Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
nvdhigh

cve-2026-92510

A use-after-free vulnerability in the Linux kernel's RDMA core affects the ib_destroy_srq_user() function, where a shared receive queue (SRQ) could remain accessible through the restrack mechanism during a brief window while its resources are being freed. An attacker could potentially exploit this race condition to access freed memory, which may lead to memory corruption or system instability. The advisory does not state a severity rating. This could be relevant where the Linux RDMA subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-92511

A use-after-free vulnerability in the Linux kernel's RDMA core affects the ib_destroy_cq_user() function, where a completion queue could remain accessible through the restrack mechanism during a brief window while its resources are being freed. An attacker could potentially exploit this race condition to access freed memory, which may lead to memory corruption or further compromise of the affected system. The advisory does not state a severity rating. This could be relevant where the Linux kernel RDMA subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-92509

A use-after-free vulnerability exists in the Linux kernel's RDMA core counter_release() function, where a counter can remain accessible through the restrack mechanism during a brief window while vendor-specific resources are being freed. An attacker could potentially exploit this race condition to access freed memory, though the advisory does not state a specific severity rating. This could be relevant where the Linux kernel RDMA subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-92508

A use-after-free vulnerability in the Linux kernel's RDMA core affects the ib_free_cq() function, where a completion queue could remain accessible through the restrack mechanism during a brief window while its resources are being freed. An attacker could potentially exploit this race condition to access freed memory, which may lead to a crash or other memory-corruption effects, though the advisory does not state a specific severity rating. This could be relevant where the Linux RDMA subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-92507

A use-after-free vulnerability exists in the Linux kernel's RDMA core, specifically in the ib_dealloc_pd_user() function, where a protection domain (PD) can remain briefly accessible after its associated resources have been freed. An attacker could potentially exploit this short window to access freed memory, which may lead to memory corruption or further compromise of the affected system. The advisory does not state a severity rating. This could be relevant where the Linux kernel RDMA subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-92506

The Linux kernel's ARM SCMI firmware interface has a race condition in how it handles removal of requested devices, which can cause memory to be freed twice when two drivers for the same protocol unregister at the same time. An attacker who can trigger this concurrent unregistration could cause a use-after-free, potentially leading to a crash or memory corruption, though the advisory does not state a severity rating. This could be relevant where the Linux kernel's ARM SCMI subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-92500

A race condition in the Linux kernel's ext4 filesystem could let a concurrent operation cause a crash or data loss during file writes, and the advisory rates this as a resolved kernel vulnerability. This could be relevant where the Linux kernel is deployed in automotive systems, since the affected component is a general-purpose operating system kernel rather than an automotive-specific product. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-92499

A flaw in the Linux kernel's ext4 file system lets a corrupted directory cause an out-of-bounds memory read, which the kernel reports as a use-after-free, when the system resumes reading a directory from an invalid position. An attacker able to supply a malformed directory could trigger this memory access error, though the advisory does not state a severity rating. This could be relevant where the Linux kernel's ext4 file system is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-92489

A flaw in the Linux kernel's xfrm networking code can cause a packet buffer to be freed twice when netfilter drops a packet, potentially leading to memory corruption or a system crash. The advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-92482

A use-after-free vulnerability exists in the Linux kernel's MediaTek pinctrl driver, where the GPIO chip memory is freed while still registered if the driver is unloaded or unbound as a module. An attacker could potentially exploit this memory corruption to cause a crash or execute code, though the advisory does not state a specific severity score. This could be relevant where MediaTek pinctrl drivers are deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90435

A flaw in the Linux kernel's RDMA/mlx5 driver lets a user with access to the affected interface supply oversized queue-pair parameters that overflow an internal size calculation, causing the kernel to map a buffer smaller than the hardware will write into. This could allow memory corruption or unintended memory access, and the advisory does not state a severity rating. This could be relevant where the mlx5 RDMA driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90431

The Linux kernel remoteproc subsystem has a flaw where a crash-handling work item can race with driver removal, potentially causing use-after-free memory corruption. An attacker who can trigger this race could crash the system or possibly execute code with kernel privileges, though the advisory does not assign a specific severity score. This could be relevant where the Linux remoteproc framework is deployed in automotive systems, for example in SoCs managing remote processor cores. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90427

The Linux kernel's tegra241-cmdqv IOMMU driver contains a use-after-free flaw where a probe failure after devm_krealloc() could cause the caller to dereference the freed original smmu structure. An attacker able to trigger this failure path could potentially cause a crash or memory corruption, though the advisory does not state a severity rating. This could be relevant where this driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90423

