Vulnerabilities in Linux

13,522 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-46257clocksource/drivers/timer-sp804: Fix an Oops when read_current_timer is called on ARM32 platforms where the SP804 is not registered as the sched_clock.EPSS 0.1%CVE-2026-23211mm, swap: restore swap_space attr aviod kernel panicEPSS 0.1%CVE-2026-23106timekeeping: Adjust the leap state for the correct auxiliary timekeeperEPSS 0.1%CVE-2026-53050HIGHquota: Fix race of dquot_scan_active() with quota deactivationEPSS 0.1%CVE-2026-23114arm64/fpsimd: ptrace: Fix SVE writes on !SME systemsEPSS 0.1%CVE-2026-53378drm/colorop: Fix blob property reference tracking in state lifecycleEPSS 0.1%CVE-2026-23149drm: Do not allow userspace to trigger kernel warnings in drm_gem_change_handle_ioctl()EPSS 0.1%CVE-2026-46305staging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_allocEPSS 0.1%CVE-2026-53257wifi: cfg80211: enforce HE/EHT cap/oper consistencyEPSS 0.1%CVE-2026-23259io_uring/rw: free potentially allocated iovec on cache put failureEPSS 0.1%CVE-2026-31710smb: client: fix dir separator in SMB1 UNIX mountsEPSS 0.1%CVE-2026-23018btrfs: release path before initializing extent tree in btrfs_read_locked_inode()EPSS 0.1%CVE-2026-43478ASoC: codecs: rt1011: Use component to get the dapm context in spk_mode_putEPSS 0.1%CVE-2025-71227wifi: mac80211: don't WARN for connections on invalid channelsEPSS 0.1%CVE-2026-53351riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_CFIEPSS 0.1%CVE-2026-53344pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap initEPSS 0.1%CVE-2026-23152wifi: mac80211: correctly decode TTLM with default link mapEPSS 0.1%CVE-2026-23377ice: change XDP RxQ frag_size from DMA write length to xdp.frame_szEPSS 0.1%CVE-2026-43348mshv_vtl: Fix vmemmap_shift exceeding MAX_FOLIO_ORDEREPSS 0.1%CVE-2026-46318Revert "mm/hugetlbfs: update hugetlbfs to use mmap_prepare"EPSS 0.1%