Vulnerabilidades em Linux

17.279 resultados
Análise Vexday

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2024-35810HIGHdrm/vmwgfx: Fix the lifetime of the bo cursor memoryEPSS 0.2%CVE-2024-47728—bpf: Zero former ARG_PTR_TO_{LONG,INT} args in case of errorEPSS 0.2%CVE-2022-50815—ext2: Add sanity checks for group and filesystem sizeEPSS 0.2%CVE-2021-47260—NFS: Fix a potential NULL dereference in nfs_get_client()EPSS 0.2%CVE-2024-58034HIGHmemory: tegra20-emc: fix an OF node reference bug in tegra_emc_find_node_by_ram_code()EPSS 0.2%CVE-2024-26765—LoongArch: Disable IRQ before init_fn() for nonboot CPUsEPSS 0.2%CVE-2021-47197HIGHnet/mlx5e: nullify cq->dbg pointer in mlx5_debug_cq_remove()EPSS 0.2%CVE-2024-49937—wifi: cfg80211: Set correct chandef when starting CACEPSS 0.2%CVE-2021-47002—SUNRPC: Fix null pointer dereference in svc_rqst_free()EPSS 0.2%CVE-2022-48778—mtd: rawnand: gpmi: don't leak PM reference in error pathEPSS 0.2%CVE-2023-54134—autofs: fix memory leak of waitqueues in autofs_catatonic_modeEPSS 0.2%CVE-2026-72441—ieee802154: fix kernel-infoleak in dgram_recvmsg()EPSS 0.2%CVE-2023-52773—drm/amd/display: fix a NULL pointer dereference in amdgpu_dm_i2c_xfer()EPSS 0.2%CVE-2024-35920HIGHmedia: mediatek: vcodec: adding lock to protect decoder context listEPSS 0.2%CVE-2022-49020—net/9p: Fix a potential socket leak in p9_socket_openEPSS 0.2%CVE-2024-49947—net: test for not too small csum_start in virtio_net_hdr_to_skb()EPSS 0.2%CVE-2024-56569MEDIUMftrace: Fix regression with module command in stack_trace_filterEPSS 0.2%CVE-2022-48660MEDIUMgpiolib: cdev: Set lineevent_state::irq after IRQ register successfullyEPSS 0.2%CVE-2021-47535HIGHdrm/msm/a6xx: Allocate enough space for GMU registersEPSS 0.2%CVE-2023-52848—f2fs: fix to drop meta_inode's page cache in f2fs_put_super()EPSS 0.2%