Vulnerabilities in Linux

13,517 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-31472xfrm: iptfs: validate inner IPv4 header length in IPTFS payloadEPSS 0.1%CVE-2026-53301reset: amlogic: t7: Fix null reset opsEPSS 0.1%CVE-2026-23338drm/amdgpu/userq: Do not allow userspace to trivially triger kernel warningsEPSS 0.1%CVE-2026-45971bpf: Limit bpf program signature sizeEPSS 0.1%CVE-2026-31632rxrpc: Fix leak of rxgk context in rxgk_verify_response()EPSS 0.1%CVE-2026-23070Octeontx2-af: Add proper checks for fwdataEPSS 0.1%CVE-2026-43482sched_ext: Disable preemption between scx_claim_exit() and kicking helper workEPSS 0.1%CVE-2026-46267nfc: hci: shdlc: Stop timers and work before freeing contextEPSS 0.1%CVE-2026-53266HIGHnetfilter: bridge: make ebt_snat ARP rewrite writableEPSS 0.1%CVE-2026-23275HIGHio_uring: ensure ctx->rings is stable for task work flags manipulationEPSS 0.1%CVE-2026-43301media: chips-media: wave5: Fix PM runtime usage count underflowEPSS 0.1%CVE-2026-46118pseries/papr-hvpipe: Fix null ptr deref in papr_hvpipe_dev_create_handle()EPSS 0.1%CVE-2026-53270HIGHipvs: clear the svc scheduler ptr early on editEPSS 0.1%CVE-2026-43247media: chips-media: wave5: Fix SError of kernel panic when closedEPSS 0.1%CVE-2026-43234team: avoid NETDEV_CHANGEMTU event when unregistering slaveEPSS 0.1%CVE-2026-53211netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR registerEPSS 0.1%CVE-2026-23366drm/client: Do not destroy NULL modesEPSS 0.1%CVE-2026-53128drbd: Balance RCU calls in drbd_adm_dump_devices()EPSS 0.1%CVE-2026-53019clk: spacemit: ccu_mix: fix inverted condition in ccu_mix_trigger_fc()EPSS 0.1%CVE-2026-23072l2tp: Fix memleak in l2tp_udp_encap_recv().EPSS 0.1%