Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
21.050 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Sin puntuar | 0.14% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: bound $AttrDef table walk to the loaded table size ntfs_attr_find_in_attrdef() walks the in-memory $AttrDef table, but the loop condition bounds only the start of each entry, not the whole entry: struct attr_def is 160 bytes; the guard reads… | |
| En análisis | Sin puntuar | 0.14% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid sectors_per_cluster in the boot sector is_boot_sector_ntfs() checks the boot sector's sectors_per_cluster field with a range test that rejects 0x81..0xf3 but accepts 0 and other non-power-of-two counts. A zero value reaches… | |
| En análisis | Sin puntuar | 0.16% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: check_cond_jmp_op(): properly infer if register is null Nicholas Carlini reported a bug when verifier can incorrectly infer that a pointer is non-null. The bug occurs when two pointers are compared and one of them has a type w/o PTR_MAYBE_NULL… | |
| En análisis | Sin puntuar | 0.15% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: leave HasEA flag untouched on setxattr failure In ntfs_set_ea(), the exit path unconditionally updates the HasEA flag based on ea_info_qsize. When an error occurs before ea_info_qsize is updated, NInoClearHasEA() hides existing on-disk EAs until… | |
| En análisis | Sin puntuar | 0.16% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: don't downgrade half-dead scalar zero spills to STACK_ZERO states.c:__clean_func_state() can downgrade scalar zero spill to STACK_ZERO in the following case: Here 4 bytes at r10-8 are dead and verifier changes scalar spill to a combination:… | |
| En análisis | Sin puntuar | 0.15% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix dma mapping leak in stmmac_tso_xmit() In stmmac_tso_xmit(), if the DMA mapping of an skb fragment fails, the frame is dropped but the DMA mappings already created for the linear part and for the fragments mapped before the failure are… | |
| En análisis | Alta (8.1) | 0.58% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START The SCTP_CMD_TIMER_START handler checks timer_pending() before calling timer_reduce(). The timer can expire and detach between these operations, causing timer_reduce() to rearm the timer without taking… | |
| En análisis | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add() sas_port_alloc_num() can return NULL on memory allocation failure. The return value is passed directly to sas_port_add() without a NULL check, which causes a NULL pointer dereference.… | |
| En análisis | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add() mpi3mr_get_tgtdev_by_addr() increments the target device kref when it returns a device. If a subsequent error triggers a goto out_fail after the tgtdev reference is acquired, the… | |
| En análisis | Sin puntuar | 0.18% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: smb/client: validate new EOF for insert range smb3_insert_range() does not check if the new file size (i_size + len) is valid. This allows FALLOC_FL_INSERT_RANGE to bypass RLIMIT_FSIZE, exceed s_maxbytes, or produce a size outside the loff_t range.… | |
| En análisis | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: smb/client: validate new EOF for zero range When FALLOC_FL_ZERO_RANGE is used without FALLOC_FL_KEEP_SIZE, smb3_zero_range() may extend EOF without checking RLIMIT_FSIZE, allowing the file to grow beyond the caller's file-size limit. Fix this by… | |
| En análisis | Sin puntuar | 0.15% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: smb/client: fix stale page cache in insert/collapse range smb3_insert_range() and smb3_collapse_range() use truncate_pagecache_range() to invalidate the affected page cache. However, if off or old_eof is not page-aligned, the boundary pages are only… | |
| En análisis | Sin puntuar | 0.16% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: smb/client: invalidate fscache for fallocate range operations smb3_zero_range(), smb3_punch_hole(), smb3_insert_range(), and smb3_collapse_range() modify file contents through server-side range operations. These operations discard the affected page… | |
| En análisis | Sin puntuar | 0.18% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration sctp_verify_asconf() walks ASCONF-ACK parameters with sctp_walk_params(), which advances by SCTP_PAD4(length), while the consumer sctp_get_asconf_response() iterates the same… | |
| En análisis | Alta (7.8) | 0.13% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del() vxlan_mdb_is_valid_source(), which validates MDBE_ATTR_SOURCE and every MDBE_ATTR_SRC_LIST member, accepts the all-zeros address. A source list is only accepted on a (*, G) entry, whose… | |
| En análisis | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: watchdog: msc313e: Fix NULL pointer dereference in PM callbacks msc313e_wdt_probe() doesn't set the driver data for the platform device. As a result, dev_get_drvdata() in msc313e_wdt_suspend() and msc313e_wdt_resume() will return NULL, leading to a… | |
| En análisis | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix subreq ref leak Fix a subrequest ref leak in netfs_unbuffered_write() in the event that subreq->io_iter ends up zero length during preparation. | |
| En análisis | Sin puntuar | 0.18% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: netfs: break unbuffered write when netfs_alloc_subrequest() fails syzbot reported a null-ptr-deref below [1] following a fault injection in netfs_alloc_subrequest(). [0] When netfs_alloc_subrequest() fails, subreq is NULL. Later, netfs_prepare_write()… | |
| En análisis | Sin puntuar | 0.16% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix readahead synchronisation issues by loading all folios upfront There are some synchronisation issues that derive from the app thread adding more folios to the rolling buffer whilst the collector thread is looking at them or trying to clear… | |
| En análisis | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: cachefiles: Fix potential UAF/KASAN warning Currently, trace_cachefiles_coherency() is being passed a pointer to a __be64 lain over the coherency data in struct cachefiles_xattr so that it can display the first 8 bytes. However, the data is of… | |
| En análisis | Alta (7.8) | 0.13% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF snd_pcm_hw_params() and snd_pcm_hw_free() guard buffer reallocation with an mmap_count check performed under the PCM stream lock, but the lock is released long before the buffer is… | |
| En análisis | Alta (8.8) | 0.27% | — | Linux Kernel | 25/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely drain sessions during logoff SMB3 multichannel allows requests for one session to run on multiple connections. Wait for all channels bound to a session before freeing shared session objects. A deferred byte-range lock remains counted as… | |
| En análisis | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: propagate DACL parsing errors parse_dacl() silently accepts truncated ACEs and allocation failures, allowing set_info_sec() to continue with an incomplete ACL conversion. Return parsing and allocation errors to parse_sec_desc() so malformed… | |
| En análisis | Sin puntuar | 0.21% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: rate limit unmapped SID errors A client can include many structurally valid but unmapped SIDs in a DACL. Logging every mapping failure lets one request generate hundreds of kernel error messages. Rate limit the message to prevent an… | |
| En análisis | Alta (7.8) | 0.12% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix listener task lifetime on netdev events The listener thread exits when its listening socket is shutdown. The netdevice notifier shuts down the socket before calling kthread_stop(), so the task_struct can be freed before kthread_stop() gets… |