Vulnerabilidades em Linux

16.673 resultados
Análise Vexday

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-68155HIGHlibceph: Reject monmaps advertising zero monitorsEPSS 0.7%CVE-2026-74281HIGHtipc: reject inverted service ranges from peer bindingsEPSS 0.7%CVE-2024-35863CRITICALsmb: client: fix potential UAF in is_valid_oplock_break()EPSS 0.7%CVE-2024-35862CRITICALsmb: client: fix potential UAF in smb2_is_network_name_deleted()EPSS 0.7%CVE-2024-35864CRITICALsmb: client: fix potential UAF in smb2_is_valid_lease_break()EPSS 0.7%CVE-2023-52513HIGHRDMA/siw: Fix connection failure handlingEPSS 0.7%CVE-2024-53066CRITICALnfs: Fix KMSAN warning in decode_getfattr_attrs()EPSS 0.7%CVE-2026-72422CRITICALksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATEEPSS 0.7%CVE-2024-53120HIGHnet/mlx5e: CT: Fix null-ptr-deref in add rule err flowEPSS 0.7%CVE-2024-49978HIGHgso: fix udp gso fraglist segmentation after pull from frag_listEPSS 0.7%CVE-2024-26953CRITICALnet: esp: fix bad handling of pages from page_poolEPSS 0.7%CVE-2024-38612HIGHipv6: sr: fix invalid unregister error pathEPSS 0.7%CVE-2022-49362CRITICALNFSD: Fix potential use-after-free in nfsd_file_put()EPSS 0.7%CVE-2026-89636CRITICALsmb: client: clear ce->tgthint in free_tgts()EPSS 0.7%CVE-2022-48829CRITICALNFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizesEPSS 0.7%CVE-2023-0461HIGHUse-after-free vulnerability in the Linux KernelEPSS 0.7%CVE-2024-47726HIGHf2fs: fix to wait dio completionEPSS 0.7%CVE-2024-36913CRITICALDrivers: hv: vmbus: Leak pages if set_memory_encrypted() failsEPSS 0.7%CVE-2024-38616HIGHwifi: carl9170: re-fix fortified-memset warningEPSS 0.7%CVE-2025-40343CRITICALnvmet-fc: avoid scheduling association deletion twiceEPSS 0.7%