Vulnerabilities in Linux

13,517 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-23014HIGHperf: Ensure swevent hrtimer is properly destroyedEPSS 0.1%CVE-2026-46249octeontx2-af: Fix PF driver crash with kexec kernel bootingEPSS 0.1%CVE-2025-38448usb: gadget: u_serial: Fix race condition in TTY wakeupEPSS 0.1%CVE-2026-22989nfsd: check that server is running in unlock_filesystemEPSS 0.1%CVE-2026-22995ublk: fix use-after-free in ublk_partition_scan_workEPSS 0.1%CVE-2026-31689EDAC/mc: Fix error path ordering in edac_mc_alloc()EPSS 0.1%CVE-2026-31650mmc: vub300: fix use-after-free on disconnectEPSS 0.1%CVE-2026-53259HIGHipv6: anycast: insert aca into global hash under idev->lockEPSS 0.1%CVE-2026-23170drm/imx/tve: fix probe device leakEPSS 0.1%CVE-2025-71134mm/page_alloc: change all pageblocks migrate type on coalescingEPSS 0.1%CVE-2025-71099HIGHdrm/xe/oa: Fix potential UAF in xe_oa_add_config_ioctl()EPSS 0.1%CVE-2025-38687HIGHcomedi: fix race between polling and detachingEPSS 0.1%CVE-2026-22993idpf: Fix RSS LUT NULL ptr issue after soft resetEPSS 0.1%CVE-2026-23019net: marvell: prestera: fix NULL dereference on devlink_alloc() failureEPSS 0.1%CVE-2026-22985idpf: Fix RSS LUT NULL pointer crash on early ethtool operationsEPSS 0.1%CVE-2026-22981idpf: detach and close netdevs while handling a resetEPSS 0.1%CVE-2026-532636lowpan: fix off-by-one in multicast context address compressionEPSS 0.1%CVE-2026-53324net: mana: Use pci_name() for debugfs directory namingEPSS 0.1%CVE-2026-46314drm/v3d: Reject empty multisync extension to prevent infinite loopEPSS 0.1%CVE-2026-23426drm/logicvc: Fix device node reference leak in logicvc_drm_config_parse()EPSS 0.1%