Vulnerabilities in Linux

13,511 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-23007block: zero non-PI portion of auto integrity bufferEPSS 0.1%CVE-2023-53683fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()EPSS 0.1%CVE-2023-53674clk: Fix memory leak in devm_clk_notifier_register()EPSS 0.1%CVE-2026-46034vfio/cdx: Fix NULL pointer dereference in interrupt trigger pathEPSS 0.1%CVE-2026-31401HIGHHID: bpf: prevent buffer overflow in hid_hw_requestEPSS 0.1%CVE-2023-53381MEDIUMNFSD: fix leaked reference count of nfsd4_ssc_umount_itemEPSS 0.1%CVE-2023-53532wifi: ath11k: fix deinitialization of firmware resourcesEPSS 0.1%CVE-2023-53292MEDIUMblk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_noneEPSS 0.1%CVE-2023-53389MEDIUMdrm/mediatek: dp: Only trigger DRM HPD events if bridge is attachedEPSS 0.1%CVE-2023-53610irqchip: Fix refcount leak in platform_irqchip_probeEPSS 0.1%CVE-2025-21732RDMA/mlx5: Fix a race for an ODP MR which leads to CQE with errorEPSS 0.1%CVE-2025-37741jfs: Prevent copying of nlink with value 0 from disk inodeEPSS 0.1%CVE-2025-21938mptcp: fix 'scheduling while atomic' in mptcp_pm_nl_append_new_local_addrEPSS 0.1%CVE-2023-53512scsi: mpt3sas: Fix a memory leakEPSS 0.1%CVE-2026-64469HIGHbinder: fix UAF in binder_thread_release()EPSS 0.1%CVE-2026-46174HIGHx86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cacheEPSS 0.1%CVE-2023-53513nbd: fix incomplete validation of ioctl argEPSS 0.1%CVE-2025-23163net: vlan: don't propagate flags on openEPSS 0.1%CVE-2026-31446HIGHext4: fix use-after-free in update_super_work when racing with umountEPSS 0.1%CVE-2022-50187ath11k: fix netdev open raceEPSS 0.1%