Vulnerabilidades em Linux

17.279 resultados
Análise Vexday

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2024-56562—i3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs()EPSS 0.2%CVE-2021-47483HIGHregmap: Fix possible double-free in regcache_rbtree_exit()EPSS 0.2%CVE-2022-50214—coresight: Clear the connection field properlyEPSS 0.2%CVE-2024-56675HIGHbpf: Fix UAF via mismatching bpf_prog/attachment RCU flavorsEPSS 0.2%CVE-2022-48650MEDIUMscsi: qla2xxx: Fix memory leak in __qlt_24xx_handle_abts()EPSS 0.2%CVE-2022-48720HIGHnet: macsec: Fix offload support for NETDEV_UNREGISTER eventEPSS 0.2%CVE-2024-47719—iommufd: Protect against overflow of ALIGN() during iova allocationEPSS 0.2%CVE-2024-45022HIGHmm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0EPSS 0.2%CVE-2024-35956—btrfs: qgroup: fix qgroup prealloc rsv leak in subvolume operationsEPSS 0.2%CVE-2025-37866—mlxbf-bootctl: use sysfs_emit_at() in secure_boot_fuse_state_show()EPSS 0.2%CVE-2024-42244—USB: serial: mos7840: fix crash on resumeEPSS 0.2%CVE-2024-27006—thermal/debugfs: Add missing count increment to thermal_debug_tz_trip_up()EPSS 0.2%CVE-2024-35896HIGHnetfilter: validate user input for expected lengthEPSS 0.2%CVE-2025-21972HIGHnet: mctp: unshare packets when reassemblingEPSS 0.2%CVE-2026-63981—net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflowEPSS 0.2%CVE-2023-52635—PM / devfreq: Synchronize devfreq_monitor_[start/stop]EPSS 0.2%CVE-2023-52577—dccp: fix dccp_v4_err()/dccp_v6_err() againEPSS 0.2%CVE-2024-39475—fbdev: savage: Handle err return when savagefb_check_var failedEPSS 0.2%CVE-2026-93241—memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper is doneEPSS 0.2%CVE-2022-49504—scsi: lpfc: Inhibit aborts if external loopback plug is insertedEPSS 0.2%