Vulnerabilidades em Linux

17.279 resultados
Análise Vexday

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2022-48693—soc: brcmstb: pm-arm: Fix refcount leak and __iomem leak bugsEPSS 0.2%CVE-2025-21919HIGHsched/fair: Fix potential memory corruption in child_cfs_rq_on_listEPSS 0.2%CVE-2022-48630—crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZEPSS 0.2%CVE-2024-50130HIGHnetfilter: bpf: must hold reference on net namespaceEPSS 0.2%CVE-2025-21999HIGHproc: fix UAF in proc_get_inode()EPSS 0.2%CVE-2024-42072HIGHbpf: Fix may_goto with negative offset.EPSS 0.2%CVE-2024-26835—netfilter: nf_tables: set dormant flag on hook register failureEPSS 0.2%CVE-2024-39298—mm/memory-failure: fix handling of dissolved but not taken off from buddy pagesEPSS 0.2%CVE-2024-50158HIGHRDMA/bnxt_re: Fix out of bound checkEPSS 0.2%CVE-2024-26716—usb: core: Prevent null pointer dereference in update_port_device_stateEPSS 0.2%CVE-2023-52800MEDIUMwifi: ath11k: fix htt pktlog lockingEPSS 0.2%CVE-2025-22104—ibmvnic: Use kernel helpers for hex dumpsEPSS 0.2%CVE-2024-36893—usb: typec: tcpm: Check for port partner validity before consuming itEPSS 0.2%CVE-2022-49529MEDIUMdrm/amdgpu/pm: fix the null pointer while the smu is disabledEPSS 0.2%CVE-2023-52677—riscv: Check if the code to patch lies in the exit sectionEPSS 0.2%CVE-2024-50300HIGHregulator: rtq2208: Fix uninitialized use of regulator_configEPSS 0.2%CVE-2024-36891—maple_tree: fix mas_empty_area_rev() null pointer dereferenceEPSS 0.2%CVE-2024-35883—spi: mchp-pci1xxx: Fix a possible null pointer dereference in pci1xxx_spi_probeEPSS 0.2%CVE-2021-47095—ipmi: ssif: initialize ssif_info->client earlyEPSS 0.2%CVE-2024-41088—can: mcp251xfd: fix infinite loop when xmit failsEPSS 0.2%