Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.17% | — | Freedesktop Udisks2AI | 6/8/2026 | 8/9/2026 | A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary… | |
| Modificada | Media (5.5) | 0.10% | — | Redhat Enterprise LinuxFreedesktop Udisks | 25/2/2026 | 17/6/2026 | A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic… | |
| Modificada | Alta (7.1) | 0.11% | — | Redhat Enterprise LinuxFreedesktop Udisks | 25/2/2026 | 15/7/2026 | A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can… | |
| Aplazada | Alta (8.5) | 0.65% | — | UdisksAI | 28/8/2025 | 25/9/2026 | A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system. This is achieved via the loop device handler, which handles requests sent through the D-BUS interface. As two of the parameters of this handle, it receives the file descriptor list and index… | |
| Aplazada | Alta (7) | 0.47% | — | LibblockdevAIFreedesktop UdisksAI | 19/6/2025 | 30/6/2026 | A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able… | |
| Modificada | Media (4.2) | 0.83% | — | Udisks Project UdisksFedoraproject FedoraRedhat Enterprise Linux | 29/11/2021 | 17/6/2026 | A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability. | |
| Modificada | Alta (7.8) | 0.41% | — | Udisks Project UdisksDebian LinuxFedoraproject FedoraOpensuse+1 | 13/11/2019 | 16/6/2026 | udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules. | |
| Modificada | Alta (7.8) | 0.62% | — | Freedesktop UdisksCanonical Ubuntu Linux | 22/9/2018 | 17/6/2026 | UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malformed filesystem label, as demonstrated by %d or %n substrings. | |
| Modificada | Media (6.9) | 0.43% | — | Freedesktop UdisksCanonical Ubuntu Linux | 11/3/2014 | 17/6/2026 | Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point. | |
| Modificada | Baja (2.1) | 0.27% | — | Freedesktop Udisks | 12/4/2010 | 16/6/2026 | probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/. |