Vulnerabilities in Linux

13,511 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2025-21958Revert "openvswitch: switch to per-action label counting in conntrack"EPSS 0.1%CVE-2025-38058__legitimize_mnt(): check for MNT_SYNC_UMOUNT should be under mount_lockEPSS 0.1%CVE-2023-53206hwmon: (pmbus_core) Fix NULL pointer dereferenceEPSS 0.1%CVE-2025-39802lib/crypto: arm/poly1305: Fix register corruption in no-SIMD contextsEPSS 0.1%CVE-2026-45932HIGHbpf: Fix tcx/netkit detach permissions when prog fd isn't givenEPSS 0.1%CVE-2025-39827net: rose: include node references in rose_neigh refcountEPSS 0.1%CVE-2025-39721crypto: qat - flush misc workqueue during device shutdownEPSS 0.1%CVE-2023-53253HIGHHID: nvidia-shield: Reference hid_device devm allocation of input_dev nameEPSS 0.1%CVE-2026-52953HIGHiommu/vt-d: Fix oops due to out of scope accessEPSS 0.1%CVE-2026-53388HIGHfuse: re-lock request before replacing page cache folioEPSS 0.1%CVE-2023-53682hwmon: (xgene) Fix ioremap and memremap leakEPSS 0.1%CVE-2025-38232NFSD: fix race between nfsd registration and exports_procEPSS 0.1%CVE-2023-53099firmware: xilinx: don't make a sleepable memory allocation from an atomic contextEPSS 0.1%CVE-2026-52971HIGHnet: ena: PHC: Fix potential use-after-free in get_timestampEPSS 0.1%CVE-2026-45990slub: fix data loss and overflow in krealloc()EPSS 0.1%CVE-2026-63803HIGHhdlc_ppp: sync per-proto timers before freeing hdlc stateEPSS 0.1%CVE-2025-39868HIGHerofs: fix runtime warning on truncate_folio_batch_exceptionals()EPSS 0.1%CVE-2025-39962rxrpc: Fix untrusted unsigned subtractEPSS 0.1%CVE-2025-39862HIGHwifi: mt76: mt7915: fix list corruption after hardware restartEPSS 0.1%CVE-2023-53678drm/i915: Fix system suspend without fbdev being initializedEPSS 0.1%