Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
20.827 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: null_blk: reject per-device queue resize for shared tag set When shared_tags is enabled, null_setup_tagset() makes the device use the global tag_set, whose driver_data stays NULL. null_map_queues() therefore falls back to the module-wide… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: null_blk: serialize configfs attribute stores with the lock The NULLB_DEVICE_ATTR _store takes no lock: apply_fn attributes (submit_queues, poll_queues) get dev->NAME written again after apply_fn returns, outside its lock; APPLY=NULL attributes are… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: null_blk: serialize configfs attribute updates with device setup The attribute store methods generated with NULLB_DEVICE_ATTR() refuse to change the configuration of a live device by testing NULLB_DEV_FL_CONFIGURED, but that flag is only set by… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: blk-iolatency: clear delay state when freeing policy data io.latency can throttle a group which has no latency target of its own. When a sibling misses its target, check_scale_change() scales down its peers, and a peer that reaches queue depth one… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: blk-iocost: clear delay state when freeing policy data iocg_kick_delay() turns sufficiently large debt into an explicit block-cgroup delay with blkcg_set_delay(), setting blkg->use_delay to -1 and incrementing blkcg->congestion_count. Clearing it… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ublk: avoid teardown retry loop on xarray allocation failure __ublk_shmem_remove_ranges() removes matching maple tree ranges in batches, but first stores each range into a temporary xarray so that the pages can be unpinned after dropping the maple… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: block: mtip32xx: synchronize ioctls with device removal The ioctl handlers only test REMOVE_PENDING before entering mtip_hw_ioctl(). Removal can set that bit immediately afterwards and free dd->port in mtip_hw_exit() while an ioctl still dereferences… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix deadlock in complain-mode change_hat The use of change_hat when in complain mode can cause a deadlock when the hat doesn't exist and a new learning profile is created for the missing profile. This is because change_hat() has taken the… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix core_data leak on CPUs without PTS pdata->core_data is allocated in init_temp_data() when the first core temp_data of a package is created, but it is only released from destroy_temp_data(), and only in the branch that handles the… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer Free it unconditionally after ksmbd_alloc_user() calls. | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: release pending child sockets outside the handler lock smbdirect_socket_destroy() releases the listener's pending/ready child sockets while still holding the listener's handler lock, the &id_priv->handler_mutex taken via… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ipc response length before dereferencing its fields ipc_validate_msg() computes the expected message size by reading length fields out of the response buffer supplied by the userspace ksmbd daemon (payload_sz, session_key_len, ngroups,… | |
| Recibida | Sin puntuar | 0.24% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: free preauth sessions on connection teardown SMB3.1.1 multichannel binding preserves the preauthentication hash in a preauth_session between the NTLM negotiate and authenticate requests. The binding NTLM negotiate allocates this object and… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize oplock close with pending break ownership close may abort an in-flight oplock break while another breaker already holds an opinfo reference. Releasing pending_break wakes that waiter, but without serializing the close transition with… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request() See the procedure below: | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix invalid pointer dereference in ksmbd_stop_durable_scavenger() See the procedure below: | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: abort initialization when proc setup fails ksmbd_server_init() calls ksmbd_proc_init() before creating the remaining proc entries and server subsystems. ksmbd_proc_init() tears down partial state on a procfs or percpu_counter allocation… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: call ksmbd_proc_cleanup() on module init failure When a later initializer fails, the unwind chain releases resources created after procfs and then jumps directly to class_unregister(). Returning an error from module_init() leaves the proc… | |
| Recibida | Sin puntuar | 0.22% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: lwt_bpf: Restore reserved headroom after xmit program ip_finish_output2() expands an skb to LL_RESERVED_SPACE(dev) before LWT xmit. An LWT_XMIT BPF program can then modify the skb head and still return BPF_OK, so bpf_xmit() rechecks the remaining… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks _bpf_setsockopt() and _bpf_getsockopt() call sock_owned_by_me() for full sockets, so these helpers expect the socket lock to be held. BPF_CGROUP_UNIX_GETPEERNAME and… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: m68k: nfcon: Do not call console_is_registered() in nfcon_device() Since 7c2af0f634f1 ("tty: tty_io: use console_list_lock for list synchronization") show_cons_active() calls the .device() method under the console_list_lock, but… | |
| Recibida | Sin puntuar | 0.22% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative optlen in cgroup getsockopt hook A cgroup getsockopt BPF program can shrink ctx->optlen after the kernel getsockopt handler has run. The kernel-buffer variant, used by TCP_ZEROCOPY_RECEIVE, only rejects values larger than the… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: detach blocked lock requests before freeing A file_lock retained by ksmbd for byte-range lock bookkeeping can still be part of the VFS blocked-request graph. In particular, the VFS can chain a new waiter below an already blocked request through… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope session state changes to bound connections ksmbd_all_conn_set_status() treats every connection whose transient binding flag is set as belonging to the target SessionId. A logoff or session replacement can consequently move an unrelated… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix session leak in ksmbd_session_register() See the procedure below: Remove the session from sessions_table and drop its table reference if xa_store() fails. |