Vulnerabilidades en Linux

13.542 resultados
Análisis Vexday

Com 12.630 CVEs catalogadas e 1.872 novas entradas nos últimos 90 dias, o Linux apresenta um volume de vulnerabilidades consistente com sua ampla base de código e adoção global. A taxa de exploração ativa — apenas 9 entradas no CISA KEV, representando 0,07% do total — está abaixo da média geral do catálogo (0,45%), o que sugere que, apesar da superfície de ataque extensa, a conversão de vulnerabilidades em ameaças ativas e confirmadas permanece relativamente contida. Ainda assim, a CVE-2026-31431 merece atenção prioritária: com EPSS de 0,9678, a probabilidade de exploração ativa é elevada, e seu status no KEV indica que esse risco já se concretizou. A falha mais comum — CWE-476 (desreferência de ponteiro nulo) — é representativa da complexidade inerente ao desenvolvimento em nível de kernel e reforça a necessidade de triagem contínua, especialmente diante das 23 vulnerabilidades com PoC pública disponível.

CVE-2025-39946CRITICALtls: make sure to abort the stream if headers are bogusEPSS 8.9%CVE-2025-38562ksmbd: fix null pointer dereference error in generate_encryptionkeyEPSS 7.6%CVE-2025-21759HIGHipv6: mcast: extend RCU protection in igmp6_send()EPSS 7.4%CVE-2026-46300HIGHnet: skbuff: preserve shared-frag marker during coalescingEPSS 7.0%CVE-2017-2634HIGHIt was found that the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation before 2.6.22.17 used the IPv4-only inet_sk_EPSS 5.2%CVE-2023-3867CRITICALksmbd: fix out of bounds read in smb2_sess_setupEPSS 5.1%CVE-2022-0742CRITICALMemory leak in ICMP6 in Linux KernelEPSS 5.0%CVE-2022-3435MEDIUMLinux Kernel IPv4 fib_semantics.c fib_nh_match out-of-boundsEPSS 3.8%CVE-2017-7558MEDIUMA kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() fEPSS 3.8%CVE-2023-0266HIGHUse after free in SNDRV_CTL_IOCTL_ELEM in Linux KernelEPSS 3.7%KEVCVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 3.6%KEVCVE-2023-2163CRITICALIncorrect Verifier Branch Pruning Logic Leads To Arbitrary Read/Write In Linux Kernel and Lateral Privilege EscalationEPSS 3.5%CVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.3%KEVCVE-2026-46242HIGHeventpoll: fix ep_remove struct eventpoll / struct file UAFEPSS 3.2%CVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2023-0045MEDIUMIncorrect indirect branch prediction barrier in the Linux KernelEPSS 2.4%CVE-2022-3594MEDIUMLinux Kernel BPF r8152.c intr_callback logging of excessive dataEPSS 2.3%CVE-2024-26581HIGHnetfilter: nft_set_rbtree: skip end interval element from gcEPSS 2.2%CVE-2025-38501HIGHksmbd: limit repeated connections from clients with the same IPEPSS 2.1%CVE-2023-31248HIGHLinux Kernel nftables Use-After-Free Local Privilege Escalation VulnerabilityEPSS 2.1%