Vulnerabilities in Linux

13,161 results
Vexday analysis

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2023-54080btrfs: zoned: skip splitting and logical rewriting on pre-alloc writeEPSS 0.2%CVE-2024-36882mm: use memalloc_nofs_save() in page_cache_ra_order()EPSS 0.2%CVE-2024-43838bpf: fix overflow check in adjust_jmp_off()EPSS 0.2%CVE-2025-40162ASoC: amd/sdw_utils: avoid NULL deref when devm_kasprintf() failsEPSS 0.2%CVE-2021-47668HIGHcan: dev: can_restart: fix use after free bugEPSS 0.2%CVE-2026-64128Bluetooth: ISO: drop ISO_END frames received without prior ISO_STARTEPSS 0.2%CVE-2023-54097regulator: stm32-pwr: fix of_iomap leakEPSS 0.2%CVE-2025-68213idpf: fix possible vport_config NULL pointer deref in removeEPSS 0.2%CVE-2021-47670HIGHcan: peak_usb: fix use after free bugsEPSS 0.2%CVE-2021-47603audit: improve robustness of the audit queue handlingEPSS 0.2%CVE-2025-21891MEDIUMipvlan: ensure network headers are in skb linear partEPSS 0.2%CVE-2025-21969HIGHBluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmdEPSS 0.2%CVE-2024-38609wifi: mt76: connac: check for null before dereferencingEPSS 0.2%CVE-2023-54132erofs: stop parsing non-compact HEAD index if clusterofs is invalidEPSS 0.2%CVE-2024-43910bpf: add missing check_func_arg_reg_off() to prevent out-of-bounds memory accessesEPSS 0.2%CVE-2025-68750usb: potential integer overflow in usbg_make_tpg()EPSS 0.2%CVE-2024-35805dm snapshot: fix lockup in dm_exception_table_exitEPSS 0.2%CVE-2022-50781amdgpu/pm: prevent array underflow in vega20_odn_edit_dpm_table()EPSS 0.2%CVE-2023-54122drm/msm/dpu: Add check for cstateEPSS 0.2%CVE-2021-47669HIGHcan: vxcan: vxcan_xmit: fix use after free bugEPSS 0.2%