Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 40 min
Buscando: "Linux" — 1392 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93786] In the Linux kernel, the following vulnerability has been resolved: ksmbd: preserve VFS inherited P…
In the Linux kernel, the following vulnerability has been resolved: ksmbd: preserve VFS inherited POSIX ACL mask The VFS initializes a child's POSIX ACL from the parent's default ACL and the requested creation mode. Do not mutate the parent ACL or overwrite the child's VFS-computed access and default ACLs afterwards. This preserves restrictive ACL_MASK entries and prevents SMB object creation f…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93787] In the Linux kernel, the following vulnerability has been resolved: smb: client: bound dirent name …
In the Linux kernel, the following vulnerability has been resolved: smb: client: bound dirent name against end of SMB response in cifs_filldir cifs_filldir() copies the entry name out of an SMB1 TRANS2_FIND_FIRST / FIND_NEXT response using a length (de.namelen) supplied by the server. The kmalloc'd SMB response buffer is bounded, but nothing checks that de.name + de.namelen still lies inside tha…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93790] In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix out-of-…
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif mvmsta->tid_data was indexed by the TFD loop counter 'i' instead of the actual TID value 'tid'. This writes lq_color into a random tid_data slot unrelated to the BA entry. Since multi-TID blockack is not really in use, 'i' was always 0 and no harm was done. Add a …
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93288] In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: wait …
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state sashiko reports: "nfnl_log_net_exit() calls nf_log_unset(), which clears the logger pointer without an RCU grace period. Immediately after, ops_free_list() frees the per-net state while concurrent packets might still be executing nf_log_packet() und…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93782] In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: flush backend after…
In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: flush backend after device ioctls vhost-scsi translates guest response descriptors into userspace iovecs when commands are submitted. Target-core completes those commands asynchronously, so VHOST_SET_MEM_TABLE can replace the memory table while an in-flight command still retains response iovecs translated through th…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93284] In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: dma-unmap pages be…
In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: dma-unmap pages before handling migration errors drm_pagemap_migrate_unmap_pages() relies on the pages array to determine which pages require DMA unmapping. However, drm_pagemap_migration_unlock_put_pages() clears the array as part of its cleanup, leaving drm_pagemap_migrate_unmap_pages() with no valid page informat…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93287] In the Linux kernel, the following vulnerability has been resolved: i2c: smbus: reject oversized bl…
In the Linux kernel, the following vulnerability has been resolved: i2c: smbus: reject oversized block transfers in the common path The SMBus block transfer length data->block[0] is validated in i2c_smbus_xfer_emulated() but that check runs too late for tracepoints and is skipped entirely when the adapter provides a native smbus_xfer implementation. This allows user-controlled oversized block le…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93280] In the Linux kernel, the following vulnerability has been resolved: greybus: audio: bound the topol…
In the Linux kernel, the following vulnerability has been resolved: greybus: audio: bound the topology section sizes against the fetched size gb_audio_gb_get_topology() fetches a topology blob of a module-supplied size, and gbaudio_tplg_parse_data() then walks it by adding the module-supplied size_dais, size_controls and size_widgets fields to form the control, widget and route section offsets. …
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93282] In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed acce…
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL permission check looks for an ACE matching the current user and falls back to the Everyone ACE. It does not consider an Authenticated Users ACE, even though an authenticated session is a member of that well-known group. As a result, opening a file whose access is granted through…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93277] In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Validate udata be…
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Validate udata before executing commands The destroy callbacks currently zero the udata output after tearing down driver resources. If the userspace access fails, uverbs preserves the uobject and allows the destroy callback to run again, even though the driver resource has already been freed. Call ib_no_udata_io()…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93265] In the Linux kernel, the following vulnerability has been resolved: PCI/pwrctrl: tc9563: Fix parsin…
