Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
10.007 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.12% | — | Linux KernelDebian Linux | 11/9/2025 | 14/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix soft lockup in br_multicast_query_expired() When set multicast_query_interval to a large value, the local variable 'time' in br_multicast_send_query() may overflow. If the time is smaller than jiffies, the timer will expire… | |
| Modificada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 11/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/hisilicon/hibmc: fix the hibmc loaded failed bug When hibmc loaded failed, the driver use hibmc_unload to free the resource, but the mutexes in mode.config are not init, which will access an NULL pointer. Just change goto statement to return,… | |
| Modificada | Media (5.5) | 0.37% | — | Linux KernelDebian Linux | 11/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM When performing Generic Segmentation Offload (GSO) on an IPv6 packet that contains extension headers, the kernel incorrectly requests checksum offload if the egress device only… | |
| Modificada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 11/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit The following setup can trigger a WARNING in htb_activate due to the condition: !cl->leaf.q->q.qlen tc qdisc del dev lo root tc qdisc add dev lo root handle 1: htb default 1 tc… | |
| Modificada | Alta (7.1) | 0.18% | — | Linux KernelDebian Linux | 11/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: core: config: Prevent OOB read in SS endpoint companion parsing usb_parse_ss_endpoint_companion() checks descriptor type before length, enabling a potentially odd read outside of the buffer size. Fix this up by checking the size first before… | |
| Modificada | Alta (7) | 0.12% | — | Linux KernelDebian Linux | 11/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix race between quota disable and quota rescan ioctl There's a race between a task disabling quotas and another running the rescan ioctl that can result in a use-after-free of qgroup records from the fs_info->qgroup_tree rbtree. This… | |
| Modificada | Alta (7.1) | 0.18% | — | Linux KernelDebian Linux | 11/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 cluster segment descriptors UAC3 class segment descriptors need to be verified whether their sizes match with the declared lengths and whether they fit with the allocated buffer sizes, too. Otherwise malicious firmware… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 11/9/2025 | 14/7/2026 | In the Linux kernel, the following vulnerability has been resolved: fs: Prevent file descriptor table allocations exceeding INT_MAX When sysctl_nr_open is set to a very high value (for example, 1073741816 as set by systemd), processes attempting to use file descriptors near the limit can trigger massive memory… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 11/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ARM: rockchip: fix kernel hang during smp initialization In order to bring up secondary CPUs main CPU write trampoline code to SRAM. The trampoline code is written while secondary CPUs are powered on (at least that true for RK3188 CPU). Sometimes that… | |
| Modificada | Alta (7) | 0.17% | — | Linux KernelDebian Linux | 11/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: rcu: Protect ->defer_qs_iw_pending from data race On kernels built with CONFIG_IRQ_WORK=y, when rcu_read_unlock() is invoked within an interrupts-disabled region of code [1], it will invoke rcu_read_unlock_special(), which uses an irq-work handler to… | |
| Modificada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 11/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: jfs: truncate good inode pages when hard link is 0 The fileset value of the inode copy from the disk by the reproducer is AGGR_RESERVED_I. When executing evict, its hard link number is 0, so its inode pages are not truncated. This causes the bugon to… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 11/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() The function divides number of online CPUs by num_core_siblings, and later checks the divider by zero. This implies a possibility to get and divide-by-zero runtime error. Fix it by… | |
| Modificada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 11/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: do not allow relocation of partially dropped subvolumes [BUG] There is an internal report that balance triggered transaction abort, with the following call trace: And btrfs check doesn't report anything wrong related to the extent tree. [CAUSE]… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 11/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup() A soft lockup warning was observed on a relative small system x86-64 system with 16 GB of memory when running a debug kernel with kmemleak enabled. The test system was running a workload with… | |
| Modificada | Media (5.5) | 0.13% | — | Linux KernelDebian Linux | 11/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock When netpoll is enabled, calling pr_warn_once() while holding kmemleak_lock in mem_pool_alloc() can cause a deadlock due to lock inversion with the netconsole subsystem. This occurs… | |
| Analizada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 7/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: Revert "fs/ntfs3: Replace inode_trylock with inode_lock" This reverts commit 69505fe98f198ee813898cbcaf6770949636430b. Initially, conditional lock acquisition was removed to fix an xfstest bug that was observed during internal testing. The deadlock… | |
| Analizada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 7/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: f2fs: vm_unmap_ram() may be called from an invalid context When testing F2FS with xfstests using UFS backed virtual disks the kernel complains sometimes that f2fs_release_decomp_mem() calls vm_unmap_ram() from an invalid context. Example trace from… | |
| Analizada | Alta (7.8) | 0.20% | — | Linux KernelDebian Linux | 7/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() The function needs to check the minimal filehandle length before it can access the embedded filehandle. | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 5/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: serial: 8250: fix panic due to PSLVERR When the PSLVERR_RESP_EN parameter is set to 1, the device generates an error response if an attempt is made to read an empty RBR (Receive Buffer Register) while the FIFO is enabled. In serial8250_do_startup(),… | |
| Modificada | Alta (7.1) | 0.15% | — | Linux KernelDebian Linux | 5/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: iio: imu: bno055: fix OOB access of hw_xlate array Fix a potential out-of-bounds array access of the hw_xlate array in bno055.c. In bno055_get_regmask(), hw_xlate was iterated over the length of the vals array instead of the length of the hw_xlate… | |
| Modificada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 5/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Validate length in packet header before skb_put() When receiving a vsock packet in the guest, only the virtqueue buffer size is validated prior to virtio_vsock_skb_rx_put(). Unfortunately, virtio_vsock_skb_rx_put() uses the length from… | |
| Modificada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 5/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: parisc: Revise __get_user() to probe user read access Because of the way read access support is implemented, read access interruptions are only triggered at privilege levels 2 and 3. The kernel executes at privilege level 0, so __get_user() never… | |
| Modificada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 5/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: parisc: Revise gateway LWS calls to probe user read access We use load and stbys,e instructions to trigger memory reference interruptions without writing to memory. Because of the way read access support is implemented, read access interruptions are… | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 5/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: media: usbtv: Lock resolution while streaming When an program is streaming (ffplay) and another program (qv4l2) changes the TV standard from NTSC to PAL, the kernel crashes due to trying to copy to unmapped memory. Changing from NTSC to PAL increases… | |
| Modificada | Media (4.7) | 0.14% | — | Linux KernelDebian Linux | 5/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() In the interrupt handler rain_interrupt(), the buffer full check on rain->buf_len is performed before acquiring rain->buf_lock. This creates a Time-of-Check to Time-of-Use (TOCTOU)… |