Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
30.451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: ibss: ref BSS entry for joined event When the IBSS is joined, we only record the BSSID/channel in the event and look up the BSS entry when processing it. However, that's racy, e.g. a new scan with NL80211_SCAN_FLAG_FLUSH can remove it,… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't start a ROC while scanning The ROC work can be pending when a scan starts (which requires ROC list to be empty, but that's possible), and then a new ROC can be added to the list and the work will pick it up. Avoid starting that… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't offload TC setup on AP_VLAN interfaces AP_VLAN interfaces are purely virtual, so don't try to offload TC setup to drivers. We can't really use the AP interface either since we may not know it all the time, and it could… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: abort chanswitch when leaving a mesh The code in ieee80211_stop_mesh() leaves CSA active, but leaving the mesh released the channel context, so the CSA finalize work crashes: Abort the channel switch properly. | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: reset state when starting AP fails ieee80211_start_ap() can set enable_beacon (and beacon_int) and fail later, leaving it set forever. Scanning can then attempt to restore beaconing on such an interface, leading to: in hwsim. Also,… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: reset the LED state when ifup fails When the first interface comes up, the radio LED is turned on. This can start the TPT trigger timer, which continues running. But if bringing up the interface fails then the timer keeps running and… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: only operate on TDLS peers in the TDLS code ieee80211_tdls_oper() can operate on the AP station, which then yields various warnings when the AP station is removed then or at a later point in time after being confused for a TDLS peer.… | |
| Recibida | Alta (7) | 0.13% | — | Linux KernelAI | 6/10/2026 | 7/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: unlist vifs when their netdev is unregistered mac80211 only removes vifs from the local->interfaces list when an interface is removed via ieee80211_if_remove(), before it unregisters the netdev. However, it's possible for a netdev to… | |
| Recibida | Alta (7) | 0.13% | — | Linux KernelAI | 6/10/2026 | 7/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: get the wiphy out of a dying network namespace When a network namespace is destroyed, cfg80211_pernet_exit() moves any wiphy back to the initial namespace, and just warns if that fails. But moving an interface can fail (due to… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't allow injecting frames wider than the chanctx Frames injected on a monitor interface can carry a radiotap field requesting a bandwidth, which mac80211 passes down to the driver regardless of the the actual operational bandwidth.… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: add HE 6 GHz capability in the scan elems len The HE 6 GHz Band Capability element is in the probe request for every band if 6 GHz is supported, so add the size to scan_ies_len. Otherwise, building probe request elements can fail,… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: mesh: reset the CSA state when leaving ifmsh->csa is allocated in ieee80211_mesh_csa_beacon() and only freed in ieee80211_mesh_finish_csa(), i.e. when the channel switch completes. Leaving the mesh while a switch is still pending… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: mesh: release the channel if start fails ieee80211_join_mesh() acquires a channel context and then calls ieee80211_start_mesh(), which can fail. In that case, the chanctx isn't released then interface removal will attempt to unassign… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: set up the TX info early to fix failure paths The previous commit 2c51457d930f ("wifi: mac80211: free ack status frame on TX header build failure") cleaned up the leak, but still left the code a bit messy and the failed SKB didn't get… | |
| Recibida | Alta (7.8) | 0.13% | — | Linux KernelAI | 6/10/2026 | 7/10/2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: pxa: fix double counting of the hw descriptors pxad_alloc_desc() was converted from to kzalloc_flex(), which sets the __counted_by() counter sw_desc->nb_desc itself - but only where the compiler has __builtin_counted_by_ref(), so from gcc… | |
| Recibida | Crítica (9.8) | 0.56% | — | Linux KernelAI | 6/10/2026 | 7/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Bound fragmented header copies by the remaining length siw_get_hdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_nat: fully initialise new_addr in netmap setup nft_nat_setup_netmap() builds the mapped address in an on-stack union nf_inet_addr. For an IPv4 mapping it writes only the 4-byte .ip member and the loop runs a single 32-bit iteration, but… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat: unregister and release hooks on error If nf_hook_entries_insert_raw() fails, the NAT hooks get never released, resulting in a memleak. Postpone setting nat_proto_net->nat_hook_ops when the hooks are registered to simplify the error… | |
| Recibida | Alta (7.8) | 0.14% | — | Linux KernelAI | 6/10/2026 | 7/10/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: hold reference on ct until flow is released nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe semantics also allow to refer to the wrong conntrack from the flowtable datapath. Hold reference on ct until flow is… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr When an out_fence_ptr is provided but DRM_MODE_PAGE_FLIP_EVENT is not set, a drm_pending_vblank_event will be allocated. If later, there is an allocation failure or another failure… | |
| Recibida | Alta (7.8) | 0.13% | — | Linux KernelAI | 6/10/2026 | 7/10/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: validate absolute native symlink targets before NT fixups With symlinkroot unset, an absolute target is copied without conversion to an NT drive path. Later code still assumes an NT prefix is present when modifying the target and… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS. NDTPA_INTERVAL_PROBE_TIME_MS sets .type and .min but misses .validation_type, so no validation is applied: Moreover, nla_get_msecs() uses msecs_to_jiffies(), and u64 is silently cast to u32,… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: bcd2000: Fix race between rawmidi and disconnect Although we tried to fix the potential UAF issues at USB disconnect on bcd2000 driver, there is still an overlooked case -- namely, when a rawmidi trigger callback has been already running at USB… | |
| Recibida | Alta (7.8) | 0.13% | — | Linux KernelAI | 6/10/2026 | 7/10/2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: protect runlist updates with the runlist lock ntfs_non_resident_attr_shrink() calls runlist helpers that require the runlist write lock, but did not hold it while freeing clusters and truncating the runlist. Serialize those operations and the… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: set timer->private_data before registering the PCM timer snd_pcm_timer_init() calls snd_device_register() to link the new struct snd_timer into the global timer list while it still carries hw.c_resolution = snd_pcm_timer_resolution (and… |