Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
10.164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 4/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: inline: fix len overflow in ext4_prepare_inline_data When running the following code on an ext4 filesystem with inline_data feature enabled, it will lead to the bug below. That happens because write_begin will succeed as when… | |
| Analizada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 4/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: f2fs: prevent kernel warning due to negative i_nlink from corrupted image | |
| Modificada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 4/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on sit_bitmap_size w/ below testcase, resize will generate a corrupted image which contains inconsistent metadata, so when mounting such image, it will trigger kernel panic: touch img truncate -s $((512*1024*1024*1024))… | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 4/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix do_register_framebuffer to prevent null-ptr-deref in fb_videomode_to_var If fb_add_videomode() in do_register_framebuffer() fails to allocate memory for fb_videomode, it will later lead to a null-ptr dereference in fb_videomode_to_var(), as… | |
| Modificada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 4/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var If fb_add_videomode() in fb_set_var() fails to allocate memory for fb_videomode, later it may lead to a null-ptr dereference in fb_videomode_to_var(), as the fb_info is registered… | |
| Modificada | Alta (7.8) | 0.19% | — | Linux KernelDebian Linux | 4/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: ipc: fix to protect IPCS lookups using RCU syzbot reported that it discovered a use-after-free vulnerability, [0] [0]: https://lore.kernel.org/all/67af13f8.050a0220.21dd3.0038.GAE@google.com/ idr_for_each() is protected by rwsem, but this is not… | |
| Modificada | Alta (7.8) | 0.41% | — | Linux KernelDebian Linux | 4/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction The commit 59c68ac31e15 ("iw_cm: free cm_id resources on the last deref") simplified cm_id resource management by freeing cm_id once all references to the cm_id were removed. The… | |
| Modificada | Alta (7.8) | 0.19% | — | Linux KernelDebian Linux | 4/7/2025 | 2/9/2026 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix double free in delayed_free The double free could happen in the following path. | |
| Modificada | Alta (7.1) | 0.19% | — | Linux KernelDebian Linux | 4/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds read in add_missing_indices stbl is s8 but it must contain offsets into slot which can go from 0 to 127. Added a bound check for that error and return -EIO if the check fails. Also make jfs_readdir return with error… | |
| Modificada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 4/7/2025 | 2/9/2026 | In the Linux kernel, the following vulnerability has been resolved: jfs: Fix null-ptr-deref in jfs_ioc_trim [ Syzkaller Report ] [ Analysis ] We believe that we have found a concurrency bug in the `fs/jfs` module that results in a null pointer dereference. There is a closely related issue which has been fixed:… | |
| Analizada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 4/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() bpf_map_lookup_percpu_elem() helper is also available for sleepable bpf program. When BPF JIT is disabled or under 32-bit host, bpf_map_lookup_percpu_elem() will not be inlined.… | |
| Analizada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 4/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: i40e: fix MMIO write access to an invalid page in i40e_clear_hw When the device sends a specific input, an integer underflow can occur, leading to MMIO write access to an invalid page. Prevent the integer underflow by changing the type of related… | |
| Modificada | Alta (7.8) | 0.19% | — | Linux KernelDebian Linux | 4/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: fbcon: Make sure modelist not set on unregistered console It looks like attempting to write to the "store_modes" sysfs node will run afoul of unregistered consoles: static struct fb_info *fbcon_registered_fb[FB_MAX]; ... static signed char… | |
| Modificada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 4/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell_rbu: Fix list usage Pass the correct list head to list_for_each_entry*() when looping through the packet list. Without this patch, reading the packet data via sysfs will show the data incorrectly (because it starts at the wrong… | |
| Analizada | Media (5.5) | 0.22% | — | Linux KernelDebian Linux | 4/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: jffs2: check that raw node were preallocated before writing summary Syzkaller detected a kernel bug in jffs2_link_node_ref, caused by fault injection in jffs2_prealloc_raw_node_refs. jffs2_sum_write_sumnode doesn't check return value of… | |
| Modificada | Media (5.5) | 0.21% | — | Linux KernelDebian Linux | 4/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: reject invalid perturb period Gerrard Tai reported that SFQ perturb_period has no range check yet, and this can be used to trigger a race condition fixed in a separate patch. We want to make sure ctl->perturb_period * HZ will not… | |
| Modificada | Media (5.5) | 1.4% | — | Linux KernelDebian Linux | 4/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in destroy_previous_session If client set ->PreviousSessionId on kerberos session setup stage, NULL pointer dereference error will happen. Since sess->user is not set yet, It can pass the user argument as NULL to… | |
| Analizada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 4/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: atm: Revert atm_account_tx() if copy_from_iter_full() fails. In vcc_sendmsg(), we account skb->truesize to sk->sk_wmem_alloc by atm_account_tx(). It is expected to be reverted by atm_pop_raw() later called by vcc->dev->ops->send(vcc, skb). However,… | |
| Analizada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 4/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: atm: atmtcp: Free invalid length skb in atmtcp_c_send(). syzbot reported the splat below. [0] vcc_sendmsg() copies data passed from userspace to skb and passes it to vcc->dev->ops->send(). atmtcp_c_send() accesses skb->data as struct atmtcp_hdr after… | |
| Modificada | Media (5.5) | 0.21% | — | Linux KernelDebian Linux | 4/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer The reproduction steps: 1. create a tun interface 2. enable l2 bearer 3. TIPC_NL_UDP_GET_REMOTEIP with media name set to tun the ub was in fact a struct dev. when bid != 0 &&… | |
| Analizada | Alta (7.8) | 0.19% | — | Linux KernelDebian Linux | 4/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net: lan743x: fix potential out-of-bounds write in lan743x_ptp_io_event_clock_get() Before calling lan743x_ptp_io_event_clock_get(), the 'channel' value is checked against the maximum value of PCI11X1X_PTP_IO_MAX_CHANNELS(8). This seems correct and… | |
| Modificada | Media (5.5) | 0.56% | — | Linux KernelDebian Linux | 4/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: calipso: Fix null-ptr-deref in calipso_req_{set,del}attr(). syzkaller reported a null-ptr-deref in sock_omalloc() while allocating a CALIPSO option. [0] The NULL is of struct sock, which was fetched by sk_to_full_sk() in calipso_req_setattr(). Since… | |
| Modificada | Alta (7.8) | 0.21% | — | Linux KernelDebian Linux | 4/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net: atm: fix /proc/net/atm/lec handling /proc/net/atm/lec must ensure safety against dev_lec[] changes. It appears it had dev_put() calls without prior dev_hold(), leading to imbalance and UAF. | |
| Modificada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 4/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: sch_hfsc: make hfsc_qlen_notify() idempotent hfsc_qlen_notify() is not idempotent either and not friendly to its callers, like fq_codel_dequeue(). Let's make it idempotent to ease qdisc_tree_reduce_backlog() callers' life: 1. update_vf() decreases… | |
| Modificada | Media (5.5) | 0.27% | — | Linux KernelDebian Linux | 4/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Do not double dequeue a configuration request Some of our devices crash in tb_cfg_request_dequeue(): general protection fault, probably for non-canonical address 0xdead000000000122 The circumstances are unclear, however, the theory is… |