Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
10.164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.32% | — | Linux KernelDebian Linux | 1/10/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm When send a broadcast packet to a tap device, which was added to a bridge, br_nf_local_in() is called to confirm the conntrack. If another conntrack with the same… | |
| Analizada | Alta (7.1) | 0.16% | — | Linux KernelDebian Linux | 1/10/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Initialize the chan_stats array to zero The adapter->chan_stats[] array is initialized in mwifiex_init_channel_scan_gap() with vmalloc(), which doesn't zero out memory. The array is filled in mwifiex_update_chan_statistics() and then… | |
| Analizada | Alta (7.8) | 8.4% | ⚠ Explotación activa | Vmware Aria OperationsVmware Cloud FoundationVmware Cloud Foundation OperationsVmware Open VM Tools+4 | 29/9/2025 | 17/6/2026 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the… | |
| Analizada | Media (5.5) | 0.12% | — | Linux KernelDebian Linux | 23/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix recursive semaphore deadlock in fiemap call syzbot detected a OCFS2 hang due to a recursive semaphore on a FS_IOC_FIEMAP of the extent list on a specially crafted mmap file. ocfs2_fiemap() takes a read lock of the ip_alloc_sem semaphore… | |
| Analizada | Alta (7.1) | 0.15% | — | Linux KernelDebian Linux | 23/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory When I did memory failure tests, below panic occurs: The root cause is that unpoison_memory() tries to check the PG_HWPoison flags of an uninitialized page. So… | |
| Modificada | Alta (7.8) | 0.15% | — | Linux KernelDebian Linux | 23/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: kernfs: Fix UAF in polling when open file is released A use-after-free (UAF) vulnerability was identified in the PSI (Pressure Stall Information) monitoring mechanism: Reproduction Steps: 1. Open test/cpu.pressure and establish epoll monitoring 2.… | |
| Modificada | Alta (7.8) | 0.32% | — | Linux KernelDebian Linux | 23/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: fix invalid accesses to ceph_connection_v1_info There is a place where generic code in messenger.c is reading and another place where it is writing to con->v1 union member without checking that the union member is active (i.e. msgr1 is in… | |
| Analizada | Alta (7.8) | 0.15% | — | Linux KernelDebian Linux | 23/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: fix use-after-free in state_show() state_show() reads kdamond->damon_ctx without holding damon_sysfs_lock. This allows a use-after-free race: CPU 0 CPU 1 ----- ----- state_show() damon_sysfs_turn_damon_on() ctx = kdamond->damon_ctx;… | |
| Analizada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 23/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable() The function of_phy_find_device may return NULL, so we need to take care before dereferencing phy_dev. | |
| Modificada | Alta (7.8) | 0.16% | — | Linux KernelDebian Linux | 23/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: can: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB can_put_echo_skb() takes ownership of the SKB and it may be freed during or after the call. However, xilinx_can xcan_write_frame() keeps using SKB after the call. Fix that by… | |
| Analizada | Alta (7.8) | 0.15% | — | Linux KernelDebian Linux | 23/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix double free in idxd_setup_wqs() The clean up in idxd_setup_wqs() has had a couple bugs because the error handling is a bit subtle. It's simpler to just re-write it in a cleaner way. The issues here are: It's better to free partial… | |
| Modificada | Alta (7.1) | 0.16% | — | Linux KernelDebian Linux | 23/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: edma: Fix memory allocation size for queue_priority_map Fix a critical memory allocation bug in edma_setup_from_hw() where queue_priority_map was allocated with insufficient memory. The code declared queue_priority_map as s8 (*)[2]… | |
| Modificada | Alta (7.8) | 0.31% | — | Linux KernelDebian Linux | 19/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: fs: writeback: fix use-after-free in __mark_inode_dirty() An use-after-free issue occurred when __mark_inode_dirty() get the bdi_writeback that was in the progress of switching. Root cause is: systemd-random-seed kworker… | |
| Modificada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 19/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: tee: fix NULL pointer dereference in tee_shm_put tee_shm_put have NULL pointer dereference: Add check in tee_shm_put to fix it. panic log: Unable to handle kernel paging request at virtual address 0000000000100cca Mem abort info: ESR =… | |
| Modificada | Alta (7.8) | 0.23% | — | Linux KernelDebian Linux | 19/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix use-after-free in cmp_bss() Following bss_free() quirk introduced in commit 776b3580178f ("cfg80211: track hidden SSID networks properly"), adjust cfg80211_update_known_bss() to free the last beacon frame elements only if they're… | |
| Modificada | Alta (7.8) | 0.23% | — | Linux KernelDebian Linux | 19/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() syzbot reported the splat below without a repro. In the splat, a single thread calling bt_accept_dequeue() freed sk and touched it after that. The root cause would be the racy… | |
| Modificada | Media (5.5) | 0.31% | — | Linux KernelDebian Linux | 19/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync() If the software RoCE device is used, ibdev->dma_device is a null pointer. As a result, the problem occurs. Null pointer detection is added to prevent problems. | |
| Modificada | Alta (7.1) | 0.16% | — | Linux KernelDebian Linux | 19/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: i40e: Fix potential invalid access when MAC list is empty list_first_entry() never returns NULL - if the list is empty, it still returns a pointer to an invalid object, leading to potential invalid memory access when dereferenced. Fix this by using… | |
| Modificada | Alta (7.8) | 0.22% | — | Linux KernelDebian Linux | 19/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() If the ssid->datalen is more than IEEE80211_MAX_SSID_LEN (32) it would lead to memory corruption so add some bounds checking. | |
| Modificada | Media (5.5) | 0.24% | — | Linux KernelDebian Linux | 19/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: ax25: properly unshare skbs in ax25_kiss_rcv() skb->dev becomes NULL and we crash in __netif_receive_skb_core(). Before above commit, different kind of bugs or corruptions could happen without a major crash. But the root cause is that ax25_kiss_rcv()… | |
| Modificada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 19/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ppp: fix memory leak in pad_compress_skb If alloc_skb() fails in pad_compress_skb(), it returns NULL without releasing the old skb. The caller does: When pad_compress_skb() returns NULL, the reference to the old skb is lost and kfree_skb(skb) ends up… | |
| Modificada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 19/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region() In __iodyn_find_io_region(), pcmcia_make_resource() is assigned to res and used in pci_bus_alloc_resource(). There is a dereference of res in pci_bus_alloc_resource(), which could lead… | |
| Modificada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 19/9/2025 | 14/7/2026 | In the Linux kernel, the following vulnerability has been resolved: x86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() Define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() to ensure page tables are properly synchronized when calling p*d_populate_kernel(). For 5-level paging,… | |
| Modificada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 19/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mm: move page table sync declarations to linux/pgtable.h During our internal testing, we started observing intermittent boot failures when the machine uses 4-level paging and has a large amount of persistent memory: It turns out that the kernel panics… | |
| Modificada | Media (5.5) | 0.11% | — | Linux KernelDebian Linux | 19/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mm: slub: avoid wake up kswapd in set_track_prepare set_track_prepare() can incur lock recursion. The issue is that it is called from hrtimer_start_range_ns holding the per_cpu(hrtimer_bases)[n].lock, but when enabled CONFIG_DEBUG_OBJECTS_TIMERS, may… |