Vulnerabilidades em Linux

17.489 resultados
Análise Vexday

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-68478—memstick: ms_block: reject a card that reports too many blocksEPSS 0.2%CVE-2026-74426—afs: fix NULL pointer dereference in afs_get_tree()EPSS 0.2%CVE-2026-74457—can: peak_usb: add bounds check for USB channel indexEPSS 0.2%CVE-2026-64504—iio: accel: bmc150: clamp the device-reported FIFO frame countEPSS 0.2%CVE-2024-42235HIGHs390/mm: Add NULL pointer check to crst_table_free() base_crst_free()EPSS 0.2%CVE-2026-90114—net: bridge: Reject descending VLAN tunnel rangesEPSS 0.2%CVE-2026-64594—usb: gadget: f_fs: initialize reset_work at allocation timeEPSS 0.2%CVE-2026-80812—ALSA: dummy: Check card index validity at probeEPSS 0.2%CVE-2026-93141—usb: gadget: r8a66597: avoid double free of ep0_req in probe error pathEPSS 0.2%CVE-2026-68223—media: meson: vdec: Fix memory leak in error path of vdec_openEPSS 0.2%CVE-2024-42157—s390/pkey: Wipe sensitive data on failureEPSS 0.2%CVE-2026-89628—HID: picolcd: clamp eeprom debugfs read to bytes actually receivedEPSS 0.2%CVE-2026-90055—usb: atm: usbatm: fix invalid ci_range initializationEPSS 0.2%CVE-2026-80889—can: isotp: fix timer drain order, wakeup handling and tx_gen orderingEPSS 0.2%CVE-2026-90070—tpm: st33zp24: Return zero on status read failureEPSS 0.2%CVE-2026-74416—drm/radeon: fix memory leak in radeon_ring_restore() on lock failureEPSS 0.2%CVE-2026-74525—net: sxgbe: free TX rings on RX allocation failureEPSS 0.2%CVE-2024-35837—net: mvpp2: clear BM pool before initializationEPSS 0.2%CVE-2026-68215—media: radio-si476x: Unregister v4l2_device on probe failureEPSS 0.2%CVE-2026-74460—can: ems_usb: validate CPC message lengthsEPSS 0.2%