Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-64517

Fecha de publicación:
25/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/xe/gsc: Fix double-free of managed BO in error path<br /> <br /> The error path in xe_gsc_init_post_hwconfig() explicitly frees a BO<br /> allocated with xe_managed_bo_create_pin_map() via<br /> xe_bo_unpin_map_no_vm(). Since the managed BO already has a devm<br /> cleanup action registered, this causes a double-free when devm<br /> unwinds during probe failure.<br /> <br /> Remove the explicit free and let devm handle it, consistent with<br /> all other xe_managed_bo_create_pin_map() callers.<br /> <br /> (cherry picked from commit 71d61e3e299a17139e47f980a4d6f425b2c59bf7)
Gravedad: Pendiente de análisis
Última modificación:
25/07/2026

CVE-2026-64501

Fecha de publicación:
25/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> iio: adc: ad_sigma_delta: fix CS held asserted and state leaks<br /> <br /> In ad_sigma_delta_single_conversion(), set_mode(AD_SD_MODE_IDLE) and<br /> disable_one() were called from the out: block while keep_cs_asserted<br /> was still true. This caused any SPI transfer issued by those callbacks<br /> to carry cs_change=1, leaving CS permanently asserted after the<br /> conversion. Fix by moving both calls into the out_unlock: block, after<br /> keep_cs_asserted is cleared, matching the pattern already used in<br /> ad_sd_calibrate().<br /> <br /> In the error path of ad_sd_buffer_postenable(), if an operation fails<br /> after set_mode(AD_SD_MODE_CONTINUOUS) has already succeeded (e.g.<br /> spi_offload_trigger_enable()), the device is left in continuous<br /> conversion mode with CS physically asserted. Additionally,<br /> bus_locked remaining true after spi_bus_unlock() causes subsequent<br /> SPI operations to call spi_sync_locked() without the bus lock actually<br /> held, allowing concurrent SPI access.<br /> <br /> Fix the error path by clearing keep_cs_asserted first, then calling<br /> set_mode(AD_SD_MODE_IDLE) to revert the device mode and deassert CS,<br /> then clearing bus_locked before releasing the bus.<br /> <br /> For devices that implement neither set_mode nor disable_one (such as<br /> MAX11205, which has no physical CS pin), no SPI transfer is issued<br /> during cleanup and the cs_change flag has no effect on any physical<br /> line.
Gravedad: Pendiente de análisis
Última modificación:
25/07/2026

CVE-2026-64502

Fecha de publicación:
25/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices<br /> <br /> ad_sigma_delta_clear_pending_event() falls through to the status register<br /> read path for devices with has_registers = false and no rdy_gpiod. For<br /> such devices, ad_sd_read_reg() skips the address byte entirely and clocks<br /> raw MISO bytes with no address phase — making it byte-for-byte identical<br /> to reading conversion data. If a pending conversion result is present,<br /> this partially consumes it and corrupts the data stream for the subsequent<br /> ad_sd_read_reg() call in ad_sigma_delta_single_conversion().<br /> <br /> Furthermore, with num_resetclks = 0 on these devices, data_read_len<br /> evaluates to 0. If the clocked byte has bit 7 clear, pending_event is set<br /> and the code attempts memset(data + 2, 0xff, 0 - 1), overflowing to<br /> SIZE_MAX and corrupting the heap.<br /> <br /> Fix by returning 0 immediately when neither rdy_gpiod nor has_registers<br /> is set. This is safe for all current registerless devices: ad7191 and<br /> ad7780 (with powerdown GPIO) are reset between conversions by CS<br /> deassertion, so there is no stale result to drain; ad7780 (without<br /> powerdown GPIO) and max11205 are continuously-converting and cycle ~DRDY<br /> at the output data rate regardless of whether the previous result was<br /> read, so the next falling edge fires naturally.<br /> <br /> A future registerless device that holds ~DRDY asserted until data is read<br /> would be broken by this early return and would require either<br /> num_resetclks set or a rdy-gpio.<br /> <br /> The same heap corruption is reachable on any device with rdy_gpiod set<br /> but num_resetclks = 0: if the GPIO indicates a pending event, the drain<br /> path executes memset(data + 2, 0xff, 0 - 1) regardless of has_registers.<br /> Add an explicit data_read_len == 0 guard after the pending event check;<br /> the stale result is then consumed by the first ad_sd_read_reg() call in<br /> ad_sigma_delta_single_conversion().
Gravedad: Pendiente de análisis
Última modificación:
25/07/2026

