Vulnerabilities in Linux

17,280 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-68082CRITICALlibceph: fix two unsafe bare decodes in decode_lockers()EPSS 0.4%CVE-2026-52945HIGHRevert "wireguard: device: enable threaded NAPI"EPSS 0.4%CVE-2022-50363CRITICALskmsg: pass gfp argument to alloc_sk_msg()EPSS 0.4%CVE-2026-53309CRITICALocfs2/dlm: fix off-by-one in dlm_match_regions() region comparisonEPSS 0.4%CVE-2026-89844HIGHscsi: qla2xxx: Hold vport_slock for host map update in report ID acquisitionEPSS 0.4%CVE-2026-74411HIGHwifi: rtw89: Correct data type for scan index to avoid infinite loopEPSS 0.4%CVE-2026-74531HIGHBluetooth: hci_conn: hold conn reference in abort_conn_sync()EPSS 0.4%CVE-2026-93042HIGHdmaengine: dw-edma: Terminate all descriptors without callbacksEPSS 0.4%CVE-2026-80989HIGHnet: thunderbolt: Mark the connection down when bringing it up failsEPSS 0.4%CVE-2026-68389HIGHBluetooth: hci_qca: Clear memdump state on invalid dump sizeEPSS 0.4%CVE-2022-1353—A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged useEPSS 0.4%CVE-2026-89860HIGHscsi: qla2xxx: Initialize NVMe abort_work once at submissionEPSS 0.4%CVE-2026-43350HIGHsmb: client: require a full NFS mode SID before reading mode bitsEPSS 0.4%CVE-2024-46755HIGHwifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()EPSS 0.4%CVE-2025-68232HIGHveth: more robust handing of race to avoid txq getting stuckEPSS 0.4%CVE-2026-23459HIGHip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATSEPSS 0.4%CVE-2026-46135CRITICALnvmet-tcp: fix race between ICReq handling and queue teardownEPSS 0.4%CVE-2025-21829CRITICALRDMA/rxe: Fix the warning "__rxe_cleanup+0x12c/0x170 [rdma_rxe]"EPSS 0.4%CVE-2024-27435HIGHnvme: fix reconnection fail due to reserved tag allocationEPSS 0.4%CVE-2025-38471CRITICALtls: always refresh the queue when reading sockEPSS 0.4%