Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
10.164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.46% | — | Linux KernelDebian Linux | 3/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net: fix udp gso skb_segment after pull from frag_list Commit a1e40ac5b5e9 ("net: gso: fix udp gso fraglist segmentation after pull from frag_list") detected invalid geometry in frag_list skbs and redirects them from skb_segment_list to more robust… | |
| Analizada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 3/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: gve: add missing NULL check for gve_alloc_pending_packet() in TX DQO gve_alloc_pending_packet() can return NULL, but gve_tx_add_skb_dqo() did not check for this case before dereferencing the returned pointer. Add a missing NULL check to prevent a… | |
| Modificada | Media (5.5) | 0.51% | — | Linux KernelDebian Linux | 3/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo_avx2: fix initial map fill If the first field doesn't cover the entire start map, then we must zero out the remainder, else we leak those bits into the next match round map. The early fix was incomplete and did only fix up the… | |
| Modificada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 3/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: core: ufs: Fix a hang in the error handler ufshcd_err_handling_prepare() calls ufshcd_rpm_get_sync(). The latter function can only succeed if UFSHCD_EH_IN_PROGRESS is not set because resuming involves submitting a SCSI command and… | |
| Modificada | Alta (7.8) | 0.20% | — | Linux KernelDebian Linux | 3/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix UAF on mgmt_remove_adv_monitor_complete This reworks MGMT_OP_REMOVE_ADV_MONITOR to not use mgmt_pending_add to avoid crashes like bellow: | |
| Modificada | Media (5.5) | 0.22% | — | Linux KernelDebian Linux | 3/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: fix a potential crash on gso_skb handling SFQ has an assumption of always being able to queue at least one packet. However, after the blamed commit, sch->q.len can be inflated by packets in sch->gso_skb, and an enqueue() on an… | |
| Analizada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 3/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Fix NULL pointer dereference when nosmp is used With nosmp in cmdline, other CPUs are not brought up, leaving their cpc_desc_ptr NULL. CPU0's iteration via for_each_possible_cpu() dereferences these NULL pointers, causing panic. Panic… | |
| Analizada | Media (4.7) | 0.14% | — | Linux KernelDebian Linux | 3/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net: Fix TOCTOU issue in sk_is_readable() sk->sk_prot->sock_is_readable is a valid function pointer when sk resides in a sockmap. After the last sk_psock_put() (which usually happens when socket is removed from sockmap), sk->sk_prot gets restored and… | |
| Modificada | Alta (7.1) | 0.22% | — | Linux KernelDebian Linux | 3/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net/mdiobus: Fix potential out-of-bounds read/write access When using publicly available tools like 'mdio-tools' to read/write data from/to network interface and its PHY via mdiobus, there is no verification of parameters passed to the ioctl and it… | |
| Modificada | Alta (7) | 0.16% | — | Linux KernelDebian Linux | 3/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net_sched: red: fix a race in __red_change() Gerrard Tai reported a race condition in RED, whenever SFQ perturb timer fires at the wrong time. The race is as follows: CPU 0 CPU 1 [1]: lock root [2]: qdisc_tree_flush_backlog() [3]: unlock root | | [5]:… | |
| Modificada | Alta (7) | 0.15% | — | Linux KernelDebian Linux | 3/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net_sched: ets: fix a race in ets_qdisc_change() Gerrard Tai reported a race condition in ETS, whenever SFQ perturb timer fires at the wrong time. The race is as follows: CPU 0 CPU 1 [1]: lock root [2]: qdisc_tree_flush_backlog() [3]: unlock root | |… | |
| Analizada | Alta (7.1) | 0.21% | — | Linux KernelDebian Linux | 3/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse() Update struct hid_descriptor to better reflect the mandatory and optional parts of the HID Descriptor as per USB HID 1.11 specification. Note: the kernel currently does not parse any… | |
| Modificada | Alta (7) | 0.16% | — | Linux KernelDebian Linux | 3/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify During our test, it is found that a warning can be trigger in try_grab_folio as follow: Digging into the source, context->notify_page may init by get_user_pages_fast and can be… | |
| Modificada | Media (5.5) | 0.21% | — | Linux KernelDebian Linux | 3/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: x86/iopl: Cure TIF_IO_BITMAP inconsistencies io_bitmap_exit() is invoked from exit_thread() when a task exists or when a fork fails. In the latter case the exit_thread() cleans up resources which were allocated during fork(). io_bitmap_exit() invokes… | |
| Modificada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 3/7/2025 | 14/9/2026 | In the Linux kernel, the following vulnerability has been resolved: espintcp: remove encap socket caching to avoid reference leak The current scheme for caching the encap socket can lead to reference leaks when we try to delete the netns. The reference chain is: xfrm_state -> enacp_sk -> netns Since the encap socket… | |
| Modificada | Media (5.5) | 0.21% | — | Linux KernelDebian Linux | 3/7/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: dma-buf: insert memory barrier before updating num_fences smp_store_mb() inserts memory barrier after storing operation. It is different with what the comment is originally aiming so Null pointer dereference can be happened if memory update is… | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 3/7/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net: cadence: macb: Fix a possible deadlock in macb_halt_tx. There is a situation where after THALT is set high, TGO stays high as well. Because jiffies are never updated, as we are in a context with interrupts disabled, we never exit that loop and… | |
| Modificada | Alta (8.2) | 0.41% | — | Debian Dpkg | 1/7/2025 | 8/7/2026 | It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe operation even on untrusted data. This may result in leaving temporary files behind on cleanup. Given automated and repeated execution of… | |
| Analizada | Alta (7.8) | 55% | ⚠ Explotación activa💥 Exploit | Sudo Project SudoCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+4 | 30/6/2025 | 17/6/2026 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. | |
| Modificada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 30/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: drivers/rapidio/rio_cm.c: prevent possible heap overwrite In cm_chan_msg_send() checks that userspace didn't send too much data but riocm_ch_send() failed to check that userspace sent sufficient data. The result is that riocm_ch_send() can write to… | |
| Analizada | Alta (7.1) | 0.17% | — | Linux KernelDebian Linux | 30/6/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv/memtrace: Fix out of bounds issue in memtrace mmap memtrace mmap issue has an out of bounds issue. This patch fixes the by checking that the requested mapping region size should stay within the allocated region size. | |
| Analizada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 28/6/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net: ch9200: fix uninitialised access during mii_nway_restart In mii_nway_restart() the code attempts to call mii->mdio_read which is ch9200_mdio_read(). ch9200_mdio_read() utilises a local buffer called "buff", which is initialised with… | |
| Modificada | Media (4.7) | 0.15% | — | Linux KernelDebian Linux | 28/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race huge_pmd_unshare() drops a reference on a page table that may have previously been shared across processes, potentially turning it into a normal page table used in another process in which unrelated… | |
| Modificada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 28/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: unshare page tables during VMA split, not before Currently, __split_vma() triggers hugetlb page table unsharing through vm_ops->may_split(). This happens before the VMA lock and rmap locks are taken - which is too early, it allows racing… | |
| Analizada | Baja (3.9) | 0.13% | — | Debian Pycode-browser | 26/6/2025 | 17/6/2026 | pycode-browser before version 1.0 is prone to a predictable temporary file vulnerability. |