Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-89739

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition<br /> <br /> In dwc3_gadget_init_endpoint, &amp;dep-&gt;nostream_work is bound with<br /> dwc3_nostream_work, and dwc3_gadget_endpoint_stream_event can queue<br /> this delayed work on system_percpu_wq when a DEPEVT_STREAM_NOSTREAM<br /> event is received.<br /> <br /> If we remove the gadget, dwc3_gadget_free_endpoints makes cleanup and<br /> the memory allocated for dep with kzalloc() is released by kfree(dep),<br /> while the delayed work mentioned above may still be pending or<br /> running. The sequence of operations that may lead to a UAF bug is as<br /> follows:<br /> <br /> CPU0 CPU1<br /> <br /> | dwc3_thread_interrupt<br /> | dwc3_endpoint_interrupt<br /> | dwc3_gadget_endpoint_stream_event<br /> | queue_delayed_work(system_percpu_wq,<br /> | &amp;dep-&gt;nostream_work)<br /> dwc3_gadget_free_endpoints |<br /> dwc3_free_trb_pool(dep) |<br /> list_del(&amp;dep-&gt;endpoint.ep_list) |<br /> dwc3_debugfs_remove_endpoint_dir(dep) |<br /> kfree(dep) |<br /> // dep is freed |<br /> | dwc3_nostream_work<br /> | // use dep (use-after-free)<br /> <br /> Fix it by canceling the delayed work before kfree(dep) in<br /> dwc3_gadget_free_endpoints.
Gravedad: Pendiente de análisis
Última modificación:
03/10/2026

CVE-2026-89731

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read<br /> <br /> cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from<br /> the RCRB MMIO block using a readl() loop bounded by sizeof(struct<br /> aer_capability_regs). This struct is a software layout and its embedded<br /> struct pcie_tlp_log is larger than the on-wire AER capability. As a<br /> result the loop reads past the mapped AER register block.<br /> <br /> The over-read also populates the software-only tail fields including<br /> header_log.header_len. An out-of-range header_len passed to<br /> pcie_print_tlp_log() can then loop past the header log buffer and cause<br /> a second out-of-bounds read.<br /> <br /> The read was correct when introduced, but struct pcie_tlp_log has since<br /> grown (Header Log and TLP Prefix Log sizes, header_len and flit fields),<br /> so sizeof(struct aer_capability_regs) no longer matches the physical AER<br /> capability.<br /> <br /> Bound the read to the physical AER registers, header through the 16 byte<br /> Header Log. Zero the destination first so the software-only fields are<br /> deterministic.
Gravedad CVSS v3.1: ALTA
Última modificación:
21/09/2026

CVE-2026-89719

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> zram: fix out-of-bounds access in read_block_state()<br /> <br /> read_block_state() calculates nr_pages before taking dev_lock. If the<br /> device is reset and reinitialized with a smaller disksize before lock<br /> acquisition, nr_pages still describes the old table. The subsequent loop<br /> can then call slot_lock() past the end of the newly allocated table.<br /> <br /> Read disksize after acquiring dev_lock and checking that the device is<br /> initialized. The read lock then keeps the table and its bound stable for<br /> the duration of the scan.
Gravedad: Pendiente de análisis
Última modificación:
21/09/2026

CVE-2026-89717

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> zram: set default primary compressor in zram_destroy_comps()<br /> <br /> Patch series "zram: fix zram issues reported by sashiko".<br /> <br /> Sashiko drove by and reported [1] a couple of zram issues:<br /> a possible BUG_ON() in zlib code due to missing winbits range<br /> validation and one possible NULL-ptr dereference in zcomp.<br /> Both are low risk yet still worth fixing.<br /> <br /> <br /> This patch (of 2):<br /> <br /> zram_destroy_comps() resets all compressors and leaves them set to NULL,<br /> including the primary one, which is invalid device state, as now<br /> comp_algorithm_show()-&gt;strcmp() can be called on a NULL compressor. Set<br /> default primary compressor in zram_destroy_comps().
Gravedad: Pendiente de análisis
Última modificación:
21/09/2026

CVE-2026-89718

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> zram: fix out-of-bounds access in writeback_store()<br /> <br /> Patch series "zram: fix stale scan bounds after reinitialization".<br /> <br /> Both writeback_store() and read_block_state() derive their table scan<br /> bounds from zram-&gt;disksize before acquiring dev_lock. If the device is<br /> reset and reinitialized with a smaller disksize between that read and lock<br /> acquisition, the bound can describe the old table while the scan operates<br /> on the new one. This can lead to out-of-bounds slot accesses.<br /> <br /> Move both bound calculations under dev_lock so each bound remains<br /> consistent with the table throughout its scan. Keep the fixes separate<br /> because the affected interfaces originate from different commits and can<br /> be backported independently.<br /> <br /> <br /> This patch (of 2):<br /> <br /> writeback_store() calculates the table scan bounds before taking dev_lock.<br /> A reset followed by reconfiguration with a smaller disksize can therefore<br /> replace zram-&gt;table while writeback_store() is waiting for the lock. Once<br /> it acquires the lock, it sees an initialized device but scans the new<br /> table using the old upper bound, resulting in an out-of-bounds access.<br /> <br /> Calculate the number of pages while holding dev_lock so the scan bound<br /> matches the table protected by the lock.
Gravedad: Pendiente de análisis
Última modificación:
21/09/2026

