Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
10.007 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.52% | — | Linux KernelDebian Linux | 25/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request If the request being processed is not a v4 compound request, then examining the cstate can have undefined results. This patch adds a check that the rpc procedure being executed… | |
| Analizada | Alta (7.8) | 0.19% | — | Linux KernelDebian Linux | 25/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - check record size in ims_pcu_flash_firmware() The "len" variable comes from the firmware and we generally do trust firmware, but it's always better to double check. If the "len" is too large it could result in memory corruption when… | |
| Modificada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 25/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: i2c: tegra: check msg length in SMBUS block read For SMBUS block read, do not continue to read if the message length passed from the device is '0' or greater than the maximum allowed bytes. | |
| Modificada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 25/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: perf: Fix sample vs do_exit() Baisheng Gao reported an ARM64 crash, which Mark decoded as being a synchronous external abort -- most likely due to trying to access MMIO in bad ways. The crash further shows perf trying to do a user stack sample while… | |
| Modificada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 25/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Modify the EEPROM and OTP size for PCI1xxxx devices Maximum OTP and EEPROM size for hearthstone PCI1xxxx devices are 8 Kb and 64 Kb respectively. Adjust max size definitions and return correct EEPROM length based on device. Also prevent… | |
| Analizada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 25/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: do not ping device which has failed to load firmware Syzkaller reports [1, 2] crashes caused by an attempts to ping the device which has failed to load firmware. Since such a device doesn't pass 'ieee80211_register_hw()', an internal… | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 25/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Cleanup acquired resources when rproc_handle_resources() fails in rproc_attach() When rproc->state = RPROC_DETACHED and rproc_attach() is used to attach to the remote processor, if rproc_handle_resources() returns a failure, the… | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 25/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Release rproc->clean_table after rproc_attach() fails When rproc->state = RPROC_DETACHED is attached to remote processor through rproc_attach(), if rproc_handle_resources() returns failure, then the clean table should be released,… | |
| Modificada | Alta (7.8) | 0.21% | — | Linux KernelDebian Linux | 25/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: NFC: nci: uart: Set tty->disc_data only in success path Setting tty->disc_data before opening the NCI device means we need to clean it up on error paths. This also opens some short window if device starts sending data, even before NCIUARTSETDRIVER… | |
| Analizada | Alta (7.8) | 0.19% | — | Linux KernelDebian Linux | 25/7/2025 | 18/6/2026 | In the Linux kernel, the following vulnerability has been resolved: Squashfs: check return result of sb_min_blocksize Syzkaller reports an "UBSAN: shift-out-of-bounds in squashfs_bio_read" bug. Syzkaller forks multiple processes which after mounting the Squashfs filesystem, issues an ioctl("/dev/loop0",… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 25/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Fix WMI data block retrieval in sysfs callbacks After retrieving WMI data blocks in sysfs callbacks, check for the validity of them before dereferencing their content. | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 25/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix a fence leak in submit error path In error paths, we could unref the submit without calling drm_sched_entity_push_job(), so msm_job_free() will never get called. Since drm_sched_job_cleanup() will NULL out the s_fence, we can use that to… | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 25/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix another leak in the submit error path put_unused_fd() doesn't free the installed file, if we've already done fd_install(). So we need to also free the sync_file. Patchwork: https://patchwork.freedesktop.org/patch/653583/ | |
| Analizada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 25/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: remove WARN on bad firmware input If the firmware gives bad input, that's nothing to do with the driver's stack at this point etc., so the WARN_ON() doesn't add any value. Additionally, this is one of the top syzbot reports now. Just… | |
| Analizada | Media (5.5) | 0.14% | — | Linux KernelDebian Linux | 25/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: displayport: Fix potential deadlock The deadlock can occur due to a recursive lock acquisition of `cros_typec_altmode_data::mutex`. The call chain is as follows: 1. cros_typec_altmode_work() acquires the mutex 2. typec_altmode_vdm() ->… | |
| Analizada | Alta (7.8) | 0.19% | — | Linux KernelDebian Linux | 25/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: Clear the vmci transport packet properly when initializing it In vmci_transport_packet_init memset the vmci_transport_packet before populating the fields to avoid any uninitialised data being left in the structure. | |
| Modificada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 25/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: mtk-sd: Prevent memory corruption from DMA map failure If msdc_prepare_data() fails to map the DMA region, the request is not prepared for data receiving, but msdc_start_data() proceeds the DMA with previous setting. Since this will lead a memory… | |
| Modificada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 25/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails. syzbot reported a warning below [1] following a fault injection in nfs_fs_proc_net_init(). [0] When nfs_fs_proc_net_init() fails, /proc/net/rpc/nfs is not removed. Later,… | |
| Modificada | Media (5.5) | 0.44% | — | Linux KernelDebian Linux | 25/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix NULL pointer dereference in core_scsi3_decode_spec_i_port() The function core_scsi3_decode_spec_i_port(), in its error code path, unconditionally calls core_scsi3_lunacl_undepend_item() passing the dest_se_deve pointer, which may be… | |
| Modificada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 25/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: fs: export anon_inode_make_secure_inode() and fix secretmem LSM bypass Export anon_inode_make_secure_inode() to allow KVM guest_memfd to create anonymous inodes with proper security context. This replaces the current pattern of calling… | |
| Modificada | Alta (7.1) | 0.18% | — | Linux KernelDebian Linux | 25/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods drvdata::gpiods is supposed to hold an array of 'gpio_desc' pointers. But the memory is allocated for only one pointer. This will lead to out-of-bounds access later in the code if… | |
| Modificada | Media (4.7) | 0.35% | — | Linux KernelDebian Linux | 25/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Fix a race to wake on NFS_LAYOUT_DRAIN We found a few different systems hung up in writeback waiting on the same page lock, and one task waiting on the NFS_LAYOUT_DRAIN bit in pnfs_update_layout(), however the pnfs_layout_hdr's… | |
| Analizada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 25/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: do not index invalid pin_assignments A poorly implemented DisplayPort Alt Mode port partner can indicate that its pin assignment capabilities are greater than the maximum value, DP_PIN_ASSIGN_F. In this case, calls to… | |
| Analizada | Alta (7.8) | 0.19% | — | Linux KernelDebian Linux | 25/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Fix timeline left held on VMA alloc error The following error has been reported sporadically by CI when a test unbinds the i915 driver on a ring submission platform: If the test also unloads the i915 module then that's followed with:… | |
| Analizada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 25/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Initialize obj_event->obj_sub_list before xa_insert The obj_event may be loaded immediately after inserted, then if the list_head is not initialized then we may get a poisonous pointer. This fixes the crash below: mlx5_core 0000:03:00.0:… |