CVE-2026-64503

Fecha de publicación:
25/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error<br /> <br /> kxsd9_write_raw() takes a runtime PM reference with pm_runtime_get_sync()<br /> but returns -EINVAL directly when a scale with a non-zero integer part is<br /> requested, skipping the matching pm_runtime_put_autosuspend(). This leaks<br /> a runtime PM usage-counter reference on every such write, after which the<br /> device can no longer autosuspend.<br /> <br /> Set the error code and fall through to the existing put instead of<br /> returning early.
Gravedad: Pendiente de análisis
Última modificación:
25/07/2026

CVE-2026-64504

Fecha de publicación:
25/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> iio: accel: bmc150: clamp the device-reported FIFO frame count<br /> <br /> __bmc150_accel_fifo_flush() copies the number of samples the device<br /> reports in its hardware FIFO into an on-stack buffer<br /> <br /> u16 buffer[BMC150_ACCEL_FIFO_LENGTH * 3];<br /> <br /> which is sized for at most BMC150_ACCEL_FIFO_LENGTH (32) samples. The<br /> frame count is read from the FIFO_STATUS register and only masked to its<br /> 7 valid bits:<br /> <br /> count = val &amp; 0x7F;<br /> <br /> so it can be 0..127. The only other limit applied to it is the optional<br /> caller-supplied sample budget:<br /> <br /> if (samples &amp;&amp; count &gt; samples)<br /> count = samples;<br /> <br /> which does not constrain count on the flush-all path (samples == 0), and<br /> leaves it well above 32 whenever samples is larger. count samples are<br /> then transferred into buffer[]:<br /> <br /> bmc150_accel_fifo_transfer(data, (u8 *)buffer, count);<br /> <br /> bmc150_accel_fifo_transfer() reads count * 6 bytes through regmap, so a<br /> malfunctioning, malicious or counterfeit accelerometer (or an attacker<br /> tampering with the I2C/SPI bus) that reports up to 127 frames writes up<br /> to 762 bytes into the 192-byte buffer: a stack out-of-bounds write of up<br /> to 570 bytes that clobbers the stack canary, saved registers and the<br /> return address.<br /> <br /> Clamp count to BMC150_ACCEL_FIFO_LENGTH, the number of samples buffer[]<br /> is sized for, before the transfer, mirroring the watermark clamp already<br /> done in bmc150_accel_set_watermark(). A well-formed flush reports at most<br /> BMC150_ACCEL_FIFO_LENGTH frames, so legitimate devices are unaffected.
Gravedad: Pendiente de análisis
Última modificación:
25/07/2026

CVE-2026-64505

Fecha de publicación:
25/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> usb: gadget: function: rndis: add length check for header<br /> <br /> Add a length check for the rndis header in rndis_rm_hdr, to ensure that<br /> MessageType, MessageLength, DataOffset, and DataLength fields are<br /> present before they are accessed.
Gravedad: Pendiente de análisis
Última modificación:
25/07/2026

CVE-2026-64506

Fecha de publicación:
25/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> wifi: rtw89: correct drop logic for malformed AMPDU frames<br /> <br /> The previous commit aims to fix issue caused by malformed AMPDU frames.<br /> But the drop logic fails to deal with the first AMPDU packet paired with<br /> certain range of sequence number, and leads to unexpected packet drop.<br /> It is more likely to encounter this failure when there are busy traffic<br /> during rekey process and could lead to disconnection from the AP.<br /> Fix this by adding a initial state judgement and only reset status<br /> during pairwise rekey.
Gravedad: Pendiente de análisis
Última modificación:
25/07/2026

