Vulnerabilities in Linux

16,673 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2025-21756HIGHvsock: Keep the binding until socket destructionEPSS 0.9%CVE-2023-34324MEDIUMPossible deadlock in Linux kernel event handlingEPSS 0.9%CVE-2024-44947fuse: Initialize beyond-EOF page contents before setting uptodateEPSS 0.9%CVE-2024-42286HIGHscsi: qla2xxx: validate nvme_local_port correctlyEPSS 0.9%CVE-2022-3646LOWLinux Kernel BPF segment.c nilfs_attach_log_writer memory leakEPSS 0.9%CVE-2024-40983CRITICALtipc: force a dst refcount before doing decryptionEPSS 0.9%CVE-2024-44985CRITICALipv6: prevent possible UAF in ip6_xmit()EPSS 0.9%CVE-2022-49058CRITICALcifs: potential buffer overflow in handling symlinksEPSS 0.9%CVE-2024-41081CRITICALila: block BH in ila_output()EPSS 0.9%CVE-2024-42145HIGHIB/core: Implement a limit on UMAD receive ListEPSS 0.9%CVE-2024-42285CRITICALRDMA/iwcm: Fix a use-after-free related to destroying CM IDsEPSS 0.9%CVE-2019-14814MEDIUMThere is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, thaEPSS 0.9%CVE-2024-50083tcp: fix mptcp DSS corruption due to large pmtu xmitEPSS 0.9%CVE-2022-49407CRITICALdlm: fix plock invalid readEPSS 0.9%CVE-2021-47544CRITICALtcp: fix page frag corruption on page faultEPSS 0.9%CVE-2024-38582MEDIUMnilfs2: fix potential hang in nilfs_detach_log_writer()EPSS 0.9%CVE-2024-44946HIGHkcm: Serialise kcm_sendmsg() for the same socket.EPSS 0.9%CVE-2023-5717HIGHOut-of-bounds write in Linux kernel's Linux Kernel Performance Events (perf) componentEPSS 0.8%CVE-2023-52776HIGHwifi: ath12k: fix dfs-radar and temperature event lockingEPSS 0.8%CVE-2022-3649LOWLinux Kernel BPF inode.c nilfs_new_inode use after freeEPSS 0.8%