Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
20.828 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: media: dm1105: fix missing error check for dma_alloc_coherent The return value of dm1105_dma_map(), which handles DMA memory allocation, is ignored in dm1105_hw_init(). If dma_alloc_coherent() fails, the driver will proceed using a NULL pointer for… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: ixp4xx - fix buffer chain unwind on allocation failure chainup_buffers() builds a linked list of buffer descriptors for a scatterlist. If dma_pool_alloc() fails while constructing the list, the current code sets buf to NULL and later… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 24/9/2026 | 28/9/2026 | In the Linux kernel, the following vulnerability has been resolved: PCI/sysfs: Add CAP_SYS_ADMIN check to __resource_resize_store() Currently, the __resource_resize_store() allows writing to the resourceN_resize sysfs attribute to change a BAR's size without checking for capabilities, currently relying only on the… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 24/9/2026 | 28/9/2026 | In the Linux kernel, the following vulnerability has been resolved: watchdog: lenovo_se10_wdt: Fix use-after-free and resource leak risk Review by sashiko.dev highlighted potential use after free and resource leak instances. Set se10_pdev to null to prevent use after free Remove DMI call back and instead directly call… | |
| Recibida | Sin puntuar | 0.14% | — | Linux KernelAI | 24/9/2026 | 28/9/2026 | In the Linux kernel, the following vulnerability has been resolved: genirq/proc: Size interrupt directory names for 10-digit interrupt numbers /proc/irq/<n>/ directory names are built in `char name[10]` buffers with `sprintf(name, "%u", irq)`. Ten-digit IRQ numbers already need 11 bytes including the trailing NUL, and… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: davinci: avoid NULL deref of host->data in IRQ handler mmc_davinci_irq() returns early only when both host->cmd and host->data are NULL: So we may legitimately reach the rest of the handler with host->data == NULL (and therefore data == NULL).… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 24/9/2026 | 28/9/2026 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: paris: bypass pinctrl GPIO layer in set GPIO direction pinctrl_gpio_direction_input() / pinctrl_gpio_direction_output() take the pinctrl mutex. This causes a gpiochip operations to need to sleep. Worse yet, the .can_sleep field in… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: phy: check length before parsing PHY status IE Hardware might report PHY status IE with unexpected length, and parser might access out of range. Check the length ahead. | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 24/9/2026 | 28/9/2026 | In the Linux kernel, the following vulnerability has been resolved: coresight: perf: Retrieve path and source from event data ETM perf callbacks currently use the per-CPU csdev_src pointer, which can race with updates during device registration and unregistration. The AUX setup already builds and stores the path in… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 24/9/2026 | 28/9/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: pin mqd and fw object bo to avoid eviction mqd and fw objects are queue core objects which should remain valid and never be unmapped and evicted for user queues to work properly. During eviction if these buffers are evicted the hw… | |
| Recibida | Alta (7.8) | 0.13% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id allocate_sdma_queue has an option where the sdma queue id can be specified (used by CRIU). We weren't bounds-checking that value. Confirm it's less than the maximum number of queues. | |
| Recibida | Alta (7.1) | 0.13% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix OOB memory exposure in get_wave_state() The get_wave_state() function for v9 trusts cp_hqd_cntl_stack_size and cp_hqd_cntl_stack_offset values read directly from the MQD, which are written by GPU microcode and fully attacker-controlled… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds on allocate_doorbell allocated_doorbell has an option to set the doorbell id to a specific value (used by CRIU). This value was not bounds checked. Check to confirm it's less than KFD_MAX_NUM_OF_QUEUES_PER_PROCESS. | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 28/9/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate and share PSP fw_pri_buf copies via psp_copy_fw Change psp_copy_fw from void to int: return -ENODEV when drm_dev_enter fails, and -EINVAL when the image size is zero or larger than the 1 MiB PSP private buffer. Replace open-coded… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 24/9/2026 | 28/9/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Bound GPIO I2C table entry count from VBIOS Reject undersized tables and cap the derived entry count to AMDGPU_MAX_I2C_BUS so we do not overrun adev->i2c_bus[] or walk an absurd number of entries on corrupt size fields. | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed In case reconfiguration of NAN fails, we call ieee80211_handle_reconfig_failure, that marks all interfaces as not in the driver. Then, at the error path of the reconfig,… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: net/rds: Don't sleep inside rds_ib_conn_path_shutdown New rds rdma self tests exposed a hang when tearing down the ib network configs. This is caused by the shutdown worker thread sleeping on the wait_event call, which blocks other work items in the… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: affs: handle set_blocksize failures affs uses buffer_heads, which don't handle block size > PAGE_SIZE well. Without this, mounting we will hit the in folio_set_bh on the first __bread_gfp call. | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: bfs: handle set_blocksize failures bfs uses buffer_heads, which don't handle block size > PAGE_SIZE well. Without this, mounting will hit the in folio_set_bh on the first __bread_gfp call. | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: qnx4: handle set_blocksize failures qnx4 uses buffer_heads, which don't handle block size > PAGE_SIZE well. Without this, mounting will hit the in folio_set_bh on the first __bread_gfp call. | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: jfs: handle set_blocksize failures jfs uses buffer_heads, which don't handle block size > PAGE_SIZE well. Without this, mounting we will hit the in folio_set_bh on the first __bread_gfp call. | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: hpfs: handle set_blocksize failures hpfs uses buffer_heads, which don't handle block size > PAGE_SIZE well. Without this, mounting will hit the in folio_set_bh on the first __bread_gfp call. | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: omfs: handle set_blocksize failures omfs uses buffer_heads, which don't handle block size > PAGE_SIZE well. Without this, mounting we will hit the in folio_set_bh on the first __bread_gfp call. | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: usbip: vhci_hcd: fix NULL deref in status_show_vhci platform_get_drvdata() can return NULL if a VHCI host controller's probe failed (e.g. due to USB bus number exhaustion). status_show_vhci() checked for a NULL pdev but not for a NULL hcd returned by… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: core: hcd: fix possible deadlock in rh control transfers >From within the SCSI error handler memory allocations must not trigger IO. Handling errors in UAS and the storage driver may involve resetting a device. The thread doing the reset itself… |