Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 216 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
20.827 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix use-after-free of master->this sysfs attribute callbacks for the master controller device dereference master->this. However, master->this is freed in i3c_master_detach_free_devs() before the master device itself is released. As a… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 17/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: Do not treat master device as a duplicate target i3c_master_search_i3c_dev_duplicate() searches the bus for another I3C device with the same PID as the reference device. The search can match master->this, causing the controller itself to… | |
| Recibida | Alta (8.4) | 0.19% | — | Linux KernelAI | 17/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: nvdimm: virtio_pmem: refcount requests for token lifetime virtio_pmem_host_ack() wakes a request that has already been freed by the submitter. This happens when the request token is still reachable via the virtqueue, but virtio_pmem_flush() returns… | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Clear queue->active_job when v3d_fence_create() fails The run_job() callbacks for BIN, RENDER, TFU and CSD assign the incoming job to queue->active_job before calling v3d_fence_create(). If v3d_fence_create() fails, the callback returns NULL… | |
| Recibida | Alta (8.4) | 0.20% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count cros_typec_register_partner_pdos() copies the partner PDOs from the EC TYPEC_STATUS response into the fixed caps_desc.pdo[PDO_MAX_OBJECTS] array. PDO_MAX_OBJECTS is 7. source_cap_count… | |
| Recibida | Alta (8.8) | 0.40% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: HID: core: quiesce input in hid_hw_stop() to prevent use-after-free A driver's probe calls hid_device_io_start() to enable input delivery, then fails at a later initialization step and unwinds via hid_hw_stop(). The unwind frees struct hidraw via… | |
| Recibida | Alta (7.1) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup vddInd and vddcInd fields from VBIOS-parsed tables are used to index into voltage lookup tables without a bounds check. Return -EINVAL when any index is out of range. | |
| Recibida | Alta (7.3) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup vddInd, vddciInd and mvddInd from VBIOS-parsed tables index into vddc, vddci and vddmem lookup tables without bounds checks across nine sites. Return -EINVAL when any index is out of… | |
| Recibida | Alta (7) | 0.14% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dangling pointer in plane reset function amdgpu_dm_plane_drm_plane_reset() frees the old state before allocating a new one. If kzalloc() fails, the function returns without updating the state pointer, leaving a dangling pointer to… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dangling pointer in CRTC reset function amdgpu_dm_crtc_reset_state() frees the old state before allocating a new one. If kzalloc() fails, the function returns without updating the state pointer, leaving a dangling pointer to… | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers Fix a race condition in AXIDMA and MCDMA irq handlers where the channel could be incorrectly marked as idle and attempt spurious transfers when descriptors… | |
| Recibida | Alta (7.7) | 0.19% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: platform/chrome: sensorhub: Fix memory overread in ring handler `max_response` and `sensor_num` are read from different EC commands: With a malfunctioning EC firmware, it is possible that the `msg->insize` (i.e., `fifo_info_length` in the context)… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Add refcounting to user ring MRs Prevent userspace from deregistering the MRs that back QP/CQ/SRQ rings by bumping the MR's refcount upon association. | |
| Recibida | Alta (7.5) | 0.70% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: fix response resource leak on queue teardown When an nvme target with rdma transport is removed while I/Os are in flight, a response can be posted but its send completion is never delivered before the connection is torn down. As a result… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject MEM_ALLOC BTF accesses past object bounds BTF struct walks relax the struct-size check for accesses through a trailing flexible array. That is valid for ordinary BTF type walking, but PTR_TO_BTF_ID | MEM_ALLOC values point to objects… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Replace ly instruction with llgf cpu_nr is a 32 bit value and BPF_REG_0 is a 64 bit register, when ly loads the cpu_nr into BPF_REG_0 it does not zero the upper bits, but llgf does. | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject writes through untrusted BTF pointers check_ptr_to_btf_access() lets program-type btf_struct_access callbacks validate writes before the default BTF access path rejects non-read accesses. That bypasses the read-only policy for untrusted… | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux bpf_get_btf_vmlinux() lazily parses the vmlinux BTF under the bpf_verifier_lock, but publishes the result through a plain store and re-checks it through a plain lockless load. Nothing orders the… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free on mm_struct in bpf_find_vma() bpf_find_vma() reads task->mm and calls mmap_read_trylock(mm) without holding a reference on the mm. On a foreign task, a concurrent exit_mm() can free the mm_struct between the lockless read and… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Drop scalar id on sign-extending narrowing stack fills When a spilled scalar is filled back with a sign-extending narrowing load (BPF_MEMSX), check_stack_read_fixed_off() copies the spilled register including its scalar id, but… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max check_kfunc_args() detects a kfunc argument named rdonly_buf_size or rdwr_buf_size and stores reg->var_off.value into meta->r0_size, a u64, and does not bound it. check_kfunc_call()… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uac: validate rate list length before storing UAC1 and UAC2 configfs rate-list attributes parse a comma-separated list of sampling rates and store each parsed value in fixed-size arrays. The arrays have UAC_MAX_RATES entries, but the… | |
| Recibida | Alta (7) | 0.15% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths The error paths for endpoint-disabled (ESHUTDOWN) and request-allocation failure (ENOMEM) in ffs_dmabuf_transfer() jump to err_fence_put which calls dma_fence_put() on the… | |
| Recibida | Alta (7) | 0.15% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wmi: fix resource leaks on probe failure During driver initialization in asus_wmi_add(), various subsystems are registered sequentially. However, the error path labels are out of order relative to the registration sequence. Fix… | |
| Recibida | Alta (7.1) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Require a BPF cpumask for bpf_cpumask_populate() bpf_cpumask_populate() writes to its destination with bitmap_copy(), but the destination is typed as struct cpumask *. That allows the verifier to accept borrowed cpumask pointers returned by… |