Vulnerabilities in Linux

13,517 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-23363wifi: mt76: mt7925: Fix possible oob access in mt7925_mac_write_txwi_80211()EPSS 0.1%CVE-2026-45938power: supply: pm8916_lbc: Fix use-after-free in power_supply_changed()EPSS 0.1%CVE-2026-31590KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGIONEPSS 0.1%CVE-2026-46121mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lockEPSS 0.1%CVE-2026-52942HIGHnetfilter: nf_log: validate MAC header was set before dumping itEPSS 0.1%CVE-2025-39924HIGHerofs: fix invalid algorithm for encoded extentsEPSS 0.1%CVE-2026-53389HIGHnet/tcp-ao: fix use-after-free of key in del_async pathEPSS 0.1%CVE-2026-23273HIGHmacvlan: observe an RCU grace period in macvlan_common_newlink() error pathEPSS 0.1%CVE-2026-23370platform/x86: dell-wmi-sysman: Don't hex dump plaintext password dataEPSS 0.1%CVE-2026-46309HIGHdrm/xe/uapi: Reject coh_none PAT index for CPU cached memory in madviseEPSS 0.1%CVE-2026-53097wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work()EPSS 0.1%CVE-2025-39785HIGHdrm/hisilicon/hibmc: fix irq_request()'s irq name variable is localEPSS 0.1%CVE-2025-39789HIGHcrypto: x86/aegis - Add missing error checksEPSS 0.1%CVE-2026-31603staging: sm750fb: fix division by zero in ps_to_hz()EPSS 0.1%CVE-2026-31599media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sectionsEPSS 0.1%CVE-2026-31619ALSA: fireworks: bound device-supplied status before string array lookupEPSS 0.1%CVE-2026-64543HIGHtipc: fix use-after-free of the discoverer in tipc_disc_rcv()EPSS 0.1%CVE-2025-68379HIGHRDMA/rxe: Fix null deref on srq->rq.queue after resize failureEPSS 0.1%CVE-2026-45957rcu: Fix rcu_read_unlock() deadloop due to softirqEPSS 0.1%CVE-2026-53376drm/amdkfd: Add upper bound check for num_of_nodesEPSS 0.1%