In the Linux kernel, the following vulnerability has been resolved: PCI/pwrctrl: tc9563: Fix parsing the integrated Ethernet MAC Endpoint node DSP3 has an integrated Ethernet MAC Endpoint which has its own set of config registers for configuring settings such as ASPM. The Endpoint device has two physical functions and those two functions share the same settings. Parse the Endpoint node under DS…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93260] In the Linux kernel, the following vulnerability has been resolved: powerpc/xive: propagate IPI ini…
In the Linux kernel, the following vulnerability has been resolved: powerpc/xive: propagate IPI init errors to prevent use-after-free When xive_init_ipis() fails (e.g. irq_domain_alloc_irqs() fails), the error path frees the global xive_ipis array. However, xive_smp_probe() previously ignored this failure and proceeded to call xive_setup_cpu_ipi(), which dereferences the already-freed xive_ipis…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93262] In the Linux kernel, the following vulnerability has been resolved: md/raid5-ppl: fix use-after-fre…
In the Linux kernel, the following vulnerability has been resolved: md/raid5-ppl: fix use-after-free in ppl_do_flush() The loop in ppl_do_flush() continues iterating after calling ppl_io_unit_finished(), touching io->pending_flushes and leading to a use-after-free. Add a break statement to stop the loop once io is freed.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93250] In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix use-after-free …
In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix use-after-free in vxlan_mdb_flush() vxlan_mdb_flush() iterates over the MDB entries using hlist_for_each_entry_safe(), which only tolerates the removal of the current entry. Contrary to the comment above the loop, the removal of an entry can trigger the removal of another entry. Flushing the remotes of a (*, G) …
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93237] In the Linux kernel, the following vulnerability has been resolved: LoongArch: Add DIRECT_MAP_PHYSM…
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Add DIRECT_MAP_PHYSMEM_END definition get_free_mem_region() and mhp_get_pluggable_range() bound their search to DIRECT_MAP_PHYSMEM_END. LoongArch does not define it, so the fallback in include/linux/mm.h applies: under CONFIG_SPARSEMEM_VMEMMAP it is (1ULL

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93229] In the Linux kernel, the following vulnerability has been resolved: nfsd: add missing read barrier …
In the Linux kernel, the following vulnerability has been resolved: nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry The hand-rolled seqcount-like protocol in nfsd_nl_rpc_status_get_dumpit() is missing a read memory barrier (smp_rmb) before its second counter check. The standard kernel read_seqcount_retry() includes smp_rmb() to ensure that all data reads complete before t…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93221] In the Linux kernel, the following vulnerability has been resolved: nfsd: convert nfsd_net boolean …
In the Linux kernel, the following vulnerability has been resolved: nfsd: convert nfsd_net boolean flags to unsigned long flags word nfsd_net contains several boolean fields that are accessed from concurrent contexts without serialization. In particular, nfsd4_end_grace() guards its drain path with a plain bool: if (nn->grace_ended) return; nn->grace_ended = true; The read…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93224] In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix unmatched rn_unreg…
In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix unmatched rn_unregister on failed accept When svc_rdma_accept() takes the errout path before rpcrdma_rn_register() has succeeded, the existing cleanup block calls rpcrdma_rn_unregister(dev, &newxprt->sc_rn) unconditionally. svcxprt_rdma is kzalloc'd, so on that path sc_rn.rn_index is 0 and sc_rn.rn_done is NULL; the…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93225] In the Linux kernel, the following vulnerability has been resolved: phy: fsl-imx8mq-usb: fix typec …
In the Linux kernel, the following vulnerability has been resolved: phy: fsl-imx8mq-usb: fix typec switch leak on probe error path If probe fails after imx95_usb_phy_get_tca() succeeds, the typec switch leaks because the only cleanup path was in .remove(), which never runs on probe failure. Use devm_add_action_or_reset() so the switch is cleaned up on both probe failure and driver removal. The …
M Alto vulnerabilidad
23/09/2026
Vulnerabilidad alta de desreferencia NULL en ASR Crane/Falcon (módulo as_rrc) en Linux
Se identificó una vulnerabilidad de desreferencia de puntero NULL en ASR Crane y ASR Falcon para sistemas Linux, específicamente en el módulo as_rrc ubicado en 3g.mod/lib/src/urrsir.c. Esta falla permite manipulación de punteros que podría resultar en ejecución de código no autorizado o denegación de servicio en servidores de telecomunicaciones y infraestructura de red alta. El CVSS de 7.4 indica severidad alta que afecta directamente servicios de conectividad en empresas LATAM.