mesh networks. The initial update to the IEEE 802.11 standard, in response to the FragAttacks, missed this case (CVE-2025-27558).…
AnalizadaMedia (5.5)0.15%—Linux KernelDebian Linux16/8/202517/6/2026
In the Linux kernel, the following vulnerability has been resolved: find_vm_area() couldn't be called in atomic_context. If find_vm_area() is called to reports vm area information, kasan can trigger deadlock like: To prevent possible deadlock while kasan reports, remove kasan_find_vm_area().
AnalizadaMedia (5.5)0.15%—Linux KernelDebian Linux16/8/202517/6/2026
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix assertion when building free space tree When building the free space tree with the block group tree feature enabled, we can hit an assertion failure like this: This happens because we are processing an empty block group, which has no…
ModificadaAlta (7.1)0.17%💥 PoCLinux KernelDebian LinuxSiemens Simatic CN 4100 Firmware16/8/202530/7/2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial reported that an out-of-bounds access in cgroup local storage can be crafted via tail calls. Given two programs each utilizing a cgroup local storage with a different value size, and one program doing…
AnalizadaAlta (7.5)2.1%💥 PoCLinux KernelDebian Linux16/8/202517/6/2026
In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with the same IP Repeated connections from clients with the same IP address may exhaust the max connections and prevent other normal client connections. This patch limit repeated connections from clients…
AnalizadaAlta (7.8)0.15%—Linux KernelDebian Linux12/8/202517/6/2026
In the Linux kernel, the following vulnerability has been resolved: xfrm: interface: fix use-after-free after changing collect_md xfrm interface collect_md property on xfrm interfaces can only be set on device creation, thus xfrmi_changelink() should fail when called on such interfaces. The check to enforce this was…
ModificadaMedia (5.5)0.16%—Linux KernelDebian Linux11/8/202530/7/2026
In the Linux kernel, the following vulnerability has been resolved: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns What we want is to verify there is that clone won't expose something hidden by a mount we wouldn't be able to undo. "Wouldn't be able to undo" may be a result of…
AnalizadaCrítica (9.8)0.24%—Debian Devscripts1/8/202517/6/2026
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification…
ModificadaMedia (5.5)0.18%—Linux KernelDebian Linux30/7/202530/7/2026
In the Linux kernel, the following vulnerability has been resolved: do_change_type(): refuse to operate on unmounted/not ours mounts Ensure that propagation settings can only be changed for mounts located in the caller's mount namespace. This change aligns permission checking with the rest of mount(2).
AnalizadaAlta (7.1)0.16%—Linux KernelDebian Linux28/7/202517/6/2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: Fix OOB read on empty string write When writing an empty string to either 'qw_sign' or 'landingPage' sysfs attributes, the store functions attempt to access page[l - 1] before validating that the length 'l' is greater than zero.…
ModificadaMedia (5.5)0.33%—Linux KernelDebian Linux28/7/202530/7/2026
In the Linux kernel, the following vulnerability has been resolved: HID: core: ensure the allocated report buffer can contain the reserved report ID When the report ID is not used, the low level transport drivers expect the first byte to be 0. However, currently the allocated buffer not account for that extra byte,…
ModificadaAlta (7.8)0.23%—Linux KernelDebian Linux28/7/202530/7/2026
In the Linux kernel, the following vulnerability has been resolved: HID: core: do not bypass hid_hw_raw_request hid_hw_raw_request() is actually useful to ensure the provided buffer and length are valid. Directly calling in the low level transport driver function bypassed those checks and allowed invalid paramto be…
ModificadaMedia (5.5)0.21%—Linux KernelDebian Linux28/7/202530/7/2026
In the Linux kernel, the following vulnerability has been resolved: mptcp: make fallback action and fallback decision atomic Syzkaller reported the following splat:
ModificadaAlta (7.8)0.68%—Linux KernelDebian Linux28/7/202530/7/2026
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in crypt_message when using async crypto The CVE-2024-50047 fix removed asynchronous crypto handling from crypt_message(), assuming all crypto operations are synchronous. However, when hardware crypto accelerators are…
AnalizadaMedia (5.5)0.16%—Linux KernelDebian Linux28/7/202517/6/2026
In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled Mitigate e.g. the following:
ModificadaAlta (7.8)0.15%—Linux KernelDebian Linux28/7/202530/7/2026
In the Linux kernel, the following vulnerability has been resolved: iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush fxls8962af_fifo_flush() uses indio_dev->active_scan_mask (with iio_for_each_active_channel()) without making sure the indio_dev stays in buffer mode. There is a race if indio_dev…