Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
20.828 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: add a check on the tid coming from the firmware ba_notif->tid is a firmware-controlled u8 that is used directly as an array index into tid_data[] without any validation. Add a bounds check against IWL_MAX_TID_COUNT before… | |
| Recibida | Alta (8.8) | 0.24% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif mvmsta->tid_data was indexed by the TFD loop counter 'i' instead of the actual TID value 'tid'. This writes lq_color into a random tid_data slot unrelated to the BA entry. Since… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: bound aligned TLV advance in FW parser Validate ALIGN(tlv_len, 4) against remaining parser length before consuming bytes from the firmware image. This avoids length underflow on malformed TLVs. | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: acpi: validate WGDS table revision index Check tbl_rev bounds before BIT(tbl_rev) to avoid undefined shifts when firmware reports an invalid revision value. | |
| Recibida | Alta (8.1) | 0.34% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: bound dirent name against end of SMB response in cifs_filldir cifs_filldir() copies the entry name out of an SMB1 TRANS2_FIND_FIRST / FIND_NEXT response using a length (de.namelen) supplied by the server. The kmalloc'd SMB response buffer… | |
| Recibida | Alta (8.1) | 0.34% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: preserve VFS inherited POSIX ACL mask The VFS initializes a child's POSIX ACL from the parent's default ACL and the requested creation mode. Do not mutate the parent ACL or overwrite the child's VFS-computed access and default ACLs afterwards.… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: cifs: validate idmap key payload length The cifs.idmap key type stores its payload length in key->datalen, which is limited to U16_MAX. Accepting a larger key payload truncates the recorded length and can make later users interpret the payload using… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie() The KASAN allocation trace shows that a malformed IE buffer is stored via SIOCSIWGENIE (cfg80211_wext_siwgenie()) without any validation. The crash trace shows that a subsequent SIOCSIWESSID… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame rfcomm_recv_frame() casts skb->data to struct rfcomm_hdr and dereferences hdr->addr and hdr->ctrl without validating skb->len first. A truncated frame with skb->len less than the minimum… | |
| Recibida | Alta (7.8) | 0.12% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: flush backend after device ioctls vhost-scsi translates guest response descriptors into userspace iovecs when commands are submitted. Target-core completes those commands asynchronously, so VHOST_SET_MEM_TABLE can replace the memory table… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: core: Do not block on tag allocation in scsi_eh_lock_door() scsi_eh_lock_door() is called from scsi_restart_operations() while the host is still in the SHOST_RECOVERY state, i.e. before the host is switched back to SHOST_RUNNING and… | |
| Recibida | Alta (7.8) | 0.13% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state sashiko reports: "nfnl_log_net_exit() calls nf_log_unset(), which clears the logger pointer without an RCU grace period. Immediately after, ops_free_list() frees the… | |
| Recibida | Alta (7.8) | 0.13% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: i2c: smbus: reject oversized block transfers in the common path The SMBus block transfer length data->block[0] is validated in i2c_smbus_xfer_emulated() but that check runs too late for tracepoints and is skipped entirely when the adapter provides a… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: net: appletalk: fix NULL pointer dereference in aarp_send_ddp() aarp_send_ddp() calls atalk_find_dev_addr(dev) in the LocalTalk fast path without checking for NULL. When the device has no AppleTalk interface configured (dev->atalk_ptr == NULL), this… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: f2fs: embed f2fs_gc_kthread in f2fs_sb_info Instead of allocating f2fs_gc_kthread dynamically, embed it in f2fs_sb_info. This simplifies lifetime management and prepares for fixing race conditions during teardown. - __sbi_store - remount|shutdown -… | |
| Recibida | Alta (8.8) | 0.13% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: dma-unmap pages before handling migration errors drm_pagemap_migrate_unmap_pages() relies on the pages array to determine which pages require DMA unmapping. However, drm_pagemap_migration_unlock_put_pages() clears the array as part of its… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix device_register() error path When device_register() fails in i3c_master_register_new_i3c_devs(), put_device() is called to drop the reference taken by device_register(). That drops the last reference, so the device's release callback… | |
| Recibida | Alta (8.1) | 0.31% | — | Linux KernelAI | 24/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL permission check looks for an ACE matching the current user and falls back to the Everyone ACE. It does not consider an Authenticated Users ACE, even though an authenticated session is a member of that… | |
| Recibida | Sin puntuar | 0.19% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix HE extended capability length check rtw89_mac_check_he_obss_narrow_bw_ru_iter() reads extended capability byte 10, but rejects only datalen values below 10. Byte 10 requires at least 11 bytes. Require datalen >= 11 before reading… | |
| Recibida | Alta (8.8) | 0.32% | — | Linux KernelAI | 24/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: greybus: audio: bound the topology section sizes against the fetched size gb_audio_gb_get_topology() fetches a topology blob of a module-supplied size, and gbaudio_tplg_parse_data() then walks it by adding the module-supplied size_dais, size_controls… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown The TX cleanup tasklet can be scheduled by the watchdog IRQ handler to execute cvm_oct_tx_do_cleanup. There can be a pending tasklet in the queue which might run after the… | |
| Recibida | Sin puntuar | 0.19% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown cvm_oct_rx_shutdown calls free_irq and netif_napi_del without disabling the napi instance first. As the free_irq only waits for completion of hard interrupt handlers, the napi poll… | |
| Recibida | Alta (7.8) | 0.14% | — | Linux KernelAI | 24/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Validate udata before executing commands The destroy callbacks currently zero the udata output after tearing down driver resources. If the userspace access fails, uverbs preserves the uobject and allows the destroy callback to run again,… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator devm_regulator_get_exclusive() initialises the regulator with enable_count = 1, requiring the consumer to disable it before release. The devm disable action was… | |
| Recibida | Sin puntuar | 0.19% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/pt: Fix stop/start with no update If pt_event_stop() is called without PERF_EF_UPDATE flag, then perf_aux_output_end() is not called. A subsequent call to pt_event_start() will call perf_aux_output_begin() again which violates the rule… |