Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
21.050 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix rlist race and missing initialization TCP_Server_Info.rlist is allocated via kzalloc which zeros both ->next and ->prev to NULL instead of pointing to itself, making list_empty() always return false and list_add() dereference a NULL… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free of iface in cifs_try_adding_channels() cifs_try_adding_channels() iterates ses->iface_list with list_for_each_entry_safe_from(), which captures the next entry (niface) under iface_lock. The loop body then drops… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbd_connection leak on cifs_get_tcp_session() error When an RDMA connection is successfully established via smbd_get_connection() but cifs_get_tcp_session() later fails (e.g. kthread_create() returns an error), the error path frees… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Fix several related bounds checking and pointer lifecycle issues in receive_encrypted_standard()'s handling of compound encrypted frames: | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() In move_smb2_ea_to_cifs(), the while (src_size > 0) loop condition is insufficient. It allows iteration to continue even if the remaining src_size is too small to contain a complete… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOB read in smb3_enum_snapshots() If snapshot_array_size is smaller than GMT_TOKEN_SIZE, smb3_enum_snapshots() sets ret_data_len to sizeof(struct smb_snapshot_array) without verifying the actual length of the server's reply.… | |
| Recibida | Sin puntuar | 0.21% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix reparse buffer bounds in cifs_query_reparse_point() In cifs_query_reparse_point(), the start >= end check before casting to struct reparse_data_buffer * only ensures the start pointer is within the response. It fails to verify that… | |
| Recibida | Sin puntuar | 0.22% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix server->total_read for compound encrypted PDUs In receive_encrypted_standard(), server->total_read is left at the full decrypted frame size when walking sub-PDUs of a compound encrypted frame. As a result, cifs_handle_standard()… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/ttm: fix swapped-out resources never leaving their bulk_move range ttm_tt_swapout() returns the number of pages swapped out on success and a negative error code on failure; for a populated ttm it never returns zero. Commit b2ed01e7ad3d ("drm/ttm:… | |
| Recibida | Sin puntuar | 0.20% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: restrict BAR0 fallback read to SR-IOV VFs only The BAR0 fallback read path was introduced as a workaround for SR-IOV VFs where the VRAM aperture is not available during early init. Restrict this workaround to only SR-IOV VFs where it's… | |
| Pendiente de análisis | Alta (7.8) | 0.07% | — | Linux KernelAI | 5/10/2026 | 6/10/2026 | In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due to an uninitialized pointer dereference. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| En análisis | Crítica (9.3) | 0.13% | — | Watchguard Kernel Memory Access DriverAI | 1/10/2026 | 2/10/2026 | A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process… | |
| Analizada | Media (5.5) | 0.14% | — | Linux Kernel | 29/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, but page tracking is per-address-space and shadow pages are shared across all address spaces. With SMM, a GFN can therefore be… | |
| Analizada | Alta (7) | 0.10% | — | Linux Kernel | 26/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcount The commit 260fbcb92bbea ("cgroup: Move dying_tasks cleanup from cgroup_task_release() to cgroup_task_free()") extended the lifetime of tasks on the dying_tasks list. The iterators have… | |
| Analizada | Media (5.5) | 0.10% | — | Linux Kernel | 25/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix tree connection leak in smb2_tree_connect() See the procedure below: Disconnect the new tree connection if ksmbd_iov_pin_rsp() fails. | |
| Modificada | Media (5.5) | 0.11% | — | Linux Kernel | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: nvdimm: pmem: keep PREFLUSH before data writes pmem_submit_bio() records a REQ_PREFLUSH error, but continues to copy the bio data and can later overwrite the error with a successful REQ_FUA flush. That lets data writes run after a failed preflush and… | |
| Analizada | Media (5.5) | 0.11% | — | Linux Kernel | 25/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() padapter->HalData is allocated via vzalloc(), but incorrectly freed using kfree() in the rtw_sdio_if1_init() error path. Using kfree() to release this vmalloc-backed buffer can… | |
| Analizada | Media (5.5) | 0.11% | — | Linux Kernel | 25/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: unregister debugfs entries on teardown ucsi_register() creates per-instance debugfs entries, but ucsi_unregister() keeps them around until ucsi_destroy(). Drivers like ucsi_glink that unregister/register the same UCSI instance across… | |
| En análisis | Media (5.5) | 0.11% | — | Linux Kernel | 25/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: pass correct argument to function The first argument to iwl_mei_write_cyclic_buf() should be the cldev but the q_head pointer is passed instead. Fix it. | |
| En análisis | Media (5.5) | 0.11% | — | Linux Kernel | 25/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Recover HW before retire hung submit During recovery, it is not safe to retire the hung submit before we recover the GPU. Retiring the submit triggers BO free and that can result in GPU pagefaults since the GPU may be actively accessing those… | |
| En análisis | Media (5.5) | 0.11% | — | Linux Kernel | 25/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths issue_beacon(), issue_probersp() and issue_asocrsp() obtain a management xmit_frame together with its xmit_buf from the driver's fixed-size management-TX pools via… | |
| En análisis | Crítica (9.8) | 0.42% | — | Linux Kernel | 25/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA contexts but leaves stale n_rw_ctx and n_rdma values (and a dangling rw_ctxs… | |
| En análisis | Media (5.5) | 0.11% | — | Linux Kernel | 25/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Mark bpf_refcount field as unique BPF_REFCOUNT is not marked as a unique field, while it should be. Fix this oversight. | |
| En análisis | Sin puntuar | 0.14% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix transaction overflow during writeback Commit 95ad8ee45cdb ("ext4: correct the reserved credits for extent conversion") was correct to note that we need to reserve enough credits for all extents possibly underlying a large folio. However it… | |
| En análisis | Sin puntuar | 0.14% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ACPI: platform: Use acpi_bus_get_primary_device() The acpi_get_first_physical_node() usage in acpi_platform_fill_resource() and acpi_create_platform_device() is generally unsafe because in theory the device returned by it may be freed at any time [1].… |