Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Linux" — 1165 resultados ✕ Limpiar búsqueda
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1782
Esta semana
RSS
L Crítico vulnerabilidad
25/06/2026
[CVE-2026-53151] In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to ex…
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table for parsing Fix modification of the received skbuff in rxrpc_input_soft_acks() and a potential incorrect access of the buffer in a fragmented UDP packet (the packet would probably have to be deliberately pre-generated as fragmented) when AF_RXRPC tries to extract the contents o…
L Alto vulnerabilidad
25/06/2026
[CVE-2026-53153] In the Linux kernel, the following vulnerability has been resolved: mm/list_lru: drain before clear…
In the Linux kernel, the following vulnerability has been resolved: mm/list_lru: drain before clearing xarray entry on reparent memcg_reparent_list_lrus() clears the dying memcg's xarray entry with xas_store(&xas, NULL) before reparenting its per-node lists into the parent. This opens a window where a concurrent list_lru_del() arriving for the dying memcg sees xa_load() == NULL, walks to the pa…
L Alto vulnerabilidad
25/06/2026
[CVE-2026-53156] In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix use-after-free…
In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix use-after-free bugs in error paths Fix several instances of error paths in which we call __nvmem_device_put() - which may end up freeing the underlying memory and other resources - and then keep on using the nvmem structure. Always put the reference to the nvmem device as the last step before returning the error…
L Alto vulnerabilidad
25/06/2026
[CVE-2026-53137] In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp HDMI HDC…
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size [Why & How] During HDCP 2.x repeater authentication over HDMI, the driver reads the sink's RxStatus register and extracts a 10-bit message size field (max value 1023). This value is used as the read length for the ReceiverID list without being clamped to the size o…
L Alto vulnerabilidad
25/06/2026
[CVE-2026-53138] In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Bound VBIOS re…
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Bound VBIOS record-chain walk loops [Why & How] All record-chain walk loops in bios_parser.c and bios_parser2.c use for(;;) and only terminate on a 0xFF record_type sentinel or zero record_size. A malformed VBIOS image missing the terminator record causes unbounded iteration at probe time, potentially hundreds o…
L Alto vulnerabilidad
25/06/2026
[CVE-2026-53143] In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow…
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 The v11 MQD manager incorrectly assigned the CP-compute variants of checkpoint_mqd/restore_mqd for KFD_MQD_TYPE_SDMA queues. These functions use sizeof(struct v11_compute_mqd) (2048 bytes) instead of sizeof(struct v11_sdma_mqd) (512 bytes), causing a 1536-…
L Alto vulnerabilidad
25/06/2026
[CVE-2026-53145] In the Linux kernel, the following vulnerability has been resolved: drm/gem: Try to fix change_hand…
In the Linux kernel, the following vulnerability has been resolved: drm/gem: Try to fix change_handle ioctl, attempt 4 [airlied: just added some comments on how to reenable] On-list because the cat is out of the bag and we're clearly not good enough to figure this out in private. The story thus far: 5e28b7b94408 ("drm: Set old handle to NULL before prime swap in change_handle") tried to fix a r…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
L Alto vulnerabilidad
25/06/2026
[CVE-2026-53146] In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain resp…
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain response copy to actual frame size tb_xdomain_copy() copies req->response_size bytes from the received packet buffer regardless of the actual frame size. When a short response arrives, this reads past the valid frame data in the DMA pool buffer into stale contents from previous transactions. Use the …
L Crítico vulnerabilidad
25/06/2026
[CVE-2026-53131] In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC…
In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and `hash:mac` ipset types, and `nf_log_syslog` access `eth_hdr(skb)` after either assuming that the skb is associated with an Ethernet device or checking only that the `ETH_HLEN` bytes at `skb_mac_header(skb…
L Alto vulnerabilidad
25/06/2026
[CVE-2026-53132] In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential unb…
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential unbounded skb queue virtio_transport_inc_rx_pkt() checks vvs->rx_bytes + len > vvs->buf_alloc. virtio_transport_recv_enqueue() skips coalescing for packets with VIRTIO_VSOCK_SEQ_EOM. If fed with packets with len == 0 and VIRTIO_VSOCK_SEQ_EOM, a very large number of packets can be queued because vvs-…
L Alto vulnerabilidad
25/06/2026
[CVE-2026-53133] In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix truncation for b…
In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix truncation for block sizes >= 4G When the iommu is used the linearization of the mapping can give a single block that is very large split across multiple SG entries. When __rdma_block_iter_next() reassembles the split SG entries it is overflowing the 32 bit stack values and computed the wrong DMA addresses for bl…
L Alto vulnerabilidad
25/06/2026
[CVE-2026-53136] In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp VBIOS HD…
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size [Why & How] The VBIOS integrated info tables (v1_11 and v2_1) contain HdmiRegNum and Hdmi6GRegNum fields that are used as loop bounds when copying retimer I2C register settings into fixed-size arrays (dp*_ext_hdmi_reg_settings[9] and dp*_ext_hdmi_6g_reg_setti…
R Alto vulnerabilidad
25/06/2026
[CVE-2026-8660] OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux …
OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter due to insufficient input validation when constructing shell commands.
R Alto vulnerabilidad
25/06/2026
[CVE-2026-8665] OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Lin…
OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command construction.
R Alto vulnerabilidad
25/06/2026
[CVE-2026-8666] OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plug…
OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient input validation when constructing shell commands.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
R Alto vulnerabilidad
25/06/2026
[CVE-2026-8592] OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin …
OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processing pipeline.
G Alto vulnerabilidad
25/06/2026
[CVE-2026-9154] Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated…
Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression parameter.
G Alto vulnerabilidad
25/06/2026
[CVE-2026-9155] OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated…
OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input validation.
M Alto vulnerabilidad
24/06/2026
[CVE-2026-48793] Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument …
Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerability exists in the subtitle conversion code path. SubtitleEncoder.ConvertTextSubtitleToSrtInternal (SubtitleEncoder.cs, line 382) interpolates the subtitle file path into FFmpeg command-line arguments without calling EncodingUtils.NormalizePath(). On Linux, filenames can contain d…
G Alto vulnerabilidad
24/06/2026
[CVE-2026-13029] Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker wh…
Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)