Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
10.164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: reject invalid file types when reading inodes To prevent inodes with invalid file types from tripping through the vfs and causing malfunctions or assertion failures, add a missing sanity check when reading an inode from a block device. If the… | |
| Modificada | Alta (7.8) | 0.17% | — | Linux KernelDebian Linux | 22/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al Check pde->proc_ops->proc_lseek directly may cause UAF in rmmod scenario. It's a gap in proc_reg_open() after commit 654b33ada4ab("proc: fix UAF in proc_get_inode()").… | |
| Modificada | Alta (7.1) | 0.18% | — | Linux KernelDebian Linux | 22/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in devs.path - touch /mnt/f2fs/012345678901234567890123456789012345678901234567890123 - truncate -s $((1024*1024*1024)) \ /mnt/f2fs/012345678901234567890123456789012345678901234567890123 - touch /mnt/f2fs/file… | |
| Analizada | Media (5.5) | 0.13% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: remove mutex_lock check in hfsplus_free_extents Syzbot reported an issue in hfsplus filesystem: To avoid deadlock, Commit 31651c607151 ("hfsplus: avoid deadlock on file truncation") unlock extree before hfsplus_free_extents(), and add check… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Check device memory pointer before usage Add a NULL check before accessing device memory to prevent a crash if dev->dm allocation in mlx5_init_once() fails. | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: reject TDLS operations when station is not associated syzbot triggered a WARN in ieee80211_tdls_oper() by sending NL80211_TDLS_ENABLE_LINK immediately after NL80211_CMD_CONNECT, before association completed and without prior TDLS… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 22/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_nfacct: don't assume acct name is null-terminated nfnl_acct_find_get() handles non-null input, but the error printk relied on its presence. | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: clk: davinci: Add NULL check in davinci_lpsc_clk_register() devm_kasprintf() returns NULL when memory allocation fails. Currently, davinci_lpsc_clk_register() does not check for this case, which results in a NULL pointer dereference. Add NULL check… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: power: supply: cpcap-charger: Fix null check for power_supply_get_by_name In the cpcap_usb_detect() function, the power_supply_get_by_name() function may return `NULL` instead of an error pointer. To prevent potential null pointer dereferences, Added… | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref fb_add_videomode() can fail with -ENOMEM when its internal kmalloc() cannot allocate a struct fb_modelist. If that happens, the modelist stays empty but the driver continues to register.… | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: PCI: pnv_php: Clean up allocated IRQs on unplug When the root of a nested PCIe bridge configuration is unplugged, the pnv_php driver leaked the allocated IRQ resources for the child bridges' hotplug event notifications, resulting in a panic. Fix this… | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: PCI: pnv_php: Fix surprise plug detection and recovery The existing PowerNV hotplug code did not handle surprise plug events correctly, leading to a complete failure of the hotplug system after device removal and a required reboot to detect new… | |
| Analizada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net: drop UFO packets in udp_rcv_segment() When sending a packet with virtio_net_hdr to tun device, if the gso_type in virtio_net_hdr is SKB_GSO_UDP and the gso_size is less than udphdr size, below crash may happen. To trigger gso segment in… | |
| Modificada | Alta (7.8) | 0.17% | — | Linux KernelDebian Linux | 22/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It is possible for a vsock to autobind to VMADDR_PORT_ANY. This can cause a use-after-free when a connection is made to the bound socket. The socket returned by accept() also has port VMADDR_PORT_ANY but… | |
| Modificada | Media (4.7) | 0.40% | — | Linux KernelDebian Linux | 22/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net/packet: fix a race in packet_set_ring() and packet_notifier() When packet_set_ring() releases po->bind_lock, another thread can run packet_notifier() and process an NETDEV_UP event. This race and the fix are both similar to that of commit… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 19/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: eventpoll: Fix semi-unbounded recursion Ensure that epoll instances can never form a graph deeper than EP_MAX_NESTS+1 links. Currently, ep_loop_check_proc() ensures that the graph is loop-free and does some recursion depth checks, but those recursion… | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 19/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc() In the error paths after fb_info structure is successfully allocated, the memory allocated in fb_deferred_io_init() for info->pagerefs is not freed. Fix that by adding the cleanup… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 19/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: powercap: dtpm_cpu: Fix NULL pointer dereference in get_pd_power_uw() The get_pd_power_uw() function can crash with a NULL pointer dereference when em_cpu_get() returns NULL. This occurs when a CPU becomes impossible during runtime, causing… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 19/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Check governor before using governor->name Commit 96ffcdf239de ("PM / devfreq: Remove redundant governor_name from struct devfreq") removes governor_name and uses governor->name to replace it. But devfreq->governor may be NULL and… | |
| Modificada | Media (5.5) | 0.40% | — | Linux KernelDebian Linux | 19/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls When sending plaintext data, we initially calculated the corresponding ciphertext length. However, if we later reduced the plaintext data length via socket policy, we failed to… | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 19/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtl818x: Kill URBs before clearing tx status queue In rtl8187_stop() move the call of usb_kill_anchored_urbs() before clearing b_tx_status.queue. This change prevents callbacks from using already freed skb due to anchor was not killed before… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 19/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: iwlwifi: Add missing check for alloc_ordered_workqueue Add check for the return value of alloc_ordered_workqueue since it may return NULL pointer. | |
| Modificada | Media (5.5) | 0.24% | — | Linux KernelDebian Linux | 19/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: clear initialized flag for deinit-ed srng lists In a number of cases we see kernel panics on resume due to ath11k kernel page fault, which happens under the following circumstances: 1) First ath11k_hal_dump_srng_stats() call Last… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 19/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent infinite loop in rt6_nlmsg_size() While testing prior patch, I was able to trigger an infinite loop in rt6_nlmsg_size() in the following place: This is because fib6_del_route() and fib6_add_rt2node() uses list_del_rcu(), which can… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 19/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible infinite loop in fib6_info_uses_dev() fib6_info_uses_dev() seems to rely on RCU without an explicit protection. Like the prior fix in rt6_nlmsg_size(), we need to make sure fib6_del_route() or fib6_add_rt2node() have not removed the… |