CVE-2026-64507

Fecha de publicación:
25/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> x86/bugs: Enable IBPB flush on BPF JIT allocation<br /> <br /> Enable hardening against JIT spraying when Spectre-v2 mitigations are in<br /> use. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip<br /> enabling the IBPB flush if the BPF dispatcher is already using a retpoline<br /> sequence.<br /> <br /> This hardening applies only when BPF-JIT is in use. Guard the enabling<br /> under CONFIG_BPF_JIT so that bugs.c still builds with CONFIG_BPF_JIT=n.
Gravedad: Pendiente de análisis
Última modificación:
25/07/2026

CVE-2026-64508

Fecha de publicación:
25/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> bpf: Support for hardening against JIT spraying<br /> <br /> The BPF JIT allocator packs many small programs into larger executable<br /> allocations and reuses space within those allocations as programs are<br /> loaded and freed. When fresh code is written into space that a previous<br /> program occupied, an indirect jump into the new program can reuse a branch<br /> prediction left behind by the old one.<br /> <br /> Flush the indirect branch predictors before reusing JIT memory so that<br /> indirect jumps into a newly written program don&amp;#39;t reuse predictions from an<br /> old program that occupied the same space.<br /> <br /> Introduce bpf_arch_pred_flush_enabled static key and bpf_arch_pred_flush<br /> static call for flushing the branch predictors on JIT memory reuse.<br /> Architectures that need a flush, can update it to a predictor flush<br /> function. By default, its a NOP and does not emit any CALL.<br /> <br /> Allocations larger than a pack are not covered by this flush. That is safe<br /> because cBPF programs (the unprivileged attack surface) are bounded well<br /> below a pack size. Issue a warning if this assumption is ever violated<br /> while the flush is active.
Gravedad: Pendiente de análisis
Última modificación:
25/07/2026

CVE-2026-64492

Fecha de publicación:
25/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> iio: temperature: tmp006: use devm_iio_trigger_register<br /> <br /> tmp006_probe() allocates the DRDY trigger with devm_iio_trigger_alloc()<br /> but registers it with plain iio_trigger_register(). The driver has no<br /> .remove() callback, so on module unload the trigger stays in the global<br /> trigger list while its memory is freed by devm, leaving a dangling<br /> entry.<br /> <br /> Switch to devm_iio_trigger_register() so the registration is undone in<br /> the same devm scope as the allocation.
Gravedad: Pendiente de análisis
Última modificación:
25/07/2026

CVE-2026-64493

Fecha de publicación:
25/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> iio: pressure: mpl115: fix runtime PM leak on read error<br /> <br /> mpl115_read_raw() takes a runtime PM reference with pm_runtime_get_sync()<br /> before reading the processed pressure or raw temperature, but on the read<br /> error path it returns without calling pm_runtime_put_autosuspend(). Each<br /> failed read therefore leaks a runtime PM reference and prevents the device<br /> from autosuspending.<br /> <br /> Drop the reference before checking the return value so both the success<br /> and error paths are balanced.
Gravedad: Pendiente de análisis
Última modificación:
25/07/2026

CVE-2026-64494

Fecha de publicación:
25/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> iio: light: gp2ap002: fix runtime PM leak on read error<br /> <br /> gp2ap002_read_raw() calls pm_runtime_get_sync() before reading the<br /> lux value, but if gp2ap002_get_lux() fails, it returns directly. This<br /> skips the pm_runtime_put_autosuspend() call at the "out" label,<br /> permanently leaking a runtime PM reference and preventing the device<br /> from autosuspending.<br /> <br /> Replace the direct return with a "goto out" to ensure the reference<br /> is properly dropped on the error path.
Gravedad: Pendiente de análisis
Última modificación:
25/07/2026