The Linux kernel's RDMA/rxe subsystem contains a use-after-free flaw in the ODP memory-region initialization error path, where a failed initialization leaves a stale pointer that is later accessed after being freed. An attacker able to trigger this error condition could cause the kernel to read freed memory, which may lead to a crash or potentially further exploitation, though the advisory does not state a severity rating. This could be relevant where the Linux kernel RDMA/rxe component is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90421

The Linux kernel PCI subsystem has a use-after-free vulnerability where a device probe running at the same time as dynamic ID removal can access freed memory. An attacker able to trigger this race condition could potentially cause memory corruption or a system crash. This could be relevant where the Linux kernel is deployed in automotive systems, so confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90414

The Linux kernel's iSER target driver (IB/isert) fails to verify that the data length declared in an incoming iSCSI PDU matches the number of bytes actually received, allowing a remote initiator to trigger an out-of-bounds read of the receive buffer and, in one code path, to write heap memory beyond the descriptor through to the backing store. The advisory rates this as a kernel memory-safety vulnerability with a KASAN slab-out-of-bounds report, exploitable after iSCSI login completes. This could be relevant where the Linux kernel's iSER target is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90413

The Linux kernel's iSCSI target driver for RDMA (IB/isert) fails to verify that a login request's declared data length matches the bytes actually received, allowing an unauthenticated attacker to trigger an out-of-bounds read of up to 8193 bytes from a fixed 8192-byte buffer before authentication. This could be relevant where the Linux kernel's IB/isert component is deployed in automotive systems, though the advisory does not confirm any automotive deployment. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90398

The Linux kernel's ath11k Wi-Fi driver has a memory allocation flaw in mac_phy_caps_parse() where the buffer is sized using a clamped length but written to using the full struct size, so when firmware sends short TLVs, later entries are written past the end of the allocated buffer. An attacker able to supply crafted firmware data could trigger out-of-bounds memory writes, which may lead to memory corruption or a crash. The advisory does not state a severity rating. This could be relevant where the ath11k Wi-Fi driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90399

The Linux kernel's ath12k Wi-Fi driver has a memory allocation bug in mac_phy_caps_parse() where the buffer is sized using a clamped length but written to using full-struct pointer arithmetic, so short firmware TLVs can cause writes past the end of the allocated buffer. An attacker able to supply crafted firmware data could trigger out-of-bounds memory writes, which may lead to memory corruption or a crash; the advisory does not state a severity rating. This could be relevant where the ath12k Wi-Fi driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90393

A race condition in the Linux kernel's BPF networking link update code can let two concurrent update operations interfere, potentially causing a use-after-free memory error. This could allow an attacker with the ability to trigger concurrent BPF link updates to crash the system or possibly execute code, though the advisory does not state a severity rating. This could be relevant where the Linux kernel's BPF networking subsystem is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90392

The Linux kernel has a use-after-free vulnerability in its BPF subsystem where reading BPF link information can access a program pointer without proper locking, allowing a concurrently freed program to be used. An attacker able to trigger this race condition could potentially cause memory corruption or a crash. The advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90380

A use-after-free race condition in the Linux kernel's mt76 driver for mt792x Wi-Fi chipsets can be triggered in mt76_rx_poll_complete when a station has already been removed but a receive status still holds a pointer to it, causing an invalid memory access. This could be relevant where mt792x Wi-Fi hardware is deployed in automotive systems, since an attacker able to trigger the race could cause a kernel crash or memory corruption. The advisory does not state an explicit severity rating. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90379

The Linux kernel's mt76 driver for MediaTek mt7921 Wi-Fi chipsets was updated to fix a flaw where a PCIe bus error could cause the driver to read invalid data and crash the system through an invalid memory access. An attacker able to trigger such a bus error could crash the affected system, though the advisory does not assign a numeric severity score. This could be relevant where mt7921 Wi-Fi hardware is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90363

A use-after-free flaw in the Linux kernel's MSM display driver (drm/msm) can crash the system when KMS initialization fails partway through, because the KMS state is torn down twice. An attacker able to trigger this failure path could cause a denial-of-service crash. This could be relevant where the MSM display driver is deployed in automotive systems, such as Qualcomm-based in-vehicle infotainment or display units. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-90358

A flaw in the Linux kernel's BPF x86 trampoline code causes the stack area for saving registers to be too small when a function argument is 128 bits wide, so saving arguments can overwrite adjacent stack memory. An attacker able to trigger this condition could corrupt kernel stack memory, though the advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.