Vulnerabilidades em Linux

17.280 resultados
Análise Vexday

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2024-26907HIGHRDMA/mlx5: Fix fortify source warning while accessing Eth segmentEPSS 0.3%CVE-2024-27039—clk: hisilicon: hi3559a: Fix an erroneous devm_kfree()EPSS 0.3%CVE-2024-53042MEDIUMipv4: ip_tunnel: Fix suspicious RCU usage warning in ip_tunnel_init_flow()EPSS 0.3%CVE-2022-49199—RDMA/nldev: Prevent underflow in nldev_stat_set_counter_dynamic_doit()EPSS 0.3%CVE-2025-37873HIGHeth: bnxt: fix missing ring index trim on error pathEPSS 0.3%CVE-2022-49703MEDIUMscsi: ibmvfc: Store vhost pointer during subcrq allocationEPSS 0.3%CVE-2022-49133—drm/amdkfd: svm range restore work deadlock when process exitEPSS 0.3%CVE-2024-50022—device-dax: correct pgoff align in dax_set_mapping()EPSS 0.3%CVE-2022-49650—dmaengine: qcom: bam_dma: fix runtime PM underflowEPSS 0.3%CVE-2021-47383HIGHtty: Fix out-of-bound vmalloc access in imageblitEPSS 0.3%CVE-2022-49513—cpufreq: governor: Use kobject release() method to free dbs_dataEPSS 0.3%CVE-2022-49714MEDIUMirqchip/realtek-rtl: Fix refcount leak in map_interruptsEPSS 0.3%CVE-2022-49164—powerpc/tm: Fix more userspace r13 corruptionEPSS 0.3%CVE-2024-38560—scsi: bfa: Ensure the copied buf is NUL terminatedEPSS 0.3%CVE-2024-46774—powerpc/rtas: Prevent Spectre v1 gadget construction in sys_rtas()EPSS 0.3%CVE-2024-56770MEDIUMnet/sched: netem: account for backlog updates from child qdiscEPSS 0.3%CVE-2025-37869HIGHdrm/xe: Use local fence in error path of xe_migrate_clearEPSS 0.3%CVE-2025-22064—netfilter: nf_tables: don't unregister hook when table is dormantEPSS 0.3%CVE-2025-22065MEDIUMidpf: fix adapter NULL pointer dereference on rebootEPSS 0.3%CVE-2024-46816HIGHdrm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_linksEPSS 0.3%