Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
1962advisories found
nvdhigh
cve-2026-93119
A flaw in the Linux kernel's USB LJCA driver lets a broken or malicious LJCA device overflow a small on-stack array by reporting an out-of-range bank count, which the existing checks fail to catch. This could allow memory corruption in the kernel. This could be relevant where the Linux kernel's LJCA USB driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93117
A use-after-free vulnerability in the Linux kernel USB subsystem could let an attacker crash or corrupt memory when a USB device probe runs at the same time as a dynamic ID removal. The flaw affects the USB interface probing code, and the advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93107
The Linux kernel's RDMA/rxe (software RDMA over Ethernet) responder can reprocess the same received packet after a queue pair enters the error state, causing duplicate successful completions and eventually a kernel NULL pointer dereference. An attacker or a racing disconnect can trigger this, delivering the same datagram to user space hundreds of times and corrupting the data stream for any upper-layer protocol relying on exactly-once delivery. The advisory does not state a numeric severity score. This could be relevant where the Linux RDMA/rxe component is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93106
A flaw in the Linux kernel's crash_dump code mishandles a keyring reference when restoring saved dm-crypt keys, causing the reference to be dropped too many times when more than one key is restored. This can lead to a refcount underflow or use-after-free, and a warning can be triggered when more than five keys are restored. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93105
The Linux kernel's ESP (IPsec) networking code can mishandle page references when processing certain zero-copy network sends, potentially freeing a page that is still in use and causing memory corruption. An attacker able to trigger this path could crash the system or possibly corrupt kernel memory, though the advisory does not assign a specific severity score. This could be relevant where the Linux kernel's IPsec networking stack is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93104
A flaw in the Linux kernel's RDMA/rvt subsystem causes a function to return a pointer to memory it has already freed when port allocation fails, and callers then dereference that stale pointer, resulting in a use-after-free. An attacker able to trigger the failed allocation path could potentially exploit this memory corruption, though the advisory does not state a severity rating. This could be relevant where the Linux kernel's RDMA/rvt component is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93100
A use-after-free flaw in the Linux kernel's resctrl filesystem (fs/resctrl) could let an attacker trigger memory corruption when resource group structures are freed while still in use, potentially leading to a crash or double-free. This could be relevant where the Linux kernel is deployed in automotive systems, such as in ECUs, infotainment units, or telematics gateways. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93099
The Linux kernel's resctrl filesystem has a use-after-free vulnerability in its memory bandwidth and cache monitoring worker threads, which can be triggered when CPU hotplug removes monitoring domains while a worker is waiting on a lock, causing it to later access freed memory. An attacker able to trigger this condition could cause a use-after-free, which may lead to a crash or potentially other memory-corruption effects, though the advisory does not state a specific severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, but the advisory does not confirm an automotive connection; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93095
The Linux kernel's HFS+ filesystem code has a flaw where a corrupted disk image can cause an out-of-bounds write when deleting a hardlink's catalog entry, because the code trusts an unchecked name length from the catalog record. An attacker able to supply a malicious HFS+ image could trigger memory corruption in the kernel. The advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93094
A use-after-free vulnerability in the Linux kernel's ath12k Wi-Fi driver can leave dangling pointers when an access point virtual device creation fails partway through, potentially allowing an attacker to trigger memory corruption through subsequent lookups. This could be relevant where the ath12k Wi-Fi component is deployed in automotive systems, though the advisory does not confirm any automotive deployment. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93091
The Linux kernel's ARM SCMI firmware interface has a flaw where notification handling can still run while the notification system is being shut down, allowing an attacker to trigger use-after-free memory access during device removal or probe failure. This could lead to a crash or potentially allow memory corruption, though the advisory does not state a severity rating. This could be relevant where ARM SCMI firmware is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93079
A heap out-of-bounds write in the Linux kernel's CXL feature handling lets an attacker with access to the FWCTL_RPC interface trigger memory corruption by supplying a Get Feature count larger than the allocated output buffer. The advisory does not state a severity score. This could be relevant where the Linux CXL subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93069
