Vulnerabilities in Linux

17,280 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-43018HIGHBluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evtEPSS 0.4%CVE-2025-38676—iommu/amd: Avoid stack buffer overflow from kernel cmdlineEPSS 0.4%CVE-2026-80635HIGHwifi: wcn36xx: fix OOB read from short trigger BA firmware responseEPSS 0.4%CVE-2026-80722HIGHwifi: mac80211: validate individual TWT params before driver setupEPSS 0.4%CVE-2026-89774HIGHBluetooth: SCO: hold sk properly in sco_conn_readyEPSS 0.4%CVE-2026-74691HIGHnet: thunderbolt: Tear down DMA paths before stopping the ringsEPSS 0.4%CVE-2026-43495HIGHnet: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handlerEPSS 0.4%CVE-2026-90357HIGHwifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreementEPSS 0.4%CVE-2026-64441HIGHstaging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()EPSS 0.4%CVE-2026-90255HIGHBluetooth: hci_conn: fix the SCO setup context lifetimeEPSS 0.4%CVE-2026-72029HIGHnet: wwan: iosm: bound device offsets in the MUX downlink decoderEPSS 0.4%CVE-2022-3533LOWLinux Kernel BPF usdt.c parse_usdt_arg memory leakEPSS 0.4%CVE-2026-74300HIGHBluetooth: hci: validate codec capability element lengthEPSS 0.4%CVE-2026-80645HIGHrapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()EPSS 0.4%CVE-2024-57936CRITICALRDMA/bnxt_re: Fix max SGEs for the Work RequestEPSS 0.4%CVE-2024-46690CRITICALnfsd: fix nfsd4_deleg_getattr_conflict in presence of third party leaseEPSS 0.4%CVE-2025-40212CRITICALnfsd: fix refcount leak in nfsd_set_fh_dentry()EPSS 0.4%CVE-2023-53360CRITICALNFSv4.2: Rework scratch handling for READ_PLUS (again)EPSS 0.4%CVE-2026-74575HIGHthunderbolt: Prevent XDomain delayed work use-after-free on disconnectEPSS 0.4%CVE-2026-31408HIGHBluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_holdEPSS 0.4%