Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.14% | — | Selinux PolicycoreutilsAI | 23/7/2026 | 23/7/2026 | A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10. | |
| Aplazada | Media (5.8) | 0.10% | — | Selinux PolicycoreutilsAI | 23/7/2026 | 23/7/2026 | A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10. | |
| Modificada | Baja (3.3) | 0.46% | — | Selinux Project SelinuxFedoraproject Fedora | 1/7/2021 | 17/6/2026 | The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indirectly from cil_check_neverallow). This occurs because there is sometimes a lack of checks for invalid statements in an optional block. | |
| Analizada | Baja (3.3) | 0.60% | — | Debian LinuxNetapp Active IQ Unified ManagerNetapp Bootstrap OSNetapp H610c Firmware+4 | 1/7/2021 | 17/6/2026 | The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list). | |
| Modificada | Baja (3.3) | 0.46% | — | Selinux Project SelinuxFedoraproject Fedora | 1/7/2021 | 17/6/2026 | The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __verify_map_perm_classperms and hashtab_map). | |
| Modificada | Baja (3.3) | 0.48% | — | Selinux Project SelinuxFedoraproject Fedora | 1/7/2021 | 17/6/2026 | The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __cil_verify_classpermission and __cil_pre_verify_helper). | |
| Modificada | Media (6.5) | 0.22% | — | Redhat Openstack-selinuxRedhat Openstack Platform | 7/6/2021 | 17/6/2026 | An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from privilege escalation. A non-root attacker in one or more Red Hat OpenStack (RHOSP) containers could send messages to the dbus. With access to the dbus, the attacker could… | |
| Modificada | Media (4.7) | 0.32% | — | Fedoraproject Selinux-policy | 24/8/2020 | 17/6/2026 | An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allowed to read the user's U2F configuration file. If configured with the nouserok option (the default… | |
| Modificada | Media (6.1) | 0.35% | — | Kernel SelinuxRedhat Enterprise Linux Server | 26/5/2020 | 17/6/2026 | A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with… | |
| Modificada | Media (5.9) | 0.60% | — | Canonical Selinux | 22/4/2019 | 16/6/2026 | The Ubuntu SELinux initscript before version 1:0.10 used touch to create a lockfile in a world-writable directory. If the OS kernel does not have symlink protections then an attacker can cause a zero byte file to be allocated on any writable filesystem. | |
| Modificada | Media (4.4) | 0.39% | — | Redhat Enterprise LinuxSelinux Project Selinux | 2/3/2018 | 17/6/2026 | Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a context with few restrictions. This only happens when the relabeling process is done, usually when taking SELinux state from disabled to… | |
| Modificada | Media (5.5) | 0.27% | — | Selinux Project Selinux | 21/7/2017 | 17/6/2026 | selinux-policy when sysctl fs.protected_hardlinks are set to 0 allows local users to cause a denial of service (SSH login prevention) by creating a hardlink to /etc/passwd from a directory named .config, and updating selinux-policy. | |
| Modificada | Alta (8.8) | 0.38% | — | Selinux Project SelinuxFedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+3 | 19/1/2017 | 17/6/2026 | SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call. | |
| Modificada | Alta (10) | 16% | — | Selinux SetroubleshootFedoraproject Fedora | 30/3/2015 | 17/6/2026 | The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name. | |
| Modificada | Media (6.9) | 0.36% | — | Selinuxproject Policycoreutils | 8/5/2014 | 17/6/2026 | seunshare in policycoreutils 2.2.5 is owned by root with 4755 permissions, and executes programs in a way that changes the relationship between the setuid system call and the getresuid saved set-user-ID value, which makes it easier for local users to gain privileges by leveraging a program that mistakenly expected… | |
| Modificada | Baja (1.9) | 0.39% | — | Selinux Setroubleshoot | 23/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in setroubleshoot 2.0.5 allows local users to inject arbitrary web script or HTML via a crafted (1) file or (2) process name, which triggers an Access Vector Cache (AVC) log entry in a log file used during composition of HTML documents for sealert. | |
| Modificada | Media (4.4) | 0.30% | — | Selinux Setroubleshoot | 23/5/2008 | 16/6/2026 | sealert in setroubleshoot 2.0.5 allows local users to overwrite arbitrary files via a symlink attack on the sealert.log temporary file. |