Vulnerabilities in Linux

13,492 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2025-39836HIGHefi: stmm: Fix incorrect buffer allocation methodEPSS 0.1%CVE-2022-49771dm ioctl: fix misbehavior if list_versions races with module loadingEPSS 0.1%CVE-2026-46145HIGHRDMA/mana: Validate rx_hash_key_lenEPSS 0.1%CVE-2026-31772HIGHBluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_syncEPSS 0.1%CVE-2025-39861HIGHBluetooth: vhci: Prevent use-after-free by removing debugfs files earlyEPSS 0.1%CVE-2021-47577io-wq: check for wq exit after adding new worker task_workEPSS 0.1%CVE-2026-46150HIGHfanotify: fix false positive on permission eventsEPSS 0.1%CVE-2026-45993LoongArch: Add spectre boundry for syscall dispatch tableEPSS 0.1%CVE-2026-64018CRITICALnet: mana: validate rx_req_idx to prevent out-of-bounds array accessEPSS 0.1%CVE-2025-38722habanalabs: fix UAF in export_dmabuf()EPSS 0.1%CVE-2024-44956drm/xe/preempt_fence: enlarge the fence critical sectionEPSS 0.1%CVE-2026-46062HIGHntfs3: fix integer overflow in run_unpack() volume boundary checkEPSS 0.1%CVE-2023-53432HIGHfirewire: net: fix use after free in fwnet_finish_incoming_packet()EPSS 0.1%CVE-2025-38221ext4: fix out of bounds punch offsetEPSS 0.1%CVE-2026-23474mtd: Avoid boot crash in RedBoot partition table parserEPSS 0.1%CVE-2023-53578net: qrtr: Fix an uninit variable access bug in qrtr_tx_resume()EPSS 0.1%CVE-2025-38250Bluetooth: hci_core: Fix use-after-free in vhci_flush()EPSS 0.1%CVE-2024-36976Revert "media: v4l2-ctrls: show all owned controls in log_status"EPSS 0.1%CVE-2025-38162netfilter: nft_set_pipapo: prevent overflow in lookup table allocationEPSS 0.1%CVE-2023-53286HIGHRDMA/mlx5: Return the firmware result upon destroying QP/RQEPSS 0.1%