Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Linux" — 1392 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
09/09/2026
[CVE-2026-80921] In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale cry…
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available. Zero out the remaining bits.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-80924] In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - use kfree_sensit…
In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - use kfree_sensitive() for derived key buffers crypto_krb5_prepare_encryption() and crypto_krb5_prepare_checksum() free the buffer holding the freshly derived keys with plain kfree(), leaving the key material behind in the freed slab object.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-80914] In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix use-after-f…
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready iso_conn_ready() looks up the BIS listener socket with iso_get_sock(), which takes a reference, and then, without re-checking its state, creates a child socket from it: parent = iso_get_sock(hdev, ...); if (!parent) return; lock_sock(pa…
P Alto vulnerabilidad
09/09/2026
CVE-2026-0305 Prisma Access Agent: Information Disclosure Vulnerability on Linux
Palo Alto Networks PSIRT publica advisory de seguridad: CVE-2026-0305 Prisma Access Agent: Information Disclosure Vulnerability on Linux (Severity: MEDIUM). Tipo: Divulgación de Información. Producto afectado: Prisma Access.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-47625] NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse miss…
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-16497] NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause exce…
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85656] An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.…
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80753] In the Linux kernel, the following vulnerability has been resolved: ovpn: run deferred work on a mo…
In the Linux kernel, the following vulnerability has been resolved: ovpn: run deferred work on a module-owned workqueue ovpn queues several work items whose callbacks execute module text. These works currently run on the global system workqueues, so module exit has no driver-owned drain point that guarantees the callbacks have fully returned before the module text can be freed. Object reference…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80754] In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - fix F55…
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - fix F55 transmitter electrode count typo During F55 sensor detection, the transmitter (TX) electrode count was incorrectly assigned the value of the receiver (RX) electrode count due to copy-paste typos. This incorrect value was then propagated to the driver data and used by F54 to determine the diagnost…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80745] In the Linux kernel, the following vulnerability has been resolved: regulator: fp9931: Fix VPOS/VNE…
In the Linux kernel, the following vulnerability has been resolved: regulator: fp9931: Fix VPOS/VNEG voltage selector table The VPOSNEG_table[] mapping does not match the FP9931 datasheet. The datasheet defines the VPOS/VNEG voltage mapping as: 00h-04h -> 7.04V (-7.04V) 05h -> 7.26V (-7.26V) 06h -> 7.49V (-7.49V) ... 28h-3Fh -> 15.06V (-15.06V) However, VPOSNEG_table[] ha…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80747] In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add bounds check fo…
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add bounds check for CRAT subtype length The CRAT parser validates that the subtype header fits within the image, but does not verify that the advertised subtype length fits. A malformed CRAT table with an oversized length field causes out-of-bounds reads when kfd_parse_subtype() casts the header to specific subtype …
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80748] In the Linux kernel, the following vulnerability has been resolved: mmc: loongson2: Fix sg iteratio…
In the Linux kernel, the following vulnerability has been resolved: mmc: loongson2: Fix sg iteration in data reorder functions In ls2k0500_mmc_reorder_cmd_data() and ls2k2000_mmc_reorder_cmd_data(), the for_each_sg() macro already iterates over the scatterlist entries, with 'sg' pointing to the current entry. However, the code incorrectly uses '&sg[i]' and 'sg_dma_len(&sg[i])' inside the loop, w…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80749] In the Linux kernel, the following vulnerability has been resolved: drm/connector/hdmi: Fix out of …
In the Linux kernel, the following vulnerability has been resolved: drm/connector/hdmi: Fix out of bounds memory read A helper function was copying a given audio infoframe into the connector's copy but using the size of the destination (a generic target, sized to accept many different data blocks) not the source (a very specific type of data block). Thus, it was copying 60 bytes of data from a 2…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80750] In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix remaini…
In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix remaining %pOF after of_node_put() scpsys_get_bus_protection_legacy() looks up several legacy bus protection regmaps from device-tree nodes. Two error paths put the device node before checking whether the regmap lookup failed, but still pass that node to dev_err_probe() with %pOF on failure. If of_node_p…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80751] In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: mfg: initia…
In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev() mtk_mfg_attach_dev() reads prev_o on the first iteration of its loop, in "if (prev_o && prev_o->freq == o->freq)", before prev_o is assigned at the end of the loop body. On that first iteration, evaluating prev_o reads an indeterminate value. If it is non-NULL, t…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80752] In the Linux kernel, the following vulnerability has been resolved: Input: psxpad-spi - set driver …
In the Linux kernel, the following vulnerability has been resolved: Input: psxpad-spi - set driver data before use psxpad_spi_suspend() retrieves the controller state with spi_get_drvdata(), but probe never stores it, so suspend dereferences a NULL pointer. Store it during probe.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80741] In the Linux kernel, the following vulnerability has been resolved: drm/log: Fix out-of-bounds read…
In the Linux kernel, the following vulnerability has been resolved: drm/log: Fix out-of-bounds read on empty message length drm_log_draw_kmsg_record() accesses s[len - 1] to strip the trailing newline, but len is unsigned int. If len is 0, the subtraction wraps to UINT_MAX, causing an out-of-bounds read. Add an early return when len is 0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80734] In the Linux kernel, the following vulnerability has been resolved: btrfs: initialize inode mapping…
In the Linux kernel, the following vulnerability has been resolved: btrfs: initialize inode mapping flags for cached inodes [BUG] When running generic/795 with 8K block size, 4K page size, the test always fails, triggering some ASSERT()s related to folio size: 795 (241074): drop_caches: 3 assertion failed: IS_ALIGNED(start, blocksize) && IS_ALIGNED(end + 1, blocksize), in extent_io.c:1404 (…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80735] In the Linux kernel, the following vulnerability has been resolved: ovpn: ensure socket is owned by…
In the Linux kernel, the following vulnerability has been resolved: ovpn: ensure socket is owned by ovpn before deref sk_user_data Some subsystems, like BPF SOCKMAP, set sk_user_data without actually setting the encap_type. For this reason, we must make sure that the type is the one ovpn expects before dereferencing sk_user_data. Failing to do so may lead to out-of-bounds reads.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80736] In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Fix bandwidth grou…
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Fix bandwidth group reservation indexing Valid bandwidth group IDs range from 1 through MAX_GROUPS, while Group ID 0 is reserved. tb_consumed_dp_bandwidth() uses the Group ID directly to index its local group_reserved[] array. The array currently has MAX_GROUPS entries, so its valid indices are 0 through MAX_GROUPS…