Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 350 respecto a la semana anterior
Críticas / altas1260▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
20.828 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: always wait for ordered extents to avoid OE races [BUG] Syzbot reported a bug that there can be conflicting OEs for the same range: [CAUSE] Since commit ff66fe666233 ("btrfs: fix incorrect buffered IO fallback for append direct writes"), if the… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: check if root is readonly when setting posix acl For a filesystem which has btrfs read-only property set to true, all write operations including acl and xattr should be denied. However, acl can still be set even if btrfs ro property is true.… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: retry verity reads for not-uptodate Merkle folios btrfs_read_merkle_tree_page() can find a folio in the mapping that is not uptodate. After taking the folio lock, the current code treats that state as a read error and returns -EIO. That can… | |
| Recibida | Sin puntuar | 0.22% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: flush active metadata block group at btree_writepages() start btree_writepages() writes the btree inode's dirty metadata in ascending logical address order. On a zoned filesystem only one metadata and one system block group is active for… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data() In that function, we round down the start position and round up the ending position. But during the calculation of @len, we use "round_up(start + len, sectorsize)", which is… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: airoha: add missed IRQ resource helpers Without hooking .irq_request_resources, gpiolib cannot set GPIOD_FLAG_USED_AS_IRQ. This breaks pin direction locking and can allow userspace or another driver to reconfigure an active IRQ pin as an… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: avoid OOB read of build info string The virtbt_setup_zephyr() sends the Zephyr vendor command 0xfc08 (Read Build Information) and hands the response to bt_dev_info() and hci_set_fw_info() as a "%s" string starting at skb->data +… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths adv_timeout_expire() hands a kmalloc()ed instance byte to hci_cmd_sync_queue() with a NULL destroy callback, and only adv_timeout_expire_sync() frees it. That leaks on… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: free the mesh send cancel command when it is cancelled mesh_send_cancel() queues the pending command with a NULL destroy callback, so it is only freed if send_cancel() runs. A cancelled entry is leaked, as _hci_cmd_sync_cancel_entry()… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: free the HCI command when it is cancelled mgmt_hci_cmd_sync() queues the pending command with a NULL destroy callback, so it is only freed if send_hci_cmd_sync() runs. A cancelled entry is leaked, as _hci_cmd_sync_cancel_entry() does… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MSFT: validate evt_prefix_len against the response length read_supported_features() only checks that the response covers the fixed part of struct msft_rp_read_supported_features, which is 11 bytes: evt_prefix[] is a flexible array member… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf, cgroup: Fix storage null-ptr-deref after replacing prog Syzkaller reported a storage null-ptr-deref issue after replacing prog. This occurs in the following scenario: 1. prog A, an empty prog, is attached to a cgrp. 2. prog B uses… | |
| Recibida | Sin puntuar | 0.22% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes The IIO core does not filter duplicate writes to the event enable attribute, so writing the same value twice invokes write_event_config() twice. Enabling twice leaks a runtime PM… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: fix teardown of an adopted proto on insert-race loss In tc_new_tfilter() the create branch sets tp_created = 1 before calling tcf_chain_tp_insert_unique(). When the caller loses the race (another request inserted a proto at the… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix mmap_lock leak in irq_work path stack_map_get_build_id_offset() introduced a per-CPU irq_work to defer mmap_read_unlock() from NMI context, and bpf_find_vma() later reused the same mmap_unlock_work. Both callers only check whether the work is… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: fbdev: kyro: Validate overlay viewport coordinates The overlay viewport end coordinates are computed from the viewport origin and dimensions using 32-bit unsigned arithmetic. Large input values can cause these calculations to wrap around before the… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix iopf_refcount leak on RID domain replacement intel_iommu_attach_device() enables IOPF for the new domain but never disables it for the old one. device_block_translation(), called at the start of the function, tears down translation but… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: media: amd: isp4: release partial allocations in isp4if_alloc_fw_gpumem() isp4if_alloc_fw_gpumem() allocates several GPU memory pools in sequence. If one of them fails, it jumps to error_no_memory and returns -ENOMEM without releasing the pools that… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: media: amd: isp4: fix self-deadlock in isp4sd_pwron_and_init() error path isp4sd_pwron_and_init() holds ops_mutex via guard(mutex) and, on any init failure, jumps to err_deinit and calls isp4sd_pwroff_and_deinit(). That helper takes the same… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Release the export reference when reaping open stateids nfs4_put_stid() releases the svc_export tracked in nfs4_stid.sc_export, but free_ol_stateid_reaplist() frees open and lock stateids by calling ->sc_free() directly, bypassing that path. An… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: nvme-pci: release descriptor pools on probe failure The per-NUMA-node descriptor DMA pools are created lazily from nvme_init_hctx_common() once the admin tag set is allocated, but they are only destroyed in nvme_remove() via… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: amt: Don't support cross-netns setup. When a lower device is unregistered, amt_device_event() tries to unregister its upper AMT device, but it has two problems. If AMT device is created on a lower device in another netns, removing the lower device… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: avoid userspace overflow on invalid optlen nfc_llcp_getsockopt() casts optval to (u32 __user *) for put_user(), so the kernel always stores 4 bytes regardless of the caller-supplied optlen. The existing min_t(u32, len, sizeof(u32)) only… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: hold a reference to the request skb during send_frame __pn533_send_async() publishes the command and then calls dev->phy_ops->send_frame(). Once dev->cmd is set, an incoming frame can be matched to this command: the I2C threaded IRQ runs… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() parse the CORE_INIT_RSP packet without validating that the skb contains enough data. A malformed response (e.g. injected… |