Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
135 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.7) | 0.16% | — | Zephyr RtosAI | 21/9/2026 | 22/9/2026 | The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c). On three failure paths — a failed full-length GET_DESCRIPTOR(CONFIGURATION) read, a mismatch between the short… | |
| Pendiente de análisis | Media (4.3) | 0.24% | — | Zephyr RtosAI | 18/9/2026 | 18/9/2026 | gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one. The loop bound was taken solely from the attacker-controlled wire field announce->steps_removed (accepted up to 254), never from… | |
| Pendiente de análisis | Baja (3.1) | 0.17% | — | Zephyr RtosAI | 18/9/2026 | 18/9/2026 | gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct gptp_hdr) (34) bytes of payload. The header accessor gptp_get_hdr() deliberately never fails for a… | |
| Pendiente de análisis | Media (4.6) | 0.17% | — | Zephyr RtosAIITE It82xx2AI | 14/9/2026 | 14/9/2026 | The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv->suspended_work, suspended_handler) inside it82xx2_enable() (the driver's .enable op) in drivers/usb/udc/udc_it82xx2.c. This work item is scheduled essentially continuously while the USB bus is… | |
| Pendiente de análisis | Media (5.9) | 0.31% | — | Zephyr RtosAI | 14/9/2026 | 14/9/2026 | Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cached client sessions that is shared by every TLS socket context. The functions that mutate and read it — tls_session_save(), tls_session_get(), tls_session_cache_reset(), and the settings restore… | |
| Pendiente de análisis | Media (6.5) | 0.20% | — | Zephyr RtosAI | 14/9/2026 | 14/9/2026 | net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max_reachable = 3*base/2 using integer division. When base_reachable_time is 1, both… | |
| Pendiente de análisis | Media (5.3) | 0.27% | — | Zephyr RtosAI | 13/9/2026 | 14/9/2026 | The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_name buffer (and, for read, a data buffer) via k_malloc() when CONFIG_MCUMGR_GRP_SETTINGS_BUFFER_TYPE_HEAP is enabled,… | |
| Pendiente de análisis | Media (6.5) | 0.18% | — | Zephyr RtosAI | 31/8/2026 | 1/9/2026 | net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitation. When it is called with a data packet pending on an unresolved neighbor and that neighbor's pending_queue is already non-empty (an NS is already outstanding), the function appends the data packet and returns early… | |
| Pendiente de análisis | Media (6.5) | 0.20% | — | Zephyr RtosAI | 31/8/2026 | 1/9/2026 | When Ethernet bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_bridge_input_process() in subsys/net/l2/ethernet/bridge/bridge_input.c decides how each frame received on a bridge member interface is handled. For frames that must also be delivered to the local stack, the code called eth_bridge_handle_locally() and… | |
| Pendiente de análisis | Baja (3.1) | 0.10% | — | Zephyr RtosAI | 31/8/2026 | 1/9/2026 | The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statically-allocated work nodes through a free-list i3c_ibi_work_nodes_free implemented as a plain sys_slist_t, which provides no synchronization. The allocation helpers (i3c_ibi_work_enqueue, i3c_ibi_work_enqueue_target_irq, i3c_ibi_work_enqueue_hotjoin,… | |
| Pendiente de análisis | Media (6.1) | 0.18% | — | Zephyr RtosAIVirtio PCIAI | 25/8/2026 | 26/8/2026 | The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization. In virtio_pci_read_cap() the device-supplied capability length byte cap_len (read from PCI config space via pcie_conf_read()) was only checked with assert(tmp.cap_len == cap_struct_size). That assert… | |
| Pendiente de análisis | Media (5.3) | 0.23% | — | Zephyr RtosAI | 24/8/2026 | 26/8/2026 | The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (uint32_t data[4]). The builders make_endpoint_info() and make_function_block_info() populate only the first two words (res.data[0] and res.data[1]) and, before this fix, declared their result as an… | |
| Pendiente de análisis | Media (6.4) | 0.11% | — | Zephyr RtosAINXP Mailbox DriverAI | 24/8/2026 | 26/8/2026 | The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the original, still-mutable userspace struct mbox_msg * pointer to z_impl_mbox_send() and the underlying driver.… | |
| Analizada | Alta (8.2) | 0.18% | — | Amazon Freertos | 21/8/2026 | 25/8/2026 | Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel memory. To remediate this issue, users should upgrade to version 11.3.1 or later. | |
| Analizada | Alta (8.3) | 0.16% | — | Amazon Freertos | 21/8/2026 | 25/8/2026 | Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corrupt secure-world heap metadata via an out-of-bounds write with an undersized stack size parameter. To remediate this issue, users should upgrade to version 11.3.1 or later. | |
| Analizada | Alta (8.3) | 0.16% | — | Amazon Freertos | 21/8/2026 | 27/8/2026 | Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. To remediate this issue, users should upgrade to version 11.3.1 or later. | |
| Analizada | Crítica (9.3) | 0.17% | — | Amazon Freertos | 21/8/2026 | 27/8/2026 | Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later. | |
| Pendiente de análisis | Alta (8.8) | 0.14% | — | Zephyr RtosAI | 17/8/2026 | 26/8/2026 | The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trust boundary for a user-mode caller. Prior to the fix it validated only the output buffer (K_SYSCALL_MEMORY_WRITE) and passed the two struct device *… | |
| Pendiente de análisis | Alta (8.4) | 0.16% | — | Zephyr RtosAI | 14/8/2026 | 26/8/2026 | The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-supplied source, desc, package, and data arguments directly to the kernel-mode implementation z_impl_z_log_msg_static_create() without performing any of the mandatory… | |
| Pendiente de análisis | Alta (7.8) | 0.11% | — | Zephyr RtosAI | 12/8/2026 | 26/8/2026 | The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapshot the caller-supplied struct net_msghdr into a kernel-side copy with k_usermode_from_copy(), but then re-read the still-live user struct for subsequent decisions. The kernel iovec shadow buffer… | |
| Pendiente de análisis | Media (5.9) | 0.51% | — | Zephyr RtosAI | 12/8/2026 | 26/8/2026 | The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its credential-store mutex as a plain zero-filled static struct k_mutex credential_lock; and never called k_mutex_init() on it. A statically zero-filled k_mutex has an uninitialized wait queue (its dlist… | |
| Pendiente de análisis | Alta (8.4) | 0.16% | — | Zephyr RtosAI | 10/8/2026 | 26/8/2026 | tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer was at least MBEDTLS_SSL_CID_OUT_LEN_MAX (default 32) bytes.… | |
| Pendiente de análisis | Baja (2.5) | 0.10% | — | Zephyr RtosAI | 10/8/2026 | 1/9/2026 | The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block context, payload buffer, status code, socket, and a one-element poll-fd array fds[1]. Access to ctx was not serialized, and prepare_fds() wrote… | |
| Analizada | Alta (8.7) | 0.68% | — | Freertos Coremqtt | 15/5/2026 | 17/6/2026 | Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users should upgrade to v5.0.1. | |
| Analizada | Media (6.1) | 0.40% | — | Amazon Freertos-plus-tcp | 29/4/2026 | 17/6/2026 | Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a prefix length value exceeding the maximum valid length, resulting in a… |