Vulnerabilities in Linux

13,161 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2025-40169bpf: Reject negative offsets for ALU opsEPSS 0.2%CVE-2024-43865s390/fpu: Re-add exception handling in load_fpu_state()EPSS 0.2%CVE-2022-50649power: supply: adp5061: fix out-of-bounds read in adp5061_get_chg_type()EPSS 0.2%CVE-2024-44943mm: gup: stop abusing try_grab_folioEPSS 0.2%CVE-2025-40061RDMA/rxe: Fix race in do_task() when drainingEPSS 0.2%CVE-2023-53079net/mlx5: Fix steering rules cleanupEPSS 0.2%CVE-2026-31787xen/privcmd: fix double free via VMA splittingEPSS 0.2%CVE-2025-71188dmaengine: lpc18xx-dmamux: fix device leak on route allocationEPSS 0.2%CVE-2026-23026dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config()EPSS 0.2%CVE-2024-42149fs: don't misleadingly warn during thaw operationsEPSS 0.2%CVE-2024-50161MEDIUMbpf: Check the remaining info_cnt before repeating btf fieldsEPSS 0.2%CVE-2022-50629wifi: rsi: Fix memory leak in rsi_coex_attach()EPSS 0.2%CVE-2025-22017devlink: fix xa_alloc_cyclic() error handlingEPSS 0.2%CVE-2025-68297ceph: fix crash in process_v2_sparse_read() for encrypted directoriesEPSS 0.2%CVE-2025-40104ixgbevf: fix mailbox API compatibility by negotiating supported featuresEPSS 0.2%CVE-2022-50051ASoC: SOF: debug: Fix potential buffer overflow by snprintf()EPSS 0.2%CVE-2025-68292mm/memfd: fix information leak in hugetlb foliosEPSS 0.2%CVE-2025-40077f2fs: fix to avoid overflow while left shift operationEPSS 0.2%CVE-2025-40067fs/ntfs3: reject index allocation if $BITMAP is empty but blocks existEPSS 0.2%CVE-2021-47280drm: Fix use-after-free read in drm_getunique()EPSS 0.2%