Vulnerabilities in Linux

13,517 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-22976net/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_resetEPSS 0.1%CVE-2026-23228smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection()EPSS 0.1%CVE-2026-64420HIGHmfd: cros_ec: Delay dev_set_drvdata() until probe successEPSS 0.1%CVE-2026-23424HIGHaccel/amdxdna: Validate command buffer payload countEPSS 0.1%CVE-2026-53314padata: Put CPU offline callback in ONLINE section to allow failureEPSS 0.1%CVE-2025-71235scsi: qla2xxx: Delay module unload while fabric scan in progressEPSS 0.1%CVE-2026-46054HIGHselinux: fix overlayfs mmap() and mprotect() access checksEPSS 0.1%CVE-2026-43280HIGHdrm/xe: Add bounds check on pat_index to prevent OOB kernel read in madviseEPSS 0.1%CVE-2026-43276net: mana: Fix double destroy_workqueue on service rescan PCI pathEPSS 0.1%CVE-2025-71232scsi: qla2xxx: Free sp in error path to fix system crashEPSS 0.1%CVE-2025-71184btrfs: fix NULL dereference on root when tracing inode evictionEPSS 0.1%CVE-2025-38461HIGHvsock: Fix transport_* TOCTOUEPSS 0.1%CVE-2026-45907net/mlx5e: Fix deadlocks between devlink and netdev instance locksEPSS 0.1%CVE-2025-71237nilfs2: Fix potential block overflow that cause system hangEPSS 0.1%CVE-2026-43070HIGHbpf: Reset register ID for BPF_END value trackingEPSS 0.1%CVE-2026-64460HIGHPCI/IOV: Skip VF Resizable BAR restore on read errorEPSS 0.1%CVE-2026-52919HIGHbatman-adv: fix tp_meter counter underflow during shutdownEPSS 0.1%CVE-2026-23376nvmet-fcloop: Check remoteport port_state before calling done callbackEPSS 0.1%CVE-2026-53112wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_taskletEPSS 0.1%CVE-2026-23337pinctrl: pinconf-generic: Fix memory leak in pinconf_generic_parse_dt_config()EPSS 0.1%