Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3242▲ 699 respecto a la semana anterior
Críticas / altas1520▲ 133 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
20.838 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.5) | 0.67% | — | Linux KernelAI | 15/8/2026 | 17/8/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/slab: prevent unbounded recursion in free path with new kmalloc type Commit 280ea9c3154b ("mm/slab: avoid allocating slabobj_ext array from its own slab") avoided recursive allocation of obj_exts from kmalloc caches of the same size, by bumping the… | |
| Recibida | Alta (8.8) | 0.40% | — | Linux KernelAI | 15/8/2026 | 23/8/2026 | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Prevent XDomain delayed work use-after-free on disconnect tb_xdp_handle_request() runs on system_wq and queues xd->state_work via queue_delayed_work() in three request handlers: PROPERTIES_CHANGED_REQUEST, UUID_REQUEST (via… | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 15/8/2026 | 17/8/2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() The failed_dev_add and failed_dev_name paths drop the file-device reference while wq->wq_lock is still held. If put_device(fdev) drops the last reference, idxd_file_dev_release() runs… | |
| Recibida | Crítica (9.3) | 0.19% | — | Linux KernelAI | 15/8/2026 | 17/8/2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE arm_vsmmu_vsid_to_sid() maps a guest's vSID to a single physical Stream ID taken from master->streams[0], assuming a device has exactly one stream. A device with several streams… | |
| Recibida | Alta (7.5) | 0.63% | — | Linux KernelAI | 15/8/2026 | 17/8/2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix deadlock between metadata writeback and transaction commit When writing out metadata extent buffers in a zoned filesystem, btree_writepages() holds fs_info->zoned_meta_io_lock across the whole writeback loop, including the call to… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 15/8/2026 | 17/8/2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: skip global block reserve accounting for rescue mounts [BUG] Mounting with rescue=ibadroots after corrupting the block group tree root triggers a NULL pointer dereference: The same crash occurs with a corrupted raid stripe tree root, via… | |
| Recibida | Crítica (9.8) | 0.55% | — | Linux KernelAI | 15/8/2026 | 17/8/2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: harden runlist realloc size calculations Add a shared helper to safely convert runlist element counts to byte sizes using overflow checks, and use it in both ntfs_rl_realloc() and ntfs_rl_realloc_nofail(). | |
| Recibida | Crítica (9.8) | 0.39% | — | Linux KernelAI | 15/8/2026 | 19/8/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() sip_help_tcp() stores the size change of each NAT-rewritten SIP message in s16 diff and accumulates it in s16 tdiff, but a single message can grow by more than S16_MAX while… | |
| Recibida | Crítica (9.3) | 0.18% | — | Linux KernelAI | 15/8/2026 | 17/8/2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Fix race between LPI release and re-registration Fix a potential race between decrementing an LPI's reference count and evicting that structure from the LPI xarray. LPI structures are maintained in the VGIC LPI xarray (dist->lpi_xa).… | |
| Recibida | Alta (7.1) | 0.12% | — | Linux KernelAI | 15/8/2026 | 19/8/2026 | In the Linux kernel, the following vulnerability has been resolved: keys: fix out-of-bounds read in keyring_get_key_chunk() For description-level chunks keyring_get_key_chunk() advances the read pointer by level * sizeof(long) past the inline prefix but only bounds-checks the prefix, so a long enough key description… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 15/8/2026 | 19/8/2026 | In the Linux kernel, the following vulnerability has been resolved: keys: make keyring key-chunk byte order agree with keyring_diff_objects() keyring_get_key_chunk() loads description bytes into the index chunk low address first, while keyring_diff_objects() numbers the first differing bit from the low end and folds… | |
| Recibida | Alta (7.8) | 0.12% | — | Linux KernelAI | 15/8/2026 | 14/9/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: make nft_object rhltable per table The nft_object rhltable is global, this allows for accessing objects that are being dismangled from lookup path by other existing netns. Given the nft_obj_destroy() releases the object… | |
