Vulnerabilities in Linux

16,673 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-89555CRITICALmpls: reload header after pskb_may_pull()EPSS 0.7%CVE-2026-72014CRITICALdrbd: reject data replies with an out-of-range payload sizeEPSS 0.7%CVE-2021-47307HIGHcifs: prevent NULL deref in cifs_compose_mount_options()EPSS 0.7%CVE-2025-22041HIGHksmbd: fix use-after-free in ksmbd_sessions_deregister()EPSS 0.7%CVE-2025-37879CRITICAL9p/net: fix improper handling of bogus negative read/write repliesEPSS 0.7%CVE-2021-47478CRITICALisofs: Fix out of bound access for corrupted isofs imageEPSS 0.7%CVE-2024-56645CRITICALcan: j1939: j1939_session_new(): fix skb reference countingEPSS 0.7%CVE-2024-47739HIGHpadata: use integer wrap around to prevent deadlock on seq_nr overflowEPSS 0.7%CVE-2026-72191CRITICALntfs3: validate split-point offset in indx_insert_into_bufferEPSS 0.7%CVE-2023-52441CRITICALksmbd: fix out of bounds in init_smb2_rsp_hdr()EPSS 0.7%CVE-2024-26665CRITICALtunnels: fix out of bounds access when building IPv6 PMTU errorEPSS 0.7%CVE-2019-19332MEDIUMAn out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor haEPSS 0.7%CVE-2023-52628HIGHnetfilter: nftables: exthdr: fix 4-byte stack OOB writeEPSS 0.7%CVE-2026-72231HIGHbatman-adv: tt: avoid request storms during pending requestEPSS 0.7%CVE-2026-90102HIGHNFSv4/pnfs: key the data server cache on the NFS versionEPSS 0.7%CVE-2026-45860HIGHnetfilter: nf_conncount: increase the connection clean up limit to 64EPSS 0.7%CVE-2026-74282HIGHtipc: prevent snt_unacked underflow on CONN_ACKEPSS 0.7%CVE-2026-72253HIGHnetfilter: nf_conntrack_sip: validate skb_dst() before accessing itEPSS 0.7%CVE-2026-72242HIGHselinux: avoid sk_socket dereference in selinux_sctp_bind_connect()EPSS 0.7%CVE-2022-49356CRITICALSUNRPC: Trap RDMA segment overflowsEPSS 0.7%