Vulnerabilities in Linux

13,517 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-31713fuse: abort on fatal signal during sync initEPSS 0.1%CVE-2026-23164rocker: fix memory leak in rocker_world_port_post_fini()EPSS 0.1%CVE-2026-23150nfc: llcp: Fix memleak in nfc_llcp_send_ui_frame().EPSS 0.1%CVE-2025-38675HIGHxfrm: state: initialize state_ptrs earlier in xfrm_state_findEPSS 0.1%CVE-2026-31652mm/damon/stat: deallocate damon_call() failure leaking damon_ctxEPSS 0.1%CVE-2025-38306HIGHfs/fhandle.c: fix a race in call of has_locked_children()EPSS 0.1%CVE-2026-23155can: gs_usb: gs_usb_receive_bulk_callback(): fix error messageEPSS 0.1%CVE-2026-31681netfilter: xt_multiport: validate range encoding in checkentryEPSS 0.1%CVE-2026-23113io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loopEPSS 0.1%CVE-2026-23129dpll: Prevent duplicate registrationsEPSS 0.1%CVE-2026-23020net: 3com: 3c59x: fix possible null dereference in vortex_probe1()EPSS 0.1%CVE-2026-31395bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handlerEPSS 0.1%CVE-2026-52930ipc/shm: serialize orphan cleanup with shm_nattch updatesEPSS 0.1%CVE-2026-46308pmdomain: mediatek: fix use-after-free in scpsys_get_bus_protection_legacy()EPSS 0.1%CVE-2026-23154net: fix segmentation of forwarding fraglist GROEPSS 0.1%CVE-2026-43272ring-buffer: Fix possible dereference of uninitialized pointerEPSS 0.1%CVE-2026-23116pmdomain: imx8m-blk-ctrl: Remove separate rst and clk mask for 8mq vpuEPSS 0.1%CVE-2026-31394mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stationsEPSS 0.1%CVE-2026-53318wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_tx_check_aggr()EPSS 0.1%CVE-2025-38520drm/amdkfd: Don't call mmput from MMU notifier callbackEPSS 0.1%