Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
4241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.15% | — | Canonical Ubuntu-pro-clientAI | 16/7/2026 | 16/7/2026 | An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL… | |
| Pendiente de análisis | Media (5) | 0.21% | — | Canonical Ubuntu PRO ClientAI | 16/7/2026 | 16/7/2026 | An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying… | |
| Pendiente de análisis | Crítica (9) | 0.53% | — | Canonical Ubuntu-pro-clientAI | 16/7/2026 | 16/7/2026 | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the… | |
| Pendiente de análisis | Alta (8.8) | 0.18% | — | OpenjdkAIUbuntuAIMailcapAIFreedesktop Xdg-desktop-portal-gtkAI | 8/7/2026 | 14/7/2026 | A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk… | |
| Aplazada | Media (5.3) | 0.21% | — | GNU TARAIUbuntuAIDebianAICentosAI | 17/6/2026 | 22/6/2026 | The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU tar) which varies by platform. While CVE-2025-10284 addressed git-specific RCE vectors, the underlying archive extraction path traversal was… | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops. | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an unprivileged local user and could result in incorrect fine-grained mediation of network sockets. | |
| Analizada | Media (5.5) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel panic. | |
| Analizada | Media (5.5) | 0.10% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock. | |
| Analizada | Alta (7.8) | 0.15% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the… | |
| Analizada | Media (5.5) | 0.15% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects. | |
| Analizada | Alta (7.8) | 0.17% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code execution. | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses. | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses. | |
| Analizada | Media (6.1) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to… | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops. | |
| Analizada | Media (5.5) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion. | |
| Modificada | Media (5.5) | 0.17% | — | Ubuntu Libefiboot | 22/4/2026 | 21/9/2026 | A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that each node's Length field is at least 4 bytes, which is the minimum size for an EFI (Extensible Firmware Interface) device path node header. A local user could exploit this vulnerability by providing… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Analizada | Baja (2.7) | 0.31% | — | Canonical Ubuntu Desktop Provision | 9/4/2026 | 30/9/2026 | In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs. | |
| Analizada | Baja (2.7) | 0.28% | — | Canonical Ubuntu Subiquity | 9/4/2026 | 30/9/2026 | In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the attached logs. | |
| Analizada | Alta (7.8) | 0.18% | — | Canonical Ubuntu Linux | 17/3/2026 | 17/6/2026 | Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS. | |
| Modificada | Media (6.9) | 1.3% | — | Canonical Ubuntu LinuxOpenbsd OpensshDebian LinuxRedhat Enterprise Linux | 12/3/2026 | 15/7/2026 | Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an… | |
| Pendiente de análisis | Alta (7.1) | 0.15% | — | Ubuntu LinuxAI | 5/3/2026 | 17/6/2026 | Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: Don’t call skb_get() for OOB skb"). When orphaned MSG_OOB sockets hit unix_gc(), the garbage collector still calls kfree_skb() as if OOB SKBs held two references; on Ubuntu Linux 6.8 (Noble Numbat)… | |
| Analizada | Media (6.9) | 0.14% | — | Ubuntu Python-aptDebian Linux | 5/12/2025 | 25/9/2026 | NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key. |