Vulnerabilidades em Linux

17.489 resultados
Análise Vexday

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2026-72256—netfilter: xt_cluster: reject template conntracks in hash matchEPSS 0.2%CVE-2026-74499—ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()EPSS 0.2%CVE-2026-89621—HID: mcp2221: validate report size in mcp2221_raw_event()EPSS 0.2%CVE-2026-63961—usb: typec: altmodes/displayport: validate count before reading Status Update VDOEPSS 0.2%CVE-2022-50156HIGHHID: cp2112: prevent a buffer overflow in cp2112_xfer()EPSS 0.2%CVE-2024-56566—mm/slub: Avoid list corruption when removing a slab from the full listEPSS 0.2%CVE-2026-72039—bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()EPSS 0.2%CVE-2026-93204—batman-adv: dat: atomically update mac addressesEPSS 0.2%CVE-2021-47312MEDIUMnetfilter: nf_tables: Fix dereference of null pointer flowEPSS 0.2%CVE-2026-63964—usb: typec: ucsi: ccg: reject firmware images without a ':' record headerEPSS 0.2%CVE-2026-63928—USB: serial: omninet: fix memory corruption with small endpointEPSS 0.2%CVE-2026-68249—drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()EPSS 0.2%CVE-2026-68195—wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio busesEPSS 0.2%CVE-2024-39277HIGHdma-mapping: benchmark: handle NUMA_NO_NODE correctlyEPSS 0.2%CVE-2026-63908—Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_memEPSS 0.2%CVE-2026-72074—Input: ims-pcu - fix type confusion in CDC union descriptor parsingEPSS 0.2%CVE-2026-74693—net: prestera: validate firmware header lengthEPSS 0.2%CVE-2026-64471—Bluetooth: btusb: fix use-after-free on registration failureEPSS 0.2%CVE-2025-71269HIGHbtrfs: do not free data reservation in fallback from inline due to -ENOSPCEPSS 0.2%CVE-2026-74585—thunderbolt: Bound the DROM dual link port number before indexing sw->portsEPSS 0.2%