Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.18% | — | Virtio WIN ViosockAI | 18/9/2026 | 30/9/2026 | virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32-bit sum used by VIOSockSelect for bounds… | |
| Pendiente de análisis | Media (6.1) | 0.18% | — | Zephyr RtosAIVirtio PCIAI | 25/8/2026 | 26/8/2026 | The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization. In virtio_pci_read_cap() the device-supplied capability length byte cap_len (read from PCI config space via pcie_conf_read()) was only checked with assert(tmp.cap_len == cap_struct_size). That assert… | |
| Pendiente de análisis | Alta (8.8) | 0.22% | — | Zephyr VirtioAI | 24/8/2026 | 26/8/2026 | The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring. In virtio_isr() (drivers/virtio/virtio_common.c), the device-written vq->used->ring[idx].id is used directly as an index into vq->recv_cbs[] and vq->desc[], which are both allocated with exactly… | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | Qemu Virtio SNDAI | 19/6/2026 | 22/6/2026 | An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition. | |
| Analizada | Alta (7.8) | 0.15% | — | Redhat Virtio-winRedhat Enterprise Linux | 30/3/2026 | 17/6/2026 | A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it fails to properly manage memory, resulting in a use-after-free vulnerability. This issue could allow a local attacker to corrupt system memory, potentially leading to system instability or… | |
| Analizada | Media (5.5) | 0.16% | — | Redhat Virtio-winRedhat Enterprise Linux | 30/3/2026 | 17/6/2026 | A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability by supplying an excessive number of descriptors, leading to a buffer overrun. This can cause a… | |
| Aplazada | Media (5.5) | 0.14% | — | QemuAIVirtio CryptoAI | 18/2/2026 | 17/6/2026 | A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length limit in the AKCIPHER path, leading to uncontrolled memory allocation. This can result in a denial of service (DoS) on the host system by causing the QEMU process to terminate unexpectedly. | |
| Aplazada | Alta (8.2) | 0.30% | — | QemuAIQemu Virtio GPUAIQemu Virtio Serial BUSAIQemu Virtio CryptoAI | 9/4/2024 | 17/6/2026 | A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial… | |
| Modificada | Alta (7.5) | 1.8% | — | Redhat Virtio-win | 26/6/2017 | 17/6/2026 | The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as demonstrated by a value that does not account for the size of the IP options. |