Vulnerabilities in Linux

16,673 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-64551CRITICALsctp: validate STALE_COOKIE cause length before reading stalenessEPSS 0.5%CVE-2026-74384CRITICALnvme-multipath: fix flex array size in struct nvme_ns_headEPSS 0.5%CVE-2026-64007CRITICALnetfilter: synproxy: refresh tcphdr after skb_ensure_writableEPSS 0.5%CVE-2026-68388CRITICALsmb/client: handle overlapping allocated ranges in fallocateEPSS 0.5%CVE-2026-63984CRITICALipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()EPSS 0.5%CVE-2026-46043CRITICALRDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcvEPSS 0.5%CVE-2026-63993CRITICALvxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()EPSS 0.5%CVE-2026-53186CRITICALRDMA/srp: bound SRP_RSP sense copy by the received lengthEPSS 0.5%CVE-2026-53228CRITICALipv6: sit: reload inner IPv6 header after GSO offloadsEPSS 0.5%CVE-2026-74495CRITICALigbvf: Fix leak in TX DMA error cleanupEPSS 0.5%CVE-2026-64047CRITICALnet: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ringEPSS 0.5%CVE-2026-53225CRITICALsctp: fix uninit-value in __sctp_rcv_asconf_lookup()EPSS 0.5%CVE-2026-74662CRITICALinet: frags: publish queues before arming timerEPSS 0.5%CVE-2026-64055CRITICALnet: ethernet: cortina: Carry over frag counterEPSS 0.5%CVE-2026-74398CRITICALipv6: addrconf: bail out of dad_failure when state is no longer POSTDADEPSS 0.5%CVE-2026-74669CRITICALipvs: clear IPv4 options after rebasing tunnel ICMP errorsEPSS 0.5%CVE-2026-68343CRITICALsmb: client: validate DFS referral PathConsumedEPSS 0.5%CVE-2026-46185CRITICALsmb/client: fix out-of-bounds read in symlink_data()EPSS 0.5%CVE-2022-48851CRITICALstaging: gdm724x: fix use after free in gdm_lte_rx()EPSS 0.5%CVE-2026-52914CRITICALbatman-adv: fix fragment reassembly length accountingEPSS 0.5%