Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
1962advisories found
nvdhigh
cve-2026-90356
A use-after-free vulnerability in the Linux kernel's mt76 Wi-Fi driver (mt7996 chipset) could let an attacker trigger memory corruption by causing a device reset while certain interface links are being freed. This could be relevant where this Wi-Fi chipset is deployed in automotive systems, such as in-vehicle infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-90353
The Linux kernel's mt76 driver for mt7915 Wi-Fi hardware contains a use-after-free vulnerability on an error path during device registration, where the extended PHY hardware is freed while still registered with the mac80211 subsystem. An attacker could potentially exploit this memory corruption to cause a crash or achieve code execution, though the advisory does not state a severity rating. This could be relevant where this Wi-Fi chipset is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-90349
A flaw in the Linux kernel's mt7996 Wi-Fi driver (part of the mt76 family) allowed an unchecked link identifier to be used as an array index, potentially causing an out-of-bounds access. An attacker able to trigger this condition could cause memory corruption or a system crash, though the advisory does not state a specific severity rating. This could be relevant where the mt7996 Wi-Fi chipset is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-90348
A flaw in the Linux kernel's ath10k Wi-Fi driver for Qualcomm WCN3990/SNOC chipsets causes a kernel crash and a failed firmware memory dump when the driver tries to collect crash data, because it uses an unsafe memory copy method on a memory