Vulnerabilities in Linux

13,517 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-46148spi: microchip-core-qspi: control built-in cs manuallyEPSS 0.1%CVE-2026-23454net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardownEPSS 0.1%CVE-2026-43401cpufreq: intel_pstate: Fix NULL pointer dereference in update_cpu_qos_request()EPSS 0.1%CVE-2026-63865HIGHbpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooksEPSS 0.1%CVE-2026-31459mm/damon/sysfs: fix param_ctx leak on damon_sysfs_new_test_ctx() failureEPSS 0.1%CVE-2026-63799HIGHsched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup pathEPSS 0.1%CVE-2026-43285mm/slab: do not access current->mems_allowed_seq if !allow_spinEPSS 0.1%CVE-2026-31784drm/xe/pxp: Clear restart flag in pxp_start after jumping backEPSS 0.1%CVE-2026-23244nvme: fix memory allocation in nvme_pr_read_keys()EPSS 0.1%CVE-2026-31457mm/damon/sysfs: check contexts->nr in repeat_call_fnEPSS 0.1%CVE-2026-22979net: fix memory leak in skb_segment_list for GRO packetsEPSS 0.1%CVE-2026-53283iommu/amd: Bounds-check devid in __rlookup_amd_iommu()EPSS 0.1%CVE-2025-39904MEDIUMarm64: kexec: initialize kexec_buf struct in load_other_segments()EPSS 0.1%CVE-2026-53282x86/kexec: Push kjump return address even for non-kjump kexecEPSS 0.1%CVE-2026-43399drm/amdgpu/userq: Fix reference leak in amdgpu_userq_wait_ioctlEPSS 0.1%CVE-2025-71265fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadataEPSS 0.1%CVE-2026-31437netfs: Fix NULL pointer dereference in netfs_unbuffered_write() on retryEPSS 0.1%CVE-2026-53018f2fs: avoid reading already updated pages during GCEPSS 0.1%CVE-2026-23299Bluetooth: purge error queues in socket destructorsEPSS 0.1%CVE-2026-43325wifi: iwlwifi: mvm: don't send a 6E related command when not supportedEPSS 0.1%