Vulnerabilities in Linux

13,161 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2025-37757tipc: fix memory leak in tipc_link_xmitEPSS 0.2%CVE-2023-54013interconnect: Fix locking for runpm vs reclaimEPSS 0.2%CVE-2025-38423ASoC: codecs: wcd9375: Fix double free of regulator suppliesEPSS 0.2%CVE-2023-53351MEDIUMdrm/sched: Check scheduler work queue before calling timeout handlingEPSS 0.2%CVE-2023-53050thunderbolt: Fix memory leak in marginingEPSS 0.2%CVE-2022-50034usb: cdns3 fix use-after-free at workaround 2EPSS 0.2%CVE-2025-38153net: usb: aqc111: fix error handling of usbnet read callsEPSS 0.2%CVE-2023-54085mptcp: fix NULL pointer dereference on fastopen early fallbackEPSS 0.2%CVE-2026-64146erofs: fix metabuf leak in inode xattr initializationEPSS 0.2%CVE-2025-40299gve: Implement gettimex64 with -EOPNOTSUPPEPSS 0.2%CVE-2025-38007HID: uclogic: Add NULL check in uclogic_input_configured()EPSS 0.2%CVE-2025-38075scsi: target: iscsi: Fix timeout on deleted connectionEPSS 0.2%CVE-2026-45896mtd: intel-dg: Fix accessing regions before setting nregionsEPSS 0.2%CVE-2025-68187net: mdio: Check regmap pointer returned by device_node_to_regmap()EPSS 0.2%CVE-2021-47494cfg80211: fix management registrations lockingEPSS 0.2%CVE-2024-57946MEDIUMvirtio-blk: don't keep queue frozen during system suspendEPSS 0.2%CVE-2025-68252misc: fastrpc: Fix dma_buf object leak in fastrpc_map_lookupEPSS 0.2%CVE-2025-38470net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtimeEPSS 0.2%CVE-2025-68189drm/msm: Fix GEM free for imported dma-bufsEPSS 0.2%CVE-2025-38468net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtreeEPSS 0.2%