Vulnerabilidades em Linux

17.489 resultados
Análise Vexday

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-64500—iio: adc: lpc32xx: Initialize completion before requesting IRQEPSS 0.2%CVE-2026-68180—intel_th: fix MSC output device reference leakEPSS 0.2%CVE-2024-36477HIGHtpm_tis_spi: Account for SPI header when allocating TPM SPI xfer bufferEPSS 0.2%CVE-2026-72182—power: supply: charger-manager: fix refcount leak in is_full_charged()EPSS 0.2%CVE-2026-68327—wan: wanxl: Only reset hardware after BAR mappingEPSS 0.2%CVE-2026-68351—wifi: carl9170: bound memcpy length in cmd callback to prevent OOB readEPSS 0.2%CVE-2026-90070—tpm: st33zp24: Return zero on status read failureEPSS 0.2%CVE-2026-68215—media: radio-si476x: Unregister v4l2_device on probe failureEPSS 0.2%CVE-2026-80867—alpha/PCI: Add security_locked_down() check to pci_mmap_resource()EPSS 0.2%CVE-2026-72039—bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()EPSS 0.2%CVE-2026-89876—media: tda18250: fix possible integer overflowEPSS 0.2%CVE-2025-71268HIGHbtrfs: fix reservation leak in some error paths when inserting inline extentEPSS 0.2%CVE-2026-63957—USB: serial: safe_serial: fix memory corruption with small endpointEPSS 0.2%CVE-2026-68217—media: pwc: Drain fill_buf on start_streaming() failureEPSS 0.2%CVE-2026-74426—afs: fix NULL pointer dereference in afs_get_tree()EPSS 0.2%CVE-2026-64504—iio: accel: bmc150: clamp the device-reported FIFO frame countEPSS 0.2%CVE-2026-90114—net: bridge: Reject descending VLAN tunnel rangesEPSS 0.2%CVE-2026-68176—tracing: Fix mmiotrace possible NULL dereferencing of hiter->devEPSS 0.2%CVE-2026-64594—usb: gadget: f_fs: initialize reset_work at allocation timeEPSS 0.2%CVE-2026-68182—comedi: comedi_parport: deal with premature interruptEPSS 0.2%