Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.8)0.14%—Selinux PolicycoreutilsAI23/7/202623/7/2026
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.
AplazadaMedia (5.8)0.10%—Selinux PolicycoreutilsAI23/7/202623/7/2026
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10.
ModificadaBaja (3.3)0.46%—Selinux Project SelinuxFedoraproject Fedora1/7/202117/6/2026
The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indirectly from cil_check_neverallow). This occurs because there is sometimes a lack of checks for invalid statements in an optional block.
AnalizadaBaja (3.3)0.60%—Debian LinuxNetapp Active IQ Unified ManagerNetapp Bootstrap OSNetapp H610c Firmware+41/7/202117/6/2026
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).
ModificadaBaja (3.3)0.46%—Selinux Project SelinuxFedoraproject Fedora1/7/202117/6/2026
The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __verify_map_perm_classperms and hashtab_map).
ModificadaBaja (3.3)0.48%—Selinux Project SelinuxFedoraproject Fedora1/7/202117/6/2026
The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __cil_verify_classpermission and __cil_pre_verify_helper).
ModificadaMedia (6.5)0.22%—Redhat Openstack-selinuxRedhat Openstack Platform7/6/202117/6/2026
An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from privilege escalation. A non-root attacker in one or more Red Hat OpenStack (RHOSP) containers could send messages to the dbus. With access to the dbus, the attacker could…
ModificadaMedia (4.7)0.32%—Fedoraproject Selinux-policy24/8/202017/6/2026
An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allowed to read the user's U2F configuration file. If configured with the nouserok option (the default…
ModificadaMedia (6.1)0.35%—Kernel SelinuxRedhat Enterprise Linux Server26/5/202017/6/2026
A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with…
ModificadaMedia (5.9)0.60%—Canonical Selinux22/4/201916/6/2026
The Ubuntu SELinux initscript before version 1:0.10 used touch to create a lockfile in a world-writable directory. If the OS kernel does not have symlink protections then an attacker can cause a zero byte file to be allocated on any writable filesystem.
ModificadaMedia (4.4)0.39%—Redhat Enterprise LinuxSelinux Project Selinux2/3/201817/6/2026
Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a context with few restrictions. This only happens when the relabeling process is done, usually when taking SELinux state from disabled to…
ModificadaMedia (5.5)0.27%—Selinux Project Selinux21/7/201717/6/2026
selinux-policy when sysctl fs.protected_hardlinks are set to 0 allows local users to cause a denial of service (SSH login prevention) by creating a hardlink to /etc/passwd from a directory named .config, and updating selinux-policy.
ModificadaAlta (8.8)0.38%—Selinux Project SelinuxFedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+319/1/201717/6/2026
SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
ModificadaAlta (10)16%—Selinux SetroubleshootFedoraproject Fedora30/3/201517/6/2026
The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name.
ModificadaMedia (6.9)0.36%—Selinuxproject Policycoreutils8/5/201417/6/2026
seunshare in policycoreutils 2.2.5 is owned by root with 4755 permissions, and executes programs in a way that changes the relationship between the setuid system call and the getresuid saved set-user-ID value, which makes it easier for local users to gain privileges by leveraging a program that mistakenly expected…
ModificadaBaja (1.9)0.39%—Selinux Setroubleshoot23/5/200816/6/2026
Cross-site scripting (XSS) vulnerability in setroubleshoot 2.0.5 allows local users to inject arbitrary web script or HTML via a crafted (1) file or (2) process name, which triggers an Access Vector Cache (AVC) log entry in a log file used during composition of HTML documents for sealert.
ModificadaMedia (4.4)0.30%—Selinux Setroubleshoot23/5/200816/6/2026
sealert in setroubleshoot 2.0.5 allows local users to overwrite arbitrary files via a symlink attack on the sealert.log temporary file.