Vulnerabilities in Linux

13,517 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-31391crypto: atmel-sha204a - Fix OOM ->tfm_count leakEPSS 0.1%CVE-2025-38388firmware: arm_ffa: Replace mutex with rwlock to avoid sleep in atomic contextEPSS 0.1%CVE-2026-43066ext4: fix iloc.bh leak in ext4_fc_replay_inode() error pathsEPSS 0.1%CVE-2026-23171HIGHbonding: fix use-after-free due to enslave fail after slave array updateEPSS 0.1%CVE-2026-31701ALSA: caiaq: take a reference on the USB device in create_card()EPSS 0.1%CVE-2026-23102arm64/fpsimd: signal: Fix restoration of SVE contextEPSS 0.1%CVE-2026-31400sunrpc: fix cache_request leak in cache_releaseEPSS 0.1%CVE-2026-43299btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure()EPSS 0.1%CVE-2025-38353drm/xe: Fix taking invalid lock on wedgeEPSS 0.1%CVE-2026-53273HIGHtee: optee: prevent use-after-free when the client exits before the supplicantEPSS 0.1%CVE-2026-43052wifi: mac80211: check tdls flag in ieee80211_tdls_operEPSS 0.1%CVE-2026-43065ext4: always drain queued discard work in ext4_mb_release()EPSS 0.1%CVE-2026-53076HIGHbpf: Fix OOB in pcpu_init_valueEPSS 0.1%CVE-2026-31684net: sched: act_csum: validate nested VLAN headersEPSS 0.1%CVE-2026-43278HIGHdm: clear cloned request bio pointer when last clone bio completesEPSS 0.1%CVE-2026-53272erofs: fix use-after-free on sbi->sync_decompressEPSS 0.1%CVE-2026-53255Bluetooth: MGMT: validate advertising TLV before type checksEPSS 0.1%CVE-2026-43273ceph: supply snapshot context in ceph_zero_partial_object()EPSS 0.1%CVE-2026-31484HIGHio_uring/fdinfo: fix OOB read in SQE_MIXED wrap checkEPSS 0.1%CVE-2026-43268hfsplus: pretend special inodes as regular filesEPSS 0.1%