Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

71 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.37%—Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware+819/4/20211/9/2026
An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from…
ModificadaMedia (6.7)0.80%—Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp Fas/aff Baseboard Management Controller+122/3/202117/6/2026
In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and…
ModificadaMedia (5.5)0.39%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+322/3/202117/6/2026
In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6.
ModificadaMedia (4.7)0.27%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+322/3/202117/6/2026
A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc.
ModificadaAlta (7.8)0.38%—Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp A250 Firmware+320/3/202117/6/2026
An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered, aka CID-1c668e1c0a0f. (This has been fixed in 5.12-rc4.)
ModificadaMedia (5.5)0.28%—Linux KernelFedoraproject FedoraNetapp A250 FirmwareNetapp AFF 500f Firmware+320/3/202117/6/2026
An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (deadlock) because exit may be waiting to park a SQPOLL thread, but concurrently that SQPOLL thread is waiting for a signal to start, aka CID-3ebba796fa25.
ModificadaAlta (8.8)1.3%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+817/3/202117/6/2026
rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work); however, system integrators may have…
ModificadaAlta (7.8)0.30%—Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware15/3/202117/6/2026
An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308.
AnalizadaAlta (7.8)2.1%💥 PoCNetapp Cloud BackupLinux KernelDebian LinuxOracle Tekelec Platform Distribution+17/3/202130/7/2026
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink…
AnalizadaAlta (7.1)0.97%—Netapp Cloud BackupLinux KernelDebian LinuxNetapp Solidfire Baseboard Management Controller Firmware+27/3/202130/7/2026
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
ModificadaMedia (4.4)0.71%—Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware7/3/202117/6/2026
An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system, at…
ModificadaMedia (6.5)0.42%—Linux KernelXENNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware5/3/202117/6/2026
An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical addresses when a configuration has…
ModificadaMedia (6.5)0.71%—Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware5/3/202117/6/2026
An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host OS denial of service may occur during misbehavior of a…
ModificadaMedia (6.7)2.3%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+15/1/202117/6/2026
mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332.
ModificadaMedia (5.7)0.28%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise MRGDebian Linux+311/12/202017/6/2026
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a…
ModificadaMedia (5.7)0.38%—Debian Advanced Package ToolNetapp Solidfire Baseboard Management Controller Firmware10/12/202017/6/2026
—
ModificadaAlta (7.8)1.1%💥 PoCLinux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+89/12/202017/6/2026
A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.
ModificadaMedia (4.4)0.47%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+79/12/202017/6/2026
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24.
ModificadaAlta (7.5)2.2%—OpenldapRedhat Enterprise LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware8/12/202017/6/2026
A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service.
ModificadaAlta (8.1)5.2%—Linux KernelNetapp Cloud BackupNetapp A250 FirmwareNetapp FAS 500f Firmware+22/12/202017/6/2026
An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to…
ModificadaAlta (7)0.61%💥 PoCLinux KernelNetapp Cloud BackupNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+328/11/202017/6/2026
An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment, aka CID-fd4d9c7d0c71.
ModificadaMedia (6.7)0.93%💥 PoCLinux KernelBroadcom Brocade Fabric Operating System FirmwareNetapp Cloud BackupNetapp Solidfire & HCI Management Node+1523/11/202017/6/2026
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
ModificadaAlta (7.8)1.0%💥 PoCLinux KernelRedhat Enterprise LinuxOpensuse LeapDebian Linux+619/8/202017/6/2026
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
ModificadaMedia (6.5)5.2%—Linux KernelOpensuse LeapDebian LinuxCanonical Ubuntu Linux+2018/5/202017/6/2026
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.
ModificadaMedia (5.3)0.40%—Linux KernelFedoraproject FedoraOpensuse LeapDebian Linux+2115/5/202017/6/2026
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.