Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 662 respecto a la semana anterior
Críticas / altas1264▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
21.051 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.4) | 0.14% | — | Linux KernelAI | 24/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: phy: fsl-imx8mq-usb: fix typec switch leak on probe error path If probe fails after imx95_usb_phy_get_tca() succeeds, the typec switch leaks because the only cleanup path was in .remove(), which never runs on probe failure. Use… | |
| Recibida | Alta (8.1) | 0.45% | — | Linux KernelAI | 24/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix unmatched rn_unregister on failed accept When svc_rdma_accept() takes the errout path before rpcrdma_rn_register() has succeeded, the existing cleanup block calls rpcrdma_rn_unregister(dev, &newxprt->sc_rn) unconditionally. svcxprt_rdma… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: staging: media: tegra-video: fix of_node_put() on VIP parse errors tegra_vip_channel_of_parse() initializes np from dev->of_node without taking a reference, but its error paths drop one through the err_node_put label. This underflows the refcount of… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: signal: avoid shared siginfo namespace rewrites send_signal_locked() rewrites sender ids for the target namespace. Group sends reuse the same siginfo, so one recipient can affect the next. Copy the siginfo before changing it. | |
| Recibida | Alta (8.1) | 0.33% | — | Linux KernelAI | 24/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: convert nfsd_net boolean flags to unsigned long flags word nfsd_net contains several boolean fields that are accessed from concurrent contexts without serialization. In particular, nfsd4_end_grace() guards its drain path with a plain bool: The… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Keep kick_sync waiting on the rq's own CPU kick_sync_wait_bal_cb() assumes it runs on the rq's CPU from the __schedule() tail: the snapshots it compares against live in that CPU's percpu area and the busy-wait runs with the rq lock dropped… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/timer-sun4i: Advertise a real minimum delta sun4i_clkevt_next_event() compensates for the timer stop/start synchronization delay by programming evt - TIMER_SYNC_TICKS into the hardware interval register. The clockevent device… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd madvise_free_pte_range() checks pmd_trans_huge(*pmd) unlocked, then madvise_free_huge_pmd() takes pmd_trans_huge_lock(). pmd_is_huge() returns true for a device-private PMD, so orig_pmd… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/madvise: skip device-private PMDs in cold and pageout walks madvise_cold_or_pageout_pte_range() takes pmd_trans_huge_lock(), whose pmd_is_huge() check returns true for a device-private PMD. The subsequent !pmd_present() branch has a VM_BUG_ON()… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg() print_page_owner_memcg() reads page->memcg_data via READ_ONCE() at the start to guard against tail pages and NULL data. However, it later re-reads page->memcg_data… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: cdx: Fix double free when sysfs file creation fails In cdx_create_res_attr(), if sysfs_create_bin_file() fails, the code frees res_attr but doesn't set cdx_dev->res_attr[num] to NULL. This leaves a dangling pointer in the array. Then… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() usbg_make_tpg() held dep_lock while calling configfs_depend_item_unlocked(), which acquires the configfs root inode lock when operating across subsystems. This creates a circular lock dependency with… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: of: fix out-of-bounds read in of_alias_scan() stem parser The stem parser tests isdigit(*(end - 1)) before checking end > start and so reads one byte before the property name when the name is empty or all digits. Check the bound first. | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: guard nfsd_serv deref in nfsd_file_net_dispose nfsd_file_net_dispose() is the consumer side of l->freeme: the nfsd service thread loop calls it to drain entries that the filecache garbage collector and shrinker append via… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize DRC hash table before registering shrinker shrinker_register() precedes the INIT_LIST_HEAD loop and the drc_hashsize store. On weakly-ordered architectures (arm64, ppc), a shrinker scan can observe drc_hashsize before the bucket list… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: harden DFS cache against invalid target hints Currently, get_tgt_name() returns ERR_PTR(-ENOENT) when ce->tgthint is NULL, and dfs_cache_noreq_update_tgthint() assumes ce->tgthint is always valid. In preparation for clearing ce->tgthint… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb BT enable fails intermittently with -ETIMEDOUT (-110). The kernel log shows the HCI Read Local Version command was sent and the firmware replied with status 0x00 (logged by… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 24/9/2026 | In the Linux kernel, the following vulnerability has been resolved: kasan_quarantine_remove_cache() first invokes per_cpu_remove_cache() on all online CPUs. Each callback moves objects belonging to the cache from cpu_quarantine to the CPU's shrink_qlist, where they can later be freed from task context.… | |
| Recibida | Crítica (9.8) | 0.47% | — | Linux KernelAI | 24/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry svcauth_gss_decode_credbody() writes the caller's rpc_gss_wire_cred field by field and assigns gc_ctx.len only on the success tail. The caller storage is svcdata->clcred, which… | |
| Recibida | Sin puntuar | 0.19% | — | Linux KernelAI | 24/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: PCI/proc: Use file_ns_capable() when checking config space read access proc_bus_pci_read() decides how much of the config space is readable based on capable(CAP_SYS_ADMIN), which checks the credentials of the task calling read(), not the credentials… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 24/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: Manage teardown with devm arm_smmu_device_remove() manually frees the IOPF queue, destroys the vmid_map and disables the device, while the IRQs and queues are devm managed. devm unwinds only after remove() returns, so the cleanup… | |
| Rechazada | Sin puntuar | 0.47% | — | Linux KernelAI | 22/9/2026 | 30/9/2026 | Rejected reason: This CVE was reserved in error and duplicates CVE-2026-89530. | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix recursive locking during device registration i3c_master_register_new_i3c_devs() registers newly discovered devices while holding i3c_bus_normaluse_lock(), a down_read(). device_register() can immediately probe the device, and probe… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate the persisted dirty_tail chain at load The writeback worker follows the persisted dirty_tail chain, which is decoded from the cache device independently of the key_tail chain that cache_replay() walks and bounds. A crafted image,… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: memcg: move LRU size accounting on reparenting instead of copying it When a memory cgroup is offlined its LRU folios are reparented to the parent. lruvec_reparent_lru() splices the child's lists into the parent's and credits the parent with the… |