CVE-2026-89708

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown<br /> <br /> After a DESTROY_SESSION the per-session teardown path can free a<br /> session while rpciod still holds an inflight callback rpc_task that<br /> dereferences clp-&gt;cl_cb_session. nfsd4_probe_callback_sync() flushes<br /> cl_callback_wq, but once nfsd4_run_cb_work() has called<br /> rpc_call_async() the rpc_task lives on rpciod; flushing the workqueue<br /> does not wait for it. rpc_shutdown_client() does drain rpciod tasks,<br /> but uses a 1-second wait_event_timeout — tasks stuck in rpc_delay()<br /> (e.g. 2-second NFS4ERR_DELAY retries) can outlive the drain.<br /> <br /> destroy path rpciod<br /> ------------ ------<br /> unhash_session(ses)<br /> nfsd4_probe_callback_sync(clp)<br /> flush_workqueue(cl_callback_wq)<br /> /* returns; rpc_task still live */<br /> nfsd4_put_session_locked(ses)<br /> free_session(ses) -&gt; kfree(ses)<br /> nfsd4_cb_sequence_done()<br /> reads cb_clp-&gt;cl_cb_session<br /> /* freed slab */<br /> <br /> A second window exists in nfsd4_process_cb_update(). When<br /> __nfsd4_find_backchannel() returns NULL because unhash_session() has<br /> already removed the destroyed session from cl_sessions,<br /> setup_callback_client() takes the v4.1 early return so<br /> clp-&gt;cl_cb_session = ses never fires and the field retains a pointer<br /> to the about-to-be-freed session.<br /> <br /> Fix both by converting cl_cb_session to an RCU-protected pointer:<br /> <br /> - Move the cl_cb_session = ses assignment in setup_callback_client()<br /> to after rpc_create() succeeds, so it is only published when a<br /> working backchannel exists. Clear cl_cb_session on the error<br /> return in nfsd4_process_cb_update(). Both stores use<br /> rcu_assign_pointer().<br /> <br /> - Annotate cl_cb_session with __rcu. All rpciod-side readers use<br /> rcu_read_lock()/rcu_dereference() and check for NULL, bailing to<br /> the appropriate error or requeue path:<br /> encode_cb_sequence4args(), decode_cb_sequence4resok(),<br /> nfsd41_cb_get_slot(), nfsd41_cb_release_slot(),<br /> nfsd4_cb_prepare(), and nfsd4_cb_sequence_done().<br /> <br /> - Switch __free_session() from kfree() to kfree_rcu() so the<br /> session slab is not reclaimed until after an RCU grace period,<br /> guaranteeing that rpciod readers inside rcu_read_lock() never<br /> dereference freed memory.<br /> <br /> - Pass the session pointer to the nfsd_cb_seq_status and<br /> nfsd_cb_free_slot tracepoints instead of having them re-read<br /> cl_cb_session.<br /> <br /> - nfsd4_cb_prepare() calls rpc_exit() when the session is NULL,<br /> routing through the done/release path to requeue the callback.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
21/09/2026

CVE-2026-89700

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfsd: validate sockaddr length per family in listener_set<br /> <br /> nfsd_sock_nl_policy declares NFSD_A_SOCK_ADDR as a bare NLA_BINARY<br /> attribute with no minimum length. A CAP_NET_ADMIN caller can send a<br /> 16-byte NFSD_A_SOCK_ADDR with sa_family=AF_INET6, causing a 12-byte<br /> OOB read across three consumers (rpc_cmp_addr_port, svc_find_listener,<br /> kernel_bind).<br /> <br /> nfsd_nl_listener_set_doit() also parsed and validated each listener<br /> entry inline in two separate loops, interleaved with mutating the<br /> running listener configuration. The validation was duplicated, used an<br /> open-coded "nla_len
Gravedad: Pendiente de análisis
Última modificación:
21/09/2026

CVE-2026-89693

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()<br /> <br /> nfsd4_create() stores the return value of nfsd4_acl_to_attr() in<br /> status, but the switch(create-&gt;cr_type) block unconditionally<br /> overwrites it in every branch. ACL translation errors are silently<br /> discarded, and the CREATE proceeds without the requested ACL.<br /> <br /> Add an early exit check after nfsd4_acl_to_attr(), matching the<br /> pattern already used in nfsd4_setattr().<br /> <br /> [ cel: prefer NFS4ERR_BADTYPE over NFS4ERR_ATTRNOTSUPP ]
Gravedad: Pendiente de análisis
Última modificación:
21/09/2026

