Vulnerabilidades em Linux

17.280 resultados
Análise Vexday

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2023-53491HIGHstart_kernel: Add __no_stack_protector function attributeEPSS 0.3%CVE-2022-49238HIGHath11k: free peer for station when disconnect from AP for QCA6390/WCN6855EPSS 0.3%CVE-2022-49548HIGHbpf: Fix potential array overflow in bpf_trampoline_get_progs()EPSS 0.3%CVE-2025-38495HIGHHID: core: ensure the allocated report buffer can contain the reserved report IDEPSS 0.3%CVE-2022-49698—netfilter: use get_random_u32 instead of prandomEPSS 0.3%CVE-2024-42133HIGHBluetooth: Ignore too large handle values in BIGEPSS 0.3%CVE-2025-21703HIGHnetem: Update sch->q.qlen before qdisc_tree_reduce_backlog()EPSS 0.3%CVE-2023-53797HIGHHID: wacom: Use ktime_t rather than int when dealing with timestampsEPSS 0.3%CVE-2024-56539—wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_config_scan()EPSS 0.3%CVE-2024-40924HIGHdrm/i915/dpt: Make DPT object unshrinkableEPSS 0.3%CVE-2024-27008—drm: nv04: Fix out of bounds accessEPSS 0.3%CVE-2025-39735HIGHjfs: fix slab-out-of-bounds read in ea_get()EPSS 0.3%CVE-2022-49326MEDIUMrtl818x: Prevent using not initialized queuesEPSS 0.3%CVE-2024-27401HIGHfirewire: nosy: ensure user_length is taken into account when fetching packet contentsEPSS 0.3%CVE-2023-52922HIGHcan: bcm: Fix UAF in bcm_proc_show()EPSS 0.3%CVE-2023-52438HIGHbinder: fix use-after-free in shinker's callbackEPSS 0.3%CVE-2021-47541HIGHnet/mlx4_en: Fix an use-after-free bug in mlx4_en_try_alloc_resources()EPSS 0.3%CVE-2024-26600—phy: ti: phy-omap-usb2: Fix NULL pointer dereference for SRPEPSS 0.3%CVE-2025-37925—jfs: reject on-disk inodes of an unsupported typeEPSS 0.3%CVE-2024-26994HIGHspeakup: Avoid crash on very long wordEPSS 0.3%