Vulnerabilities in Linux

17,487 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2021-47065—rtw88: Fix array overrun in rtw_get_tx_power_params()EPSS 0.2%CVE-2022-48688—i40e: Fix kernel crash during module removalEPSS 0.2%CVE-2024-49947—net: test for not too small csum_start in virtio_net_hdr_to_skb()EPSS 0.2%CVE-2024-41095—drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_ld_modesEPSS 0.2%CVE-2024-50093MEDIUMthermal: intel: int340x: processor: Fix warning during module unloadEPSS 0.2%CVE-2024-36898HIGHgpiolib: cdev: fix uninitialised kfifoEPSS 0.2%CVE-2024-38551—ASoC: mediatek: Assign dummy when codec not specified for a DAI linkEPSS 0.2%CVE-2022-50815—ext2: Add sanity checks for group and filesystem sizeEPSS 0.2%CVE-2021-47087HIGHtee: optee: Fix incorrect page free bugEPSS 0.2%CVE-2021-47250—net: ipv4: fix memory leak in netlbl_cipsov4_add_stdEPSS 0.2%CVE-2026-74331—firmware_loader: Fix recursive lock in device_cache_fw_images()EPSS 0.2%CVE-2024-49871—Input: adp5589-keys - fix NULL pointer dereferenceEPSS 0.2%CVE-2024-35814HIGHswiotlb: Fix double-allocation of slots due to broken alignment handlingEPSS 0.2%CVE-2023-52787—blk-mq: make sure active queue usage is held for bio_integrity_prep()EPSS 0.2%CVE-2024-36918HIGHbpf: Check bloom filter map value sizeEPSS 0.2%CVE-2021-47223—net: bridge: fix vlan tunnel dst null pointer dereferenceEPSS 0.2%CVE-2024-50000—net/mlx5e: Fix NULL deref in mlx5e_tir_builder_alloc()EPSS 0.2%CVE-2024-38554—ax25: Fix reference count leak issue of net_deviceEPSS 0.2%CVE-2025-21726HIGHpadata: avoid UAF for reorder_workEPSS 0.2%CVE-2022-49010—hwmon: (coretemp) Check for null before removing sysfs attrsEPSS 0.2%