Vulnerabilities in Linux

13,161 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-53101wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_syncEPSS 0.2%CVE-2024-58081MEDIUMclk: mmp2: call pm_genpd_init() only after genpd.name is setEPSS 0.2%CVE-2025-68772f2fs: fix to avoid updating compression context during writebackEPSS 0.2%CVE-2026-63847HIGHdrm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ringEPSS 0.2%CVE-2024-35798btrfs: fix race in read_extent_buffer_pages()EPSS 0.2%CVE-2023-54129octeontx2-af: Add validation for lmac typeEPSS 0.2%CVE-2026-64061CRITICALnetfs: Fix early put of sink folio in netfs_read_gaps()EPSS 0.2%CVE-2023-54203ksmbd: fix slab-out-of-bounds in init_smb2_rsp_hdrEPSS 0.2%CVE-2023-54146x86/kexec: Fix double-free of elf header bufferEPSS 0.2%CVE-2023-54152can: j1939: prevent deadlock by moving j1939_sk_errqueue()EPSS 0.2%CVE-2026-53402HIGHfbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()EPSS 0.2%CVE-2026-64112HIGHrbd: eliminate a race in lock_dwork draining on unmapEPSS 0.2%CVE-2025-71193phy: qcom-qusb2: Fix NULL pointer dereference on early suspendEPSS 0.2%CVE-2023-54250ksmbd: avoid out of bounds access in decode_preauth_ctxt()EPSS 0.2%CVE-2022-50699selinux: enable use of both GFP_KERNEL and GFP_ATOMIC in convert_context()EPSS 0.2%CVE-2026-53328sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task()EPSS 0.2%CVE-2023-54222hte: tegra-194: Fix off by one in tegra_hte_map_to_line_id()EPSS 0.2%CVE-2026-53387HIGHiio: light: veml6075: add bounds check to veml6075_it_ms indexEPSS 0.2%CVE-2023-54139tracing/user_events: Ensure write index cannot be negativeEPSS 0.2%CVE-2022-50698ASoC: da7219: Fix an error handling path in da7219_register_dai_clks()EPSS 0.2%