CVE-2026-89698

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage<br /> <br /> struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain<br /> "struct sockaddr" (16 bytes). When an IPv6 NFS client is connected,<br /> nfsd_genl_rpc_status_compose_msg() casts these fields to<br /> "struct sockaddr_in6 *" (28 bytes) and reads sin6_addr at offset 8..24,<br /> which extends 8 bytes past the end of the 16-byte sockaddr field into<br /> the adjacent rq_flags member. The 16-byte nla_put_in6_addr then ships 8<br /> bytes of truncated IPv6 address followed by 8 bytes of rq_flags to<br /> userspace via the NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes.<br /> <br /> This is reachable by any unprivileged process in the network namespace<br /> because NFSD_CMD_RPC_STATUS_GET uses GENL_CMD_CAP_DUMP without<br /> GENL_ADMIN_PERM.<br /> <br /> Fix by widening rq_daddr and rq_saddr to struct sockaddr_storage so the<br /> IPv6 casts operate within bounds, copying sizeof(struct sockaddr_storage)<br /> bytes in the memcpy calls so the full address is captured, and<br /> zero-initializing the genl_rqstp stack variable to prevent leaking<br /> uninitialized tail bytes through netlink.
Gravedad: Pendiente de análisis
Última modificación:
21/09/2026

CVE-2026-89685

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfsd: fix clock domain mismatch in clients_still_reclaiming()<br /> <br /> clients_still_reclaiming() computes a deadline from nn-&gt;boot_time<br /> (CLOCK_REALTIME, ~1.7 billion) but compares it against<br /> ktime_get_boottime_seconds() (CLOCK_BOOTTIME, seconds since boot).<br /> The comparison is always false — it would take ~54 years of uptime<br /> for BOOTTIME to exceed the REALTIME-derived deadline.<br /> <br /> This means any client can hold the server in grace indefinitely by<br /> sending CLAIM_PREVIOUS OPEN requests, blocking all non-reclaim<br /> operations for all other clients.<br /> <br /> Add boot_time_bt (CLOCK_BOOTTIME) alongside the existing boot_time<br /> and use it for the deadline computation. boot_time (CLOCK_REALTIME)<br /> is preserved for its cl_boot clientid-nonce role.
Gravedad CVSS v3.1: ALTA
Última modificación:
21/09/2026

CVE-2026-89676

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfsd: fix stale s2s_cp_stateids IDR entry for async COPY<br /> <br /> For an async COPY, nfsd4_copy() called nfs4_init_copy_state() before<br /> dup_copy_fields(), so the s2s_cp_stateids IDR was pointed at<br /> &amp;u-&gt;copy-&gt;cp_stateid -- memory in the per-rqstp COMPOUND buffer that is<br /> reused by the next request. dup_copy_fields() copies only the value into<br /> async_copy, so the IDR slot dangled at the transient buffer for the whole<br /> background copy. Any IDR walker then dereferences reused request memory:<br /> the laundromat reads cs_type from it and, if the bytes look like an<br /> expired NFS4_COPYNOTIFY_STID, follows into<br /> refcount_dec()/idr_remove()/kfree() on garbage; manage_cpntf_state() has<br /> the same exposure via idr_find().<br /> <br /> Duplicate the fields first, then register the stateid on the stable<br /> async_copy. result-&gt;cb_stateid is unchanged.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
21/09/2026

CVE-2026-89667

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache<br /> <br /> The shrinker, GC worker, and fsnotify/lease callbacks can unhash an<br /> nfsd_file from the rhashtable and then call<br /> nfsd_file_dispose_list_delayed() to move it to the per-net dispose list.<br /> If nfsd_file_cache_shutdown_net() runs concurrently, its rhashtable walk<br /> misses the already-unhashed file, and its drain of the per-net dispose<br /> list can run before the file has been queued. The file then sits on<br /> the per-net list with no thread to drain it, leaking both the file and<br /> its associated state.<br /> <br /> The GC worker and shrinker already hold nfsd_gc_lock while walking the<br /> LRU, but in the original code they release it before calling<br /> nfsd_file_dispose_list_delayed(). The fsnotify/lease path<br /> (nfsd_file_close_inode) has no synchronization at all.<br /> <br /> Fix this by:<br /> <br /> 1. Widening nfsd_gc_lock in both nfsd_file_gc() and nfsd_file_lru_scan()<br /> to cover the nfsd_file_dispose_list_delayed() call.<br /> <br /> 2. Wrapping nfsd_file_close_inode() in nfsd_gc_lock so that all three<br /> callers of nfsd_file_dispose_list_delayed() hold the lock.<br /> <br /> 3. Adding a spin_lock/unlock(nfsd_gc_lock) barrier in<br /> nfsd_file_cache_shutdown_net() after the purge, so that any<br /> in-progress disposal has fully completed before the per-net list<br /> is drained.<br /> <br /> All operations inside the lock are non-sleeping (rhashtable lookups,<br /> atomic bit/refcount ops, list moves, svc_wake_up), so the spinlock is<br /> appropriate.
Gravedad CVSS v3.1: ALTA
Última modificación:
21/09/2026