Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
20.827 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Mark tracing_multi trampolines as ftrace managed Since tracing_multi link does not set ftrace_managed, it would fail to release the tracing_multi link when attaching tracing_multi link and then attaching fentry link. Fix it by setting… | |
| Recibida | Alta (8.2) | 0.56% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error state When do_complete() finds the QP in the error state it returns RESPST_CHK_RESOURCE. Before commit 49dc9c1f0c7e ("RDMA/rxe: Cleanup reset state handling in rxe_resp.c")… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: esp: do not unref managed frag pages in esp_ssg_unref() esp_ssg_unref() releases the page references held on the source scatterlist after the AEAD operation completes. It calls skb_page_unref() on every frag page for an out-of-place transform… | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: validate thread record before delete key rebuild hfsplus_delete_cat() is called with str == NULL when the last open reference to an unlinked HFS+ hardlink backing inode is closed. In that case, the function finds the catalog thread by CNID… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: cxl/features: Reject Get Feature count larger than the output buffer cxlctl_get_feature() sizes its output buffer from the user's fwctl_rpc.out_len, but the device is told to write cxl_mbox_get_feat_in.count bytes into rpc_out->payload, which is a… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: use __va(phys) for kaddr in direct_access Use __va(phys) instead of virt_addr + linear_offset for the kaddr return in __fsdev_dax_direct_access(). The previous code added a device-linear byte offset to virt_addr (which is __va of… | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: media: ipu6: Do not free aux device pdata after init ipu6_bus_initialize_device() stores the isys/psys pdata pointer in struct ipu6_bus_device and initializes the auxiliary device. After that point, error unwinding must drop the auxiliary device… | |
| Recibida | Alta (8.4) | 0.21% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: check SAP message length before reading it Verify the SAP message size is not larger than the local buffer before reading the message to avoid buffer overflow. | |
| Recibida | Alta (7) | 0.16% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: uio: Fix stale info pointer in failed registration path After device_add(), the UIO device is visible to userspace and /dev/uioX can be opened. If a later setup step fails, __uio_register_device() unwinds the device but leaves idev->info pointing at… | |
| Recibida | Alta (7) | 0.16% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: software node: Fix software_node_get_reference_args() with index -1 The bounds check for the index passed to software_node_get_reference_args() was failing when passed UINT_MAX, this in turn would lead to an out of bound access in the property array.… | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject arena frees below the arena base bpf_arena_free_pages() accepts scalar arena addresses. The runtime masks the address to the low 32 bits and reconstructs a full user address from the arena base before returning the range to the arena free… | |
| Recibida | Alta (8.8) | 0.40% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Terminate all descriptors without callbacks The DMA Engine client documentation says in the "Terminate APIs" section of Documentation/driver-api/dmaengine/client.rst: "No callback functions will be called for any incomplete… | |
| Recibida | Alta (7.4) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: Keep link pointers valid on realloc failure meson_card_reallocate_links() grows the DAI link and private data arrays with two consecutive krealloc() calls and updates the owner pointers only after both calls have succeeded. A successful… | |
| Recibida | Alta (7.8) | 0.18% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Propagate sdma_txinit_ahg() errors set_txreq_header_ahg() ignores the return value of sdma_txinit_ahg(). If sdma_txinit_ahg() fails, it returns before initializing tx->txreq. However, set_txreq_header_ahg() ignores the error and returns the… | |
| Recibida | Alta (7.1) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] For a user QP, qp->sq.queue is a ring the application writes directly, so rxe_post_send() takes the is_user branch and only schedules send_task without validating the WQE.… | |
| Recibida | Alta (7.3) | 0.18% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds The IOAPIC hotplug lookup parses both MADT and _MAT records directly. The MADT walk previously used a subtable's declared length to advance the cursor after only locating a generic header. The _MAT… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix kernel stack corruption in tailcall with CFI When CONFIG_CFI_CLANG is enabled, prog->bpf_func already skips the kcfi instruction during setup. Including it again in the tailcall jump offset causes it to jump over an extra 4 bytes,… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destroy_cq_user() When accessing a CQ via the netlink path the only synchronization mechanism for the said CQ is rdma_restrack_get(). Currently, rdma_restrack_del() is invoked at the end of… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destroy_srq_user() When accessing a SRQ via the netlink path the only synchronization mechanism for the said SRQ is rdma_restrack_get(). Currently, rdma_restrack_del() is invoked at the end of… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_free_cq() When accessing a CQ via the netlink path the only synchronization mechanism for the said CQ is rdma_restrack_get(). Currently, rdma_restrack_del() is invoked at the end of ib_free_cq(), which is… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_dealloc_pd_user() When accessing a PD via the netlink path the only synchronization mechanism for the said PD is rdma_restrack_get(). Currently, rdma_restrack_del() is invoked at the end of… | |
| Recibida | Alta (7) | 0.16% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: thermal: intel: int3400: clean up ODVP on probe failures evaluate_odvp() creates per-ODVP sysfs files before the thermal zone and later probe resources are registered. The current unwind path only calls cleanup_odvp() from the late sysfs failure path,… | |
| Recibida | Crítica (9.8) | 0.67% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless frees the skb on this path, causing a… | |
| Recibida | Alta (7) | 0.15% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: complete object teardown when the destroy command fails erdma_destroy_qp(), erdma_destroy_cq(), erdma_dereg_mr(), and erdma_destroy_ah() returned early when erdma_post_cmd_wait() failed, leaking the queue buffers, MTTs, doorbells and the… | |
| Recibida | Alta (7.8) | 0.17% | — | Linux KernelAI | 17/9/2026 | 18/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix WARNING in bpf_tracing_link_release The trampoline could be corrupted by the blindly 'tr->flags = BPF_TRAMP_F_TAIL_CALL_CTX' in verifier. Fix the warning by updating 'tr->flags' with '|=' and lock. |