Vulnerabilidades em Linux

17.279 resultados
Análise Vexday

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2021-47451HIGHnetfilter: xt_IDLETIMER: fix panic that occurs when timer_type has garbage valueEPSS 0.2%CVE-2024-35860HIGHbpf: support deferring bpf_link dealloc to after RCU grace periodEPSS 0.2%CVE-2025-39750HIGHwifi: ath12k: Correct tid cleanup when tid setup failsEPSS 0.2%CVE-2024-50019—kthread: unpark only parked kthreadEPSS 0.2%CVE-2021-47441HIGHmlxsw: thermal: Fix out-of-bounds memory accessesEPSS 0.2%CVE-2026-97509HIGHthunderbolt: Keep XDomain reference during the lifetime of a serviceEPSS 0.2%CVE-2024-38554—ax25: Fix reference count leak issue of net_deviceEPSS 0.2%CVE-2022-49441MEDIUMtty: fix deadlock caused by calling printk() under tty_port->lockEPSS 0.2%CVE-2023-52792—cxl/region: Do not try to cleanup after cxl_region_setup_targets() failsEPSS 0.2%CVE-2023-52878—can: dev: can_put_echo_skb(): don't crash kernel if can_priv::echo_skb is accessed out of boundsEPSS 0.2%CVE-2022-49010—hwmon: (coretemp) Check for null before removing sysfs attrsEPSS 0.2%CVE-2025-37923HIGHtracing: Fix oob write in trace_seq_to_buffer()EPSS 0.2%CVE-2024-53187MEDIUMio_uring: check for overflows in io_pin_pagesEPSS 0.2%CVE-2021-47065—rtw88: Fix array overrun in rtw_get_tx_power_params()EPSS 0.2%CVE-2024-50093MEDIUMthermal: intel: int340x: processor: Fix warning during module unloadEPSS 0.2%CVE-2024-26807HIGHspi: cadence-qspi: fix pointer reference in runtime PM hooksEPSS 0.2%CVE-2021-47296HIGHKVM: PPC: Fix kvm_arch_vcpu_ioctl vcpu_load leakEPSS 0.2%CVE-2023-52788—i915/perf: Fix NULL deref bugs with drm_dbg() callsEPSS 0.2%CVE-2022-48778—mtd: rawnand: gpmi: don't leak PM reference in error pathEPSS 0.2%CVE-2023-52662HIGHdrm/vmwgfx: fix a memleak in vmw_gmrid_man_get_nodeEPSS 0.2%