Vulnerabilidades em Linux

17.279 resultados
Análise Vexday

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2022-49743HIGHovl: Use "buf" flexible array for memcpy() destinationEPSS 0.4%CVE-2024-41046HIGHnet: ethernet: lantiq_etop: fix double free in detachEPSS 0.4%CVE-2026-53198HIGHksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCELEPSS 0.4%CVE-2023-53986HIGHmips: bmips: BCM6358: disable RAC flush for TP1EPSS 0.4%CVE-2024-44992HIGHsmb/client: avoid possible NULL dereference in cifs_free_subrequest()EPSS 0.4%CVE-2026-80844—xfrm: ah6: validate routing header segments_leftEPSS 0.4%CVE-2022-21546HIGHscsi: target: Fix WRITE_SAME No Data Buffer crashEPSS 0.4%CVE-2025-38123CRITICALnet: wwan: t7xx: Fix napi rx poll issueEPSS 0.4%CVE-2026-23457HIGHnetfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp()EPSS 0.4%CVE-2022-50062HIGHnet: bgmac: Fix a BUG triggered by wrong bytes_complEPSS 0.4%CVE-2022-50059HIGHceph: don't leak snap_rwsem in handle_cap_grantEPSS 0.4%CVE-2024-46696CRITICALnfsd: fix potential UAF in nfsd4_cb_getattr_releaseEPSS 0.4%CVE-2025-40204HIGHsctp: Fix MAC comparison to be constant-timeEPSS 0.4%CVE-2025-38561CRITICALksmbd: fix Preauh_HashValue race conditionEPSS 0.4%CVE-2022-4696HIGHThere exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is EPSS 0.4%CVE-2025-21959HIGHnetfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()EPSS 0.4%CVE-2025-68315CRITICALf2fs: fix to detect potential corrupted nid in free_nid_listEPSS 0.4%CVE-2023-6610HIGHKernel: oob access in smb2_dump_detailEPSS 0.4%CVE-2025-68741CRITICALscsi: qla2xxx: Fix improper freeing of purex itemEPSS 0.4%CVE-2025-40074CRITICALipv4: start using dst_dev_rcu()EPSS 0.4%