Vulnerabilidades em Linux

17.279 resultados
Análise Vexday

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2024-36898HIGHgpiolib: cdev: fix uninitialised kfifoEPSS 0.2%CVE-2024-38551—ASoC: mediatek: Assign dummy when codec not specified for a DAI linkEPSS 0.2%CVE-2021-47296HIGHKVM: PPC: Fix kvm_arch_vcpu_ioctl vcpu_load leakEPSS 0.2%CVE-2025-39848HIGHax25: properly unshare skbs in ax25_kiss_rcv()EPSS 0.2%CVE-2022-50815—ext2: Add sanity checks for group and filesystem sizeEPSS 0.2%CVE-2024-50002—static_call: Handle module init failure correctly in static_call_del_module()EPSS 0.2%CVE-2021-47087HIGHtee: optee: Fix incorrect page free bugEPSS 0.2%CVE-2024-58034HIGHmemory: tegra20-emc: fix an OF node reference bug in tegra_emc_find_node_by_ram_code()EPSS 0.2%CVE-2024-35814HIGHswiotlb: Fix double-allocation of slots due to broken alignment handlingEPSS 0.2%CVE-2023-52787—blk-mq: make sure active queue usage is held for bio_integrity_prep()EPSS 0.2%CVE-2024-50000—net/mlx5e: Fix NULL deref in mlx5e_tir_builder_alloc()EPSS 0.2%CVE-2026-72441—ieee802154: fix kernel-infoleak in dgram_recvmsg()EPSS 0.2%CVE-2024-49947—net: test for not too small csum_start in virtio_net_hdr_to_skb()EPSS 0.2%CVE-2021-47003—dmaengine: idxd: Fix potential null dereference on pointer statusEPSS 0.2%CVE-2021-47258—scsi: core: Fix error handling of scsi_host_alloc()EPSS 0.2%CVE-2021-47052—crypto: sa2ul - Fix memory leak of rxdEPSS 0.2%CVE-2022-49005—ASoC: ops: Fix bounds check for _sx controlsEPSS 0.2%CVE-2021-47339—media: v4l2-core: explicitly clear ioctl input dataEPSS 0.2%CVE-2024-26807HIGHspi: cadence-qspi: fix pointer reference in runtime PM hooksEPSS 0.2%CVE-2021-47223—net: bridge: fix vlan tunnel dst null pointer dereferenceEPSS 0.2%