Vulnerabilidades em Linux

17.489 resultados
Análise Vexday

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2024-36965HIGHremoteproc: mediatek: Make sure IPI buffer fits in L2TCMEPSS 0.2%CVE-2023-54087—ubi: Fix possible null-ptr-deref in ubi_free_volume()EPSS 0.2%CVE-2021-47497—nvmem: Fix shift-out-of-bound (UBSAN) with byte size cellsEPSS 0.2%CVE-2024-50261HIGHmacsec: Fix use-after-free while sending the offloading packetEPSS 0.2%CVE-2024-36884HIGHiommu/arm-smmu: Use the correct type in nvidia_smmu_context_fault()EPSS 0.2%CVE-2024-43845HIGHudf: Fix bogus checksum computation in udf_rename()EPSS 0.2%CVE-2024-47700—ext4: check stripe size compatibility on remount as wellEPSS 0.2%CVE-2024-56546—drivers: soc: xilinx: add the missing kfree in xlnx_add_cb_for_suspend()EPSS 0.2%CVE-2023-53849—drm/msm: fix workqueue leak on bind errorsEPSS 0.2%CVE-2024-42064HIGHdrm/amd/display: Skip pipe if the pipe idx not set properlyEPSS 0.2%CVE-2024-56766—mtd: rawnand: fix double free in atmel_pmecc_create_user()EPSS 0.2%CVE-2024-38566—bpf: Fix verifier assumptions about socket->skEPSS 0.2%CVE-2022-48751HIGHnet/smc: Transitional solution for clcsock race issueEPSS 0.2%CVE-2023-52660—media: rkisp1: Fix IRQ handling due to shared interruptsEPSS 0.2%CVE-2024-40949HIGHmm: shmem: fix getting incorrect lruvec when replacing a shmem folioEPSS 0.2%CVE-2024-50168MEDIUMnet/sun3_82586: fix potential memory leak in sun3_82586_send_packet()EPSS 0.2%CVE-2021-47380HIGHHID: amd_sfh: Fix potential NULL pointer dereferenceEPSS 0.2%CVE-2024-56623HIGHscsi: qla2xxx: Fix use after free on unloadEPSS 0.2%CVE-2025-21793MEDIUMspi: sn-f-ospi: Fix division by zeroEPSS 0.2%CVE-2026-23005—x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1EPSS 0.2%