Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 50 min
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1253
Esta semana
RSS
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89810] In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix error path at s…
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix error path at svm_migrate_copy_to_ram If page migration from device to sys ram fails for some reasons driver needs release and unlock allocated system pages. To do that driver should use page physical address, or pfn, then get struct page*. Current driver uses dma address(for adev) that is not correct with IOMMU …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89811] In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add TLB flush after…
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add TLB flush after MES queue eviction/suspension MES (Micro Engine Scheduler) does not perform heavy-weight TLB invalidation after unmapping queues, unlike HWS which does this automatically. This causes a race condition where in-flight DMA descriptors can access memory that has been unmapped, leading to page faults …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89814] In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: clamp the isolation…
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: clamp the isolation index for rings outside a partition adev->isolation[] has one slot per partition, but a ring that is not assigned to one keeps AMDGPU_XCP_NO_PARTITION, which is ~0, so indexing the array with it is out of bounds. SDMA submissions hit this on both the isolation enforcement and the VM flush path and…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89815] In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Drop tt->restore after…
In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Drop tt->restore after successful restore ttm_pool_restore_and_alloc() can successfully complete the restore process via ttm_pool_restore_commit(), but tt->restore is not dropped afterward. As a result, subsequent backup/restore flows observe what appears to be a completed restore, while in reality shmem handles are sti…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89803] In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: unsubscribe the ch…
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: unsubscribe the channel-kill event before the fence context nouveau_channel_del() tears the fence context down first and only drops the channel-kill subscription later, in the middle of the nvif object teardown: if (chan->fence) nouveau_fence(chan->cli->drm)->context_del(chan); ... nvif_object_dtor(&chan->vram…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89804] In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/dmem: fix mismatche…
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/dmem: fix mismatched DMA unmap size for large folios Device-private THP migration maps migration buffers with page_size() and records that length in dma_info->size. For a compound folio page_size() is PAGE_SIZE
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89805] In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: Fix folio allocati…
In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: Fix folio allocation fallback and use-after-put drm_pagemap_migrate_populate_ram_pfn() had two issues when populating RAM PFNs with higher-order folios: 1. The higher-order vma_alloc_folio()/folio_alloc() calls did not pass __GFP_NOWARN, so a THP allocation failure under memory pressure would spam the kernel …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89806] In the Linux kernel, the following vulnerability has been resolved: drm/sysfb: ofdrm: Fix integer o…
In the Linux kernel, the following vulnerability has been resolved: drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation The framebuffer size calculation `fb_size = linebytes * height` can overflow when both values are large (e.g., 46341 * 46341 > INT_MAX). Since linebytes and height are both int types, the multiplication is performed as int * int, which results in undefined behavior on…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89808] In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix the case that v…
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram When migration vm range is hole at cpu side(MIGRATE_PFN_MIGRATE set + MIGRATE_PFN_VALID unset) driver still allocates device pages. There is no dma map of src pages and migration. j is 0 and svm_migrate_copy_memory_gart() will return an uninitialized r. T…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89795] In the Linux kernel, the following vulnerability has been resolved: PCI: Allow per function PCI slo…
In the Linux kernel, the following vulnerability has been resolved: PCI: Allow per function PCI slots to fix slot reset on s390 On s390 systems, which use a machine level hypervisor, PCI devices are always accessed through a form of PCI pass-through which fundamentally operates on a per PCI function granularity. This is also reflected in the s390 PCI hotplug driver which creates hotplug slots fo…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89799] In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in bpf_…
In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in bpf_get_stackid The get_perf_callchain call needs disabled preemption plus we need it disabled as long as we access its returned trace entries buffer. Note the bpf_get_stackid_pe function is executed already with preemption disabled.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89801] In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/uvmm: fix premature…
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE In nouveau_uvmm_bind_job_submit()'s OP_UNMAP_SPARSE arm, op->reg is set from nouveau_uvma_region_find(), which only looks the region up and takes no reference; a region's sole reference is its membership in uvmm->region_mt. Two failure paths leave op->reg set:…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89793] In the Linux kernel, the following vulnerability has been resolved: ublk: clear VM_MAYWRITE on read…
In the Linux kernel, the following vulnerability has been resolved: ublk: clear VM_MAYWRITE on read-only ublk char device mmap ublk_ch_mmap() rejects mmap requests with VM_WRITE set, but never clears VM_MAYWRITE on the resulting read-only mapping. This allows a userspace daemon to mmap the per-queue command buffer PROT_READ, then upgrade it to PROT_WRITE via mprotect(), since VM_MAYWRITE was nev…
M Alto vulnerabilidad
16/09/2026
Vulnerabilidad alta en Arista EOS OSPFv3: reinicio no autorizado de agente
Una vulnerabilidad en Arista EOS con OSPFv3 configurado (CVSS 7.5) permite que paquetes especialmente crafteados causen el reinicio inesperado del agente OSPFv3, interrumpiendo la disponibilidad de enrutadores en infraestructuras altas. El impacto afecta principalmente a operadores de redes en centros de datos y proveedores de conectividad en LATAM que dependen de equipos Arista para su backbone de red.
M Alto vulnerabilidad
16/09/2026
Vulnerabilidad alta en Arista EOS con OSPFv2 permite denegación de servicio en redes
Arista EOS es vulnerable a packets OSPFv2 especialmente diseñados que pueden ser enviados por atacantes no autenticados en el mismo segmento de broadcast. La vulnerabilidad provoca inestabilidad en adyacencias OSPF y pérdida de paquetes, disrumpiendo el enrutamiento en dominios OSPF amplios. En infraestructuras altas de LATAM (telecomunicaciones, finanzas, energía) esto compromete la disponibilidad de servicios de red.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89792] In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds re…
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config responses Validate IPC share configuration payload sizes before consuming variable-length fields. Bound veto list parsing and account for the separator byte when deriving the path length.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89789] In the Linux kernel, the following vulnerability has been resolved: gtp: add synchronize_net() in g…
In the Linux kernel, the following vulnerability has been resolved: gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free gtp_newlink()'s error path frees tid_hash and addr_hash without waiting for an RCU grace period after clearing sk_user_data. A concurrent gtp_encap_recv() in softirq may still hold the gtp_dev pointer obtained via rcu_dereference_sk_user_data() and …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89791] In the Linux kernel, the following vulnerability has been resolved: perf: Fix use-after-free when p…
In the Linux kernel, the following vulnerability has been resolved: perf: Fix use-after-free when perf mmap() revival races with the last munmap() perf_mmap_close() drops rb->mmap_count *without* holding event->mmap_mutex (the refcount_dec_and_test() right before the refcount_dec_and_mutex_lock() of event->mmap_count). A concurrent perf_mmap_rb() can slot its entire "revival" path into that wind…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89777] In the Linux kernel, the following vulnerability has been resolved: vfio/pci: clear vdev->msi_perm …
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: clear vdev->msi_perm after freeing it on init failure vfio_msi_cap_len() lazily allocates the per-device MSI permission table: vdev->msi_perm = kmalloc_obj(struct perm_bits, GFP_KERNEL_ACCOUNT); if (!vdev->msi_perm) return -ENOMEM; ret = init_pci_cap_msi_perm(vdev->msi_perm, len, flags); if (ret) { kfree(vdev…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89781] In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds rea…
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() read_log_rec_buf() copies a log record into a caller buffer starting at u32 off = lsn_to_page_off(log, lsn) + log->record_header_len; log->record_header_len (and log->data_off, used for the following pages) comes verbatim from the on-disk restart area and is only checked …