A use-after-free vulnerability exists in the Linux kernel's OPP (Operating Performance Points) power-management framework, where a cleanup ordering error can cause the kernel to access memory that has already been freed. An attacker able to trigger this condition could potentially crash the system or corrupt kernel memory, though the advisory does not state a specific severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in ECUs or infotainment units. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93066
A use-after-free vulnerability in the Linux kernel's x86 memory attribute handling allows concurrent module loading and unloading to corrupt freed page-table memory, potentially causing crashes or fatal faults. This could be relevant where the Linux kernel is deployed in automotive systems, since the flaw affects core memory management used during module operations. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93063
The Linux kernel iwlwifi mei driver has a buffer overflow vulnerability where the SAP message size is not validated before reading, allowing an attacker to potentially overflow a local buffer. This could be relevant where the Linux kernel iwlwifi mei component is deployed in automotive systems, such as in infotainment or telematics units using Intel wireless hardware. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93060
A use-after-free vulnerability exists in the Linux kernel's drm/msm/adreno driver, specifically in the a6xx_gpu_init() error path, where the a6xx_destroy() function frees memory that is subsequently accessed. An attacker could potentially exploit this memory corruption to cause a crash or other undefined behavior, though the advisory does not state a specific severity rating. This could be relevant where the Qualcomm Adreno GPU driver is deployed in automotive systems, such as in infotainment or instrument-cluster platforms using affected Qualcomm SoCs. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93054
A flaw in the Linux kernel's UIO driver framework can leave a stale pointer after a failed device registration, so a process that opens the device during that window could later trigger a use-after-free memory access. This could be relevant where the Linux UIO subsystem is deployed in automotive or embedded systems, since UIO is commonly used to expose hardware devices to userspace drivers. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93050
The Linux kernel's ipack/ipoctal serial driver has three memory-safety flaws that can be triggered when the device is removed while a terminal session is still open, allowing an attacker to cause use-after-free and null-pointer-dereference crashes. This could be relevant where the Linux ipack subsystem and ipoctal driver are deployed in automotive or embedded systems, though the advisory does not confirm any automotive deployment. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93045
A flaw in the Linux kernel's BPF arena memory management allows an attacker to free memory using an address below the arena base, which can corrupt the free tree and cause a later allocation to return an address outside the intended arena mapping. The advisory does not state a severity rating. This could be relevant where the Linux kernel's BPF subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93043
The Linux kernel BPF subsystem does not recognize a specific instruction used by the insn_array map, causing a kernel BUG and crash at runtime when the BPF interpreter processes it. The fix forces just-in-time compilation so the interpreter is not used for this instruction. This could be relevant where the Linux kernel is deployed in automotive systems, such as ECUs or telematics units running BPF-based networking or tracing. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93044
A flaw in the Linux kernel's BPF subsystem allows arena-related instructions to fall back to the interpreter, which does not support them, causing a kernel crash (BUG_ON) at runtime. An attacker able to trigger this path could crash the kernel, resulting in a denial-of-service condition; the advisory does not state a formal severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, so confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-92518
The Linux kernel contains a vulnerability in its RISC-V BPF tailcall handling that, when the CONFIG_CFI_CLANG option is enabled, causes the kernel stack to become corrupted. An attacker able to trigger this condition could corrupt kernel memory, potentially leading to a crash or other unpredictable system behavior. The advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-92514
The Linux kernel's erdma RDMA driver has a use-after-free flaw in its completion-event-queue cleanup path, where a tasklet can still access freed queue memory after the associated interrupt is removed. An attacker able to trigger this race could cause memory corruption or a system crash, though the advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-92513
A use-after-free vulnerability in the Linux kernel's RDMA/mana_ib driver allows a race condition during queue-pair table insertion to leave stale references, so a concurrent completion handler can access memory after the QP is freed. This could be relevant where the Linux kernel RDMA subsystem is deployed in automotive systems, though the advisory does not confirm any automotive deployment. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-92512
The Linux kernel RDMA core has a use-after-free flaw in ib_query_qp() where a queue pair can still be accessed while it is being destroyed, because the resource tracking removal happens too late in the teardown path. An attacker able to trigger this race could cause a use-after-free, potentially leading to a crash or memory corruption. The advisory does not state a severity rating. This could be relevant where the Linux kernel RDMA subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.