Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3335▲ 417 respecto a la semana anterior
Críticas / altas1494▲ 172 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)579▲ 105 respecto a la semana anterior
593 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.44% | — | Ansible Freebsd Jail Connection PluginAI | 21/9/2026 | 24/9/2026 | Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic… | |
| Analizada | Alta (7.8) | 0.17% | — | Freebsd | 26/8/2026 | 10/9/2026 | mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root. | |
| Analizada | Alta (8.8) | 0.60% | — | Freebsd | 26/8/2026 | 10/9/2026 | LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root. | |
| Analizada | Alta (8.8) | 0.60% | — | Freebsd | 26/8/2026 | 10/9/2026 | mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially execute arbitrary code as root. | |
| Analizada | Alta (7.8) | 0.12% | — | Freebsd | 26/8/2026 | 24/9/2026 | The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to be used immediately after creating the object, before any memory is allocated for the object. The handler checked whether a page size had already been configured without holding the rangelock. Two… | |
| Analizada | Alta (7) | 0.10% | — | Freebsd | 26/8/2026 | 24/9/2026 | The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently being destroyed to the calling process' session. An unprivileged local user can… | |
| Analizada | Alta (8.1) | 0.35% | — | Freebsd | 26/8/2026 | 24/9/2026 | In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a dedicated field. This change was largely internal to the kernel… | |
| Analizada | Alta (7.8) | 0.15% | — | Freebsd | 26/8/2026 | 24/9/2026 | The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync group list lock and sleeps. Upon reawakening, it is possible that the sync group structure is freed, but the implementation did not handle this possibility. On a system… | |
| Analizada | Alta (7.8) | 0.15% | — | Freebsd | 26/8/2026 | 24/9/2026 | The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user can exploit this use-after-free to escalate… | |
| Analizada | Alta (7.8) | 0.14% | — | Freebsd | 26/8/2026 | 24/9/2026 | When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly. An unprivileged local user who has attached PMCs to a process can continue monitoring it after the process… | |
| Analizada | Alta (7.4) | 0.10% | — | Freebsd | 19/8/2026 | 31/8/2026 | The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program headers, then iterated over the map a second time to populate them. A process sharing the address space via rfork(2) can mutate the map between the two passes, causing the second pass to write program… | |
| Analizada | Alta (7.8) | 0.17% | — | Freebsd | 19/8/2026 | 31/8/2026 | The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protecting the set, allocated a buffer sized for that count, and reacquired the lock. A sequence-number check was used to verify that the set had not been replaced in the interim, but the sequence number… | |
| Analizada | Alta (8.1) | 0.38% | — | Freebsd | 19/8/2026 | 31/8/2026 | As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed root user. Tracing configured by a jailed root user was therefore not flagged as privileged. An unprivileged user in a jail that has permission to debug the target process can modify the jailed root user's ktrace(2)… | |
| Analizada | Alta (7.5) | 0.32% | — | Freebsd | 19/8/2026 | 31/8/2026 | After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC verification step succeeded. The driver thus silently accepted packets with an invalid Poly1305 authentication tag. A remote attacker who can send UDP packets to a WireGuard endpoint, and who can… | |
| Analizada | Media (5.5) | 0.14% | — | Freebsd | 19/8/2026 | 31/8/2026 | To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's clock. For a timer using CLOCK_TAI this can fail when no TAI offset has been configured, but the error return was not checked, so the uninitialized output buffer was copied to userspace. An… | |
| Analizada | Alta (8.4) | 0.17% | — | Freebsd | 19/8/2026 | 31/8/2026 | While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's active list before the copy was complete. The copy routine did not account for this and could enqueue the new knote a second time, corrupting the active list. In addition, the copy routine did… | |
| Analizada | Crítica (9.8) | 0.52% | — | Freebsd | 19/8/2026 | 31/8/2026 | The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output. Some ISO-2022 variants can require up to 10 bytes per character, in which case conversions can trigger a stack buffer overflow of up to four bytes. An application that uses iconv(3) to convert untrusted… | |
| Analizada | Crítica (9.8) | 0.52% | — | Freebsd | 19/8/2026 | 31/8/2026 | Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses… | |
| Analizada | Media (5.5) | 0.15% | — | Freebsd | 19/8/2026 | 31/8/2026 | The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero the stack struct. An unprivileged user may observe a small amount of uninitialized kernel stack data, which may contain sensitive information. | |
| Analizada | Media (5.5) | 0.15% | — | Freebsd | 19/8/2026 | 31/8/2026 | The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct. An unprivileged user may observe 104 bytes of uninitialized kernel stack data, which may contain sensitive information. | |
| Analizada | Baja (3.3) | 0.14% | — | Freebsd | 19/8/2026 | 31/8/2026 | When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index for every mbuf in the chain, including mbufs that were skipped because they contained only TLS header bytes. This left uninitialized entries in the iovec array. The iovec array was allocated without… | |
| Analizada | Baja (3.3) | 0.12% | — | Freebsd | 19/8/2026 | 1/9/2026 | The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is able to set metadata on a dataset indicating that the dataset has received properties from a zfs-recv(8) stream. Any local user can set the internal ZFS metadata flag "$hasrecvd" on datasets via… | |
| Analizada | Alta (7.8) | 0.15% | — | Freebsd | 19/8/2026 | 1/9/2026 | The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a 32-bit integer for allocation, then used the original 64-bit size as the length for a byteswap operation. A local user with the "receive" delegated ZFS permission can trigger kernel memory corruption via… | |
| Analizada | Alta (7.8) | 0.15% | — | Freebsd | 19/8/2026 | 1/9/2026 | The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer for the kernel allocation, but used the original 64-bit size as the buffer limit when writing records. A local user with the "userused" delegated ZFS permission can trigger a kernel heap overflow via… | |
| Analizada | Alta (8.4) | 0.34% | — | Freebsd | 19/8/2026 | 1/9/2026 | Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this. An unprivileged local user can abuse the bug to access freed kernel memory. This can… |