| Recibida | Alta (7.1) | 0.12% | — | Linux KernelAI | 15/8/2026 | 19/8/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH The XT_HASHLIMIT_RATE_MATCH flag mode changes the semantics of the dsthash_ent structure which represents an entry in the hashtable. There is a union area which uses a… | |
| Recibida | Alta (7.8) | 0.12% | — | Linux KernelAI | 15/8/2026 | 19/8/2026 | In the Linux kernel, the following vulnerability has been resolved: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() rds_tcp_laddr_check() looks up a scoped IPv6 interface with dev_get_by_index_rcu(), drops the RCU read-side lock, and only then passes the bare struct net_device * into… | |
| Recibida | Alta (8.8) | 0.17% | — | Linux KernelAI | 15/8/2026 | 17/8/2026 | In the Linux kernel, the following vulnerability has been resolved: nexthop: take nh->lock for f6i_list walks in replace check and notify fib6_check_nh_list() and __nexthop_replace_notify() walk nh->f6i_list during an RTNL-serialized nexthop replace without holding nh->lock. IPv6 RTM_NEWROUTE/RTM_DELROUTE run without… | |
| Recibida | Alta (8.8) | 0.17% | — | Linux KernelAI | 15/8/2026 | 17/8/2026 | In the Linux kernel, the following vulnerability has been resolved: nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush nh_rt_cache_flush() walks nh->f6i_list during an RTNL-serialized nexthop replace without holding nh->lock, racing the unlocked IPv6 route add/delete that mutate the list under nh->lock and… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 15/8/2026 | 17/8/2026 | In the Linux kernel, the following vulnerability has been resolved: xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx This patch is inspired by the check[1] from sashiko. It says when overflow happens, the address of cq to be published is invalid. Actually the severer thing is the whole process of… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 15/8/2026 | 17/8/2026 | In the Linux kernel, the following vulnerability has been resolved: xsk: drain continuation descs after overflow in xsk_build_skb() Fix generic xmit path multi-buffer logic when packets are either too big (count of descriptors exceed MAX_SKB_FRAGS) or an invalid descriptor is included in fragmented packet. Introduce… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 15/8/2026 | 17/8/2026 | In the Linux kernel, the following vulnerability has been resolved: xsk: reclaim invalid Tx descriptors in ZC batch path The zero-copy Tx batch parser stops when it encounters an invalid descriptor. If this happens after one or more continuation descriptors, the Tx consumer can be advanced past fragments that are… | |
| Recibida | Alta (7.5) | 0.33% | — | Linux KernelAI | 15/8/2026 | 19/8/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer iscsi_scsi_cmd_rsp() copies the sense data of a SCSI Response from the target-supplied data segment. The segment carries a 2-byte sense length followed by the sense bytes, so it must hold… | |
| Recibida | Crítica (9.8) | 0.40% | — | Linux KernelAI | 15/8/2026 | 19/8/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer iscsi_tcp_hdr_dissect() receives the data segment of several PDU types into the fixed-size conn->data buffer, which is allocated for ISCSI_DEF_MAX_RECV_SEG_LEN (8192) bytes.… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 15/8/2026 | 19/8/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race Commit fbefe22811c3 ("scsi: libsas: Don't always drain event workqueue for HA resume") introduced sas_resume_ha_no_sync() to avoid a deadlock: the PHYE_RESUME_TIMEOUT handler, running on… | |
| Recibida | Alta (8.8) | 0.34% | — | Linux KernelAI | 15/8/2026 | 17/8/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup() ath12k_mac_dp_peer_cleanup() clears the ML peer ID slot on the free_ml_peer_id_map bitmap by indexing it with dp_peer->peer_id. That is wrong: dp_peer->peer_id for an MLO peer… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 15/8/2026 | 19/8/2026 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 Unlike NCT6106, NCT6116 only has three temperature registers, and with it only three temperature source and temperature source configuration registers. The register addresses match… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 15/8/2026 | 19/8/2026 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Only report alarms if driver is ready Userspace can read sysfs attributes before driver registration is complete, immediately after devm_hwmon_device_register_with_info() has been called. At that time, data->hwmon_dev is not yet… |