Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
10.007 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Use memcpy() for BIOS version The strlcat() with FORTIFY support is triggering a panic because it thinks the target buffer will overflow although the correct target buffer size is passed in. Anyway, instead of memset() with 0 followed by a… | |
| Modificada | Media (5.5) | 0.34% | — | Linux KernelDebian Linux | 10/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Use TOE/TSO on all TCP It is desireable to push the hardware accelerator to also process non-segmented TCP frames: we pass the skb->len to the "TOE/TSO" offloader and it will handle them. Without this quirk the driver becomes… | |
| Analizada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: jffs2: check jffs2_prealloc_raw_node_refs() result in few other places Fuzzing hit another invalid pointer dereference due to the lack of checking whether jffs2_prealloc_raw_node_refs() completed successfully. Subsequent logic implies that the node… | |
| Analizada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: aoe: clean device rq_list in aoedev_downdev() An aoe device's rq_list contains accepted block requests that are waiting to be transmitted to the aoe target. This queue was added as part of the conversion to blk_mq. However, the queue was not cleaned… | |
| Analizada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu(). As syzbot reported [0], mpls_route_input_rcu() can be called from mpls_getroute(), where is under RTNL. net->mpls.platform_label is only updated under RTNL. Let's use rcu_dereference_rtnl()… | |
| Analizada | Alta (7.8) | 0.20% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net: atm: add lec_mutex syzbot found its way in net/atm/lec.c, and found an error path in lecd_attach() could leave a dangling pointer in dev_lec[]. Add a mutex to protect dev_lecp[] uses from lecd_attach(), lec_vcc_attach() and lec_mcast_attach().… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 10/7/2025 | 14/7/2026 | In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Fix crash in icl_update_topdown_event() The perf_fuzzer found a hard-lockup crash on a RaptorLake machine: CPUs 16-23 are E-core CPUs that don't support the perf metrics feature. The icl_update_topdown_event() should not be invoked on… | |
| Analizada | Alta (7.1) | 0.20% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth() This issue seems to be related to the behavior of some gcc compilers and was also fixed on the s390 architecture before: commit d93a855c31b7 ("s390/ptrace: Avoid KASAN false… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/pp: Fix potential NULL pointer dereference in atomctrl_initialize_mc_reg_table The function atomctrl_initialize_mc_reg_table() and atomctrl_initialize_mc_reg_table_v2_2() does not check the return value of smu_atom_get_data_table(). If… | |
| Analizada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc: fix double-free on mc_dev The blamed commit tried to simplify how the deallocations are done but, in the process, introduced a double-free on the mc_dev variable. In case the MC device is a DPRC, a new mc_bus is allocated and the mc_dev… | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod() In fb_find_mode_cvt(), iff mode->refresh somehow happens to be 0x80000000, cvt.f_refresh will become 0 when multiplying it by 2 due to overflow. It's then passed to fb_cvt_hperiod(), where… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: seg6: Fix validation of nexthop addresses The kernel currently validates that the length of the provided nexthop address does not exceed the specified length. This can lead to the kernel reading uninitialized memory if user space provided a shorter… | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ptp: remove ptp->n_vclocks check logic in ptp_vclock_in_use() There is no disagreement that we should check both ptp->is_virtual_clock and ptp->n_vclocks to check if the ptp virtual clock is in use. However, when we acquire ptp->n_vclocks_mux to read… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix NULL pointer deference on eir_get_service_data The len parameter is considered optional so it can be NULL so it cannot be used for skipping to next entry of EIR_SERVICE_DATA. | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ce-cipher - fix error handling in sun8i_ce_cipher_prepare() Fix two DMA cleanup issues on the error path in sun8i_ce_cipher_prepare(): To fix this, check for !dma_mapping_error() before calling dma_unmap_single() on the "theend_iv" path. | |
| Analizada | Alta (7.8) | 0.21% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: EDAC/skx_common: Fix general protection fault After loading i10nm_edac (which automatically loads skx_edac_common), if unload only i10nm_edac, then reload it and perform error injection testing, a general protection fault may occur: The issue arose… | |
| Modificada | Media (5.5) | 0.32% | — | Linux KernelDebian Linux | 10/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix node corruption in ar->arvifs list In current WLAN recovery code flow, ath11k_core_halt() only reinitializes the "arvifs" list head. This will cause the list node immediately following the list head to become an invalid list node.… | |
| Analizada | Alta (7.1) | 0.20% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: at91: Fix possible out-of-boundary access at91_gpio_probe() doesn't check that given OF alias is not available or something went wrong when trying to get it. This might have consequences when accessing gpio_chips array with that value as an… | |
| Modificada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix WARN() in get_bpf_raw_tp_regs syzkaller reported an issue: Tracepoint like trace_mmap_lock_acquire_returned may cause nested call as the corner case show above, which will be resolved with more general method in the future. As a result,… | |
| Analizada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: kernfs: Relax constraint in draining guard The active reference lifecycle provides the break/unbreak mechanism but the active reference is not truly active after unbreak -- callers don't use it afterwards but it's important for proper pairing of… | |
| Modificada | Alta (7.8) | 0.20% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid __bpf_prog_ret0_warn when jit fails syzkaller reported an issue: When creating bpf program, 'fp->jit_requested' depends on bpf_jit_enable. This issue is triggered because of CONFIG_BPF_JIT_ALWAYS_ON is not set and bpf_jit_enable is set to… | |
| Analizada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mtd: nand: ecc-mxic: Fix use of uninitialized variable ret If ctx->steps is zero, the loop processing ECC steps is skipped, and the variable ret remains uninitialized. It is later checked and returned, which leads to undefined behavior and may cause… | |
| Analizada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 10/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug The qmp_usb_iomap() helper function currently returns the raw result of devm_ioremap() for non-exclusive mappings. Since devm_ioremap() may return a NULL pointer and the caller only checks error pointers… | |
| Modificada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 10/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net: tipc: fix refcount warning in tipc_aead_encrypt syzbot reported a refcount warning [1] caused by calling get_net() on a network namespace that is being destroyed (refcount=0). This happens when a TIPC discovery timer fires during network… | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 9/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: bcache: fix NULL pointer in cache_set_flush() 1. LINE#1794 - LINE#1887 is some codes about function of bch_cache_set_alloc(). 2. LINE#2078 - LINE#2142 is some codes about function of register_cache_set(). 3. register_cache_set() will call… |