Vulnerabilities in Linux

13,162 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2024-50183MEDIUMscsi: lpfc: Ensure DA_ID handling completion before deleting an NPIV instanceEPSS 0.2%CVE-2025-38513wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev()EPSS 0.2%CVE-2022-50152usb: ohci-nxp: Fix refcount leak in ohci_hcd_nxp_probeEPSS 0.2%CVE-2025-38576powerpc/eeh: Make EEH driver device hotplug safeEPSS 0.2%CVE-2022-48937io_uring: add a schedule point in io_add_buffers()EPSS 0.2%CVE-2026-45848apparmor: fix NULL sock in aa_sock_file_permEPSS 0.2%CVE-2026-45916power: supply: sbs-battery: Fix use-after-free in power_supply_changed()EPSS 0.2%CVE-2026-45965apparmor: fix invalid deref of rawdata when export_binary is unsetEPSS 0.2%CVE-2026-23233f2fs: fix to avoid mapping wrong physical block for swapfileEPSS 0.2%CVE-2022-50140memstick/ms_block: Fix a memory leakEPSS 0.2%CVE-2025-71304smack: /smack/doi: accept previously used valuesEPSS 0.2%CVE-2025-38639netfilter: xt_nfacct: don't assume acct name is null-terminatedEPSS 0.2%CVE-2025-21953MEDIUMnet: mana: cleanup mana struct after debugfs_remove()EPSS 0.2%CVE-2022-50047net: dsa: mv88e6060: prevent crash on an unused portEPSS 0.2%CVE-2023-53999net/mlx5e: TC, Fix internal port memory leakEPSS 0.2%CVE-2026-45861HIGHgfs2: Fix slab-use-after-free in qd_putEPSS 0.2%CVE-2025-38010phy: tegra: xusb: Use a bitmask for UTMI pad power state trackingEPSS 0.2%CVE-2023-53014MEDIUMdmaengine: tegra: Fix memory leak in terminate_all()EPSS 0.2%CVE-2022-50118powerpc/perf: Optimize clearing the pending PMI and remove WARN_ON for PMI check in power_pmu_disableEPSS 0.2%CVE-2025-22099drm: xlnx: zynqmp_dpsub: Add NULL check in zynqmp_audio_initEPSS 0.2%