Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2507▼ 423 respecto a la semana anterior
Críticas / altas1283▲ 4 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
20.616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 25/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: virtio_ring: fix stale descriptor flags after a failed packed add In a packed ring the AVAIL and USED bits sit in the descriptor itself, so writing them makes that descriptor available. Those bit combinations flip meaning on every round of the ring,… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: virtio: fix use-after-free in unregister_virtio_device() device_unregister() is device_del() plus put_device(). When the caller holds no extra reference, that drops the last one and runs the release callback, which for several transports frees the… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: virtio_console: do not free control-out buffers on remove __send_control_msg() publishes &portdev->cpkt as the control-out virtqueue cookie. remove_vqs() walks every virtqueue and passes leftover cookies to free_buf(), which treats them as struct… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: vhost/vdpa: reject VRING_NUM larger than device max vhost_vring_set_num() accepts any non-zero power-of-two queue size that fits in 16 bits. vhost-vdpa then passes that value to set_vq_num() without comparing it with get_vq_num_max(). A process with… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx vhost_vdpa_set_config_call() swaps the eventfd_ctx_fdget() return value into v->config_ctx before checking it, so on failure the field briefly holds an ERR_PTR: Commit 0bde59c1723a… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 25/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: protect config_ctx from being freed under the config callback vhost_vdpa_config_cb() loads v->config_ctx and signals it without taking a reference and without holding any lock: VHOST_VDPA_SET_CONFIG_CALL replaces that field and drops what… | |
| Recibida | Alta (7.8) | 0.12% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: vdpa_sim_blk: reject out-of-range sector starts vdpasim_blk_check_range() logs an invalid start sector but continues validating the request. The subsequent unsigned capacity subtraction can underflow and let an out-of-range buffer offset reach the… | |
| Recibida | Alta (7.5) | 0.12% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: vdpa_sim_net: check TX pull result before RX copy vringh_iov_pull_iotlb() returns a signed byte count. A failed TX pull is currently added to the unsigned byte counter and then passed as a size_t length to receive_filter() and vringh_iov_push_iotlb().… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 25/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: vduse: validate virtqueue alignment vduse_validate_config() only checks the upper bound of vq_align. Invalid values can therefore reach vring_create_virtqueue_map(). The split-ring helpers use align - 1 as a bit mask, so the alignment must be a… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 25/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: vhost: invalidate vring access on IOTLB transitions When VIRTIO_F_ACCESS_PLATFORM changes, cached vring pointers and IOTLB metadata are interpreted in a different address space. Keeping them across the transition can leave stale ring mappings in use.… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: virtio_input: reset device if input_register_device() fails Probe marks the device DRIVER_OK with virtio_device_ready() before calling input_register_device(). If registration fails, the error path cleared vi->ready and called del_vqs() while the… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: virtio_input: stop callbacks before unregistering input device virtinput_remove() unregisters the input device before resetting the virtio device. virtinput_recv_events() drops vi->lock around input_event(), so clearing vi->ready does not stop a… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Update last skb marker in manage_oob(). Fahad Alharbi reported that blocking recv(MSG_PEEK) could hog CPU due to OOB skb. In the following cases, manage_oob() skips OOB skb(s) and returns NULL for the last recv(MSG_PEEK): Then, @copied is 0… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: net: ipv6: Fix UDP length overflow with PMTU discover and big MTU This commit bounds cork->base.fragsize to IP6_MAX_MTU for UDP sockets to avoid a possible overflow of UDP length that triggers a WARN in udp_set_len_short when setsockopt… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 25/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: vduse: return compat ioctl results directly The compat handler handles VDUSE_IOTLB_GET_FD and VDUSE_VQ_GET_INFO, but then calls the native handler. Their different command sizes make native dispatch return -ENOIOCTLCMD. For GET_FD, this overwrites… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Fix budget accounting The gmac_rx() function returns the remaining NAPI budget, but its caller treats the return value as the number of packets received. An idle poll therefore reports a full budget and remains scheduled.… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Count dropped frames as NAPI work The RX loop only consumes budget when it successfully delivers a frame. Error paths keep consuming descriptors without reducing the budget, so a stream of bad frames can process the entire… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 25/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: s390/debug: Fix NULL pointer dereference in debug_set_level() Commit a2cec6863709 ("s390/debug: Add s390dbf kernel parameter") incorrectly removed a null-id check from debug_set_level(), introducing a possible NULL pointer dereference for debug-API… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: ice: add missing xa_destroy for sched_node_ids Commit 16dfa49406bc ("ice: Introduce new parameters in ice_sched_node") added a sched_node_ids xarray to the port info structure, but never called xa_destroy on it. Since xarrays can allocate internal… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: eth: ice: don't dereference pointers from TP_printk() After forwarding net-next during the v7.3 merge window we started seeing: this is due to extra checks added in tracing subsystem in commit b5cc230af5e5 ("tracing: Warn when an event dereferences a… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: Fix UAF of btusb_data by rx_work btusb_close() and btusb_flush() cancel data->rx_work with the asynchronous cancel_delayed_work(), so if btusb_rx_work() is already running on another CPU it keeps running after the cancel returns.… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: validate packet_len before skb_put_data btintel_pcie_submit_rx_work() reads packet_len from rfh_hdr without checking if it exceeds the RX buffer size. An oversized packet_len can lead to an out-of-bounds read in… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del() A NULL pointer dereference in klist_put() occurs when a child device (such as a BNEP network device in bnep_session) is concurrently being unregistered while hci_conn_del_sysfs()… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: null-check fib6_node before accessing in __ip6_del_rt_siblings() syzbot reported a null-ptr-deref in __ip6_del_rt_siblings() [0]. The stack trace hinted towards a null dereference of rt->fib6_node when fn->leaf is accessed in… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: net: macb: destroy the phylink instance on the probe error path macb_mii_init() creates a phylink instance on both of its success paths, but the probe unwind frees the netdev without destroying it, so a failing macb_alloc_tieoff() or register_netdev()… |