Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
10.007 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.21% | — | Linux KernelDebian Linux | 16/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net: rose: convert 'use' field to refcount_t The 'use' field in struct rose_neigh is used as a reference counter but lacks atomicity. This can lead to race conditions where a rose_neigh structure is freed while still being referenced by other code… | |
| Modificada | Media (4.7) | 0.12% | — | Linux KernelDebian Linux | 16/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix race with concurrent opens in rename(2) Besides sending the rename request to the server, the rename process also involves closing any deferred close, waiting for outstanding I/O to complete as well as marking all existing open… | |
| Modificada | Alta (7.8) | 0.17% | — | Linux KernelDebian Linux | 16/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: HID: asus: fix UAF via HID_CLAIMED_INPUT validation After hid_hw_start() is called hidinput_connect() will eventually be called to set up the device with the input layer since the HID_CONNECT_DEFAULT connect mask is used. During hidinput_connect() all… | |
| Modificada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 16/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: use array_index_nospec with indices that come from guest min and dest_id are guest-controlled indices. Using array_index_nospec() after the bounds checks clamps these values to mitigate speculative execution side-channels. | |
| Modificada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 16/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: fs/smb: Fix inconsistent refcnt update A possible inconsistent update of refcount was identified in `smb2_compound_op`. Such inconsistent update could lead to possible resource leaks. Why it is a possible bug: 1. In the comment section of the… | |
| Modificada | Alta (7.1) | 0.17% | — | Linux KernelDebian Linux | 16/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare Observed on kernel 6.6 (present on master as well): If dentry->d_name.len < EFI_VARIABLE_GUID_LEN , 'guid' can become negative, leadings to oob. The issue can be triggered by parallel lookups… | |
| Modificada | Media (4.7) | 0.12% | — | Linux KernelDebian Linux | 16/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix potential warning in trace_printk_seq during ftrace_dump When calling ftrace_dump_one() concurrently with reading trace_pipe, a WARN_ON_ONCE() in trace_printk_seq() can be triggered due to a race condition. The issue occurs because: CPU0… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 16/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: initialize more fields in sctp_v6_from_sk() syzbot found that sin6_scope_id was not properly initialized, leading to undefined behavior. Clear sin6_scope_id and sin6_flowinfo. | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 16/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() in ntrig_report_version(), hdev parameter passed from hid_probe(). sending descriptor to /dev/uhid can make hdev->dev.parent->parent to null if hdev->dev.parent->parent is null,… | |
| Modificada | Alta (7.1) | 0.24% | — | Linux KernelDebian Linux | 16/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: fix slab out-of-bounds access in mt_report_fixup() A malicious HID device can trigger a slab out-of-bounds during mt_report_fixup() by passing in report descriptor smaller than 607 bytes. mt_report_fixup() attempts to patch byte… | |
| Analizada | Alta (7.1) | 0.15% | — | Linux KernelDebian Linux | 15/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: VMCI: check context->notify_page after call to get_user_pages_fast() to avoid GPF The call to get_user_pages_fast() in vmci_host_setup_notify() can return NULL context->notify_page causing a GPF. To avoid GPF check if context->notify_page == NULL and… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 15/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value The return value of acpi_fetch_acpi_dev() could be NULL, which would cause a NULL pointer dereference to occur in acpi_device_hid(). [ rjw: Subject and changelog edits, added empty line… | |
| Modificada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 15/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Remove WARN_ON for device endpoint command timeouts This commit addresses a rarely observed endpoint command timeout which causes kernel panic due to warn when 'panic_on_warn' is enabled and unnecessary call trace prints when… | |
| Modificada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 15/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: abort transaction on unexpected eb generation at btrfs_copy_root() If we find an unexpected generation for the extent buffer we are cloning at btrfs_copy_root(), we just WARN_ON() and don't error out and abort the transaction, meaning we allow… | |
| Modificada | Media (5.5) | 0.28% | — | Linux KernelDebian Linux | 12/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: NFS: Fix the setting of capabilities when automounting a new filesystem Capabilities cannot be inherited when we cross into a new filesystem. They need to be reset to the minimal defaults, and then probed for again. | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 12/9/2025 | 14/7/2026 | In the Linux kernel, the following vulnerability has been resolved: block: avoid possible overflow for chunk_sectors check in blk_stack_limits() In blk_stack_limits(), we check that the t->chunk_sectors value is a multiple of the t->physical_block_size value. However, by finding the chunk_sectors value in bytes, we… | |
| Modificada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 12/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ARM: tegra: Use I/O memcpy to write to IRAM | |
| Modificada | Alta (7.5) | 1.4% | — | Haxx CurlDebian Linux | 12/9/2025 | 14/9/2026 | 1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with only a slash as path (`path="/"`). Since this site is not secure,… | |
| Modificada | Media (5.5) | 0.35% | — | Linux KernelDebian Linux | 11/9/2025 | 14/7/2026 | In the Linux kernel, the following vulnerability has been resolved: x86/vmscape: Add conditional IBPB mitigation VMSCAPE is a vulnerability that exploits insufficient branch predictor isolation between a guest and a userspace hypervisor (like QEMU). Existing mitigations already protect kernel/KVM from a malicious… | |
| Modificada | Alta (7.8) | 0.16% | — | Linux KernelDebian Linux | 11/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Detect events pointing to unexpected TREs When a remote device sends a completion event to the host, it contains a pointer to the consumed TRE. The host uses this pointer to process all of the TREs between it and the host's local copy… | |
| Modificada | Alta (7.8) | 0.17% | — | Linux KernelDebian Linux | 11/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE On Google gs101, the number of UTP transfer request slots (nutrs) is 32, and in this case the driver ends up programming the UTRL_NEXUS_TYPE incorrectly as 0. This is because the left hand side… | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 11/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: soc: qcom: mdt_loader: Ensure we don't read past the ELF header When the MDT loader is used in remoteproc, the ELF header is sanitized beforehand, but that's not necessary the case for other clients. Validate the size of the firmware buffer to ensure… | |
| Modificada | Alta (7.8) | 0.17% | — | Linux KernelDebian Linux | 11/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Fix configfs group list head handling Doing a list_del() on the epf_group field of struct pci_epf_driver in pci_epf_remove_cfs() is not correct as this field is a list head, not a list entry. This list_del() call triggers a KASAN… | |
| Modificada | Media (5.5) | 0.13% | — | Linux KernelDebian Linux | 11/9/2025 | 14/7/2026 | In the Linux kernel, the following vulnerability has been resolved: jbd2: prevent softlockup in jbd2_log_do_checkpoint() Both jbd2_log_do_checkpoint() and jbd2_journal_shrink_checkpoint_list() periodically release j_list_lock after processing a batch of buffers to avoid long hold times on the j_list_lock. However,… | |
| Modificada | Alta (7.8) | 0.15% | — | Linux KernelDebian Linux | 11/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/debug_vm_pgtable: clear page table entries at destroy_args() The mm/debug_vm_pagetable test allocates manually page table entries for the tests it runs, using also its manually allocated mm_struct. That in itself is ok, but when it exits, at… |