Vulnerabilities in Linux

13,486 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2022-50319coresight: trbe: remove cpuhp instance node before remove cpuhp stateEPSS 0.1%CVE-2023-53660bpf, cpumap: Handle skb as well when clean up ptr_ringEPSS 0.1%CVE-2022-50443drm/rockchip: lvds: fix PM usage counter unbalance in poweronEPSS 0.1%CVE-2023-53462hsr: Fix uninit-value access in fill_frame_info()EPSS 0.1%CVE-2025-39851MEDIUMvxlan: Fix NPD when refreshing an FDB entry with a nexthop objectEPSS 0.1%CVE-2022-50541dmaengine: ti: k3-udma: Reset UDMA_CHAN_RT byte counters to prevent overflowEPSS 0.1%CVE-2022-50429memory: of: Fix refcount leak bug in of_lpddr3_get_ddr_timings()EPSS 0.1%CVE-2023-53461io_uring: wait interruptibly for request completions on exitEPSS 0.1%CVE-2025-21807block: fix queue freeze vs limits lock order in sysfs store methodsEPSS 0.1%CVE-2025-38300crypto: sun8i-ce-cipher - fix error handling in sun8i_ce_cipher_prepare()EPSS 0.1%CVE-2022-50533wifi: mac80211: mlme: fix null-ptr deref on failed assocEPSS 0.1%CVE-2025-38304Bluetooth: Fix NULL pointer deference on eir_get_service_dataEPSS 0.1%CVE-2022-50438net: hinic: fix memory leak when reading function tableEPSS 0.1%CVE-2025-38366LoongArch: KVM: Check validity of "num_cpu" from user spaceEPSS 0.1%CVE-2026-64238gpio: shared: fix deadlock on shared proxy's parent removalEPSS 0.1%CVE-2022-50475RDMA/core: Make sure "ib_port" is valid when access sysfs nodeEPSS 0.1%CVE-2022-50273f2fs: fix to do sanity check on destination blkaddr during recoveryEPSS 0.1%CVE-2025-38544rxrpc: Fix bug due to prealloc collisionEPSS 0.1%CVE-2023-53237MEDIUMdrm/amdgpu: fix amdgpu_irq_put call trace in gmc_v11_0_hw_finiEPSS 0.1%CVE-2022-50491coresight: cti: Fix hang in cti_disable_hw()EPSS 0.1%