Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
10.007 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.19% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too. | |
| Modificada | Alta (7.1) | 0.32% | — | Linux KernelDebian Linux | 4/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: smb3: fix for slab out of bounds on mount to ksmbd With KASAN enabled, it is possible to get a slab out of bounds during mount to ksmbd due to missing check in parse_server_interfaces() (see below): | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 4/9/2025 | 14/7/2026 | In the Linux kernel, the following vulnerability has been resolved: netlink: avoid infinite retry looping in netlink_unicast() netlink_attachskb() checks for the socket's read memory allocation constraints. Firstly, it has: to check if the just increased rmem value fits into the socket's receive buffer. If not, it… | |
| Modificada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 4/9/2025 | 14/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: add phy_mask for ax88772 mdio bus Without setting phy_mask for ax88772 mdio bus, current driver may create at most 32 mdio phy devices with phy address range from 0x00 ~ 0x1f. DLink DUB-E100 H/W Ver B1 is such a device.… | |
| Modificada | Alta (7.8) | 0.39% | — | Linux KernelDebian Linux | 4/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() Lei Lu recently reported that nfsd4_setclientid_confirm() did not check the return value from get_client_locked(). a SETCLIENTID_CONFIRM could race with a confirmed client… | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix jump offset calculation in tailcall The extra pass of bpf_int_jit_compile() skips JIT context initialization which essentially skips offset calculation leaving out_offset = -1, so the jmp_offset in emit_bpf_tail_call is calculated… | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 4/9/2025 | 14/7/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix refcount leak on table dump While its very unlikely, its possible that ct == last. If this happens, then the refcount of ct was already incremented. This 2nd increment is never undone. This prevents the conntrack object from… | |
| Modificada | Alta (7.8) | 0.16% | — | Linux KernelDebian Linux | 4/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: linearize cloned gso packets in sctp_rcv A cloned head skb still shares these frag skbs in fraglist with the original head skb. It's not safe to access these frag skbs. syzbot reported two use-of-uninitialized-memory bugs caused by this: and… | |
| Modificada | Alta (7.1) | 0.17% | — | Linux KernelDebian Linux | 4/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: hfs: fix slab-out-of-bounds in hfs_bnode_read() This patch introduces is_bnode_offset_valid() method that checks the requested offset value. Also, it introduces check_and_correct_requested_length() method that checks and correct the requested length… | |
| Modificada | Alta (7.1) | 0.17% | — | Linux KernelDebian Linux | 4/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read() The hfsplus_bnode_read() method can trigger the issue: | |
| Modificada | Alta (7.1) | 0.17% | — | Linux KernelDebian Linux | 4/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() The hfsplus_readdir() method is capable to crash by calling hfsplus_uni2asc(): | |
| Modificada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: don't use BUG_ON() in hfsplus_create_attributes_file() When the volume header contains erroneous values that do not reflect the actual state of the filesystem, hfsplus_fill_super() assumes that the attributes file is not yet created, which… | |
| Modificada | Media (5.5) | 0.12% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: avoid deadlock when linking with ReplaceIfExists If smb2_create_link() is called with ReplaceIfExists set and the name does exist then a deadlock will happen. ksmbd_vfs_kern_path_locked() will return with success and the parent directory… | |
| Modificada | Alta (7.8) | 0.38% | — | Linux KernelDebian Linux | 4/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: drbd: add missing kref_get in handle_write_conflicts With `two-primaries` enabled, DRBD tries to detect "concurrent" writes and handle write conflicts, so that even if you write to the same sector simultaneously on both nodes, they end up with the… | |
| Modificada | Alta (7.8) | 0.17% | — | Linux KernelDebian Linux | 4/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add sanity check for file name The length of the file name should be smaller than the directory entry size. | |
| Modificada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime() snd_soc_remove_pcm_runtime() might be called with rtd == NULL which will leads to null pointer dereference. This was reproduced with topology loading and marking a link as ignore due to… | |
| Modificada | Alta (7.8) | 0.19% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: fbdev: fix potential buffer overflow in do_register_framebuffer() The current implementation may lead to buffer overflow when: 1. Unregistration creates NULL gaps in registered_fb[] 2. All array slots become occupied despite num_registered_fb < FB_MAX… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr A syzbot fuzzed image triggered a BUG_ON in ext4_update_inline_data() when an inode had the INLINE_DATA_FL flag set but was missing the system.data extended attribute. Since this can happen… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated In case of an ib_fast_reg_mr allocation failure during iSER setup, the machine hits a panic because iscsi_conn->dd_data is initialized unconditionally, even when no memory is… | |
| Modificada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Double-free fix When the bfad_im_probe() function fails during initialization, the memory pointed to by bfad->im is freed without setting bfad->im to NULL. Subsequently, during driver uninstallation, when the state machine enters the… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: jfs: Regular file corruption check The reproducer builds a corrupted file on disk with a negative i_size value. Add a check when opening this file to avoid subsequent operation failures. | |
| Modificada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 4/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: jfs: upper bound check of tree index in dbAllocAG When computing the tree index in dbAllocAG, we never check if we are out of bounds realative to the size of the stree. This could happen in a scenario where the filesystem metadata are corrupted. | |
| Modificada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: MIPS: Don't crash in stack_top() for tasks without ABI or vDSO Not all tasks have an ABI associated or vDSO mapped, for example kthreads never do. If such a task ever ends up calling stack_top(), it will derefence the NULL ABI pointer and crash. This… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure If a call to lpfc_sli4_read_rev() from lpfc_sli4_hba_setup() fails, the resultant cleanup routine lpfc_sli4_vport_delete_fcp_xri_aborted() may occur before sli4_hba.hdwqs are… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: dib7090p: fix null-ptr-deref in dib7090p_rw_on_apb() In dib7090p_rw_on_apb, msg is controlled by user. When msg[0].buf is null and msg[0].len is zero, former checks on msg[0].buf would be passed. If accessing msg[0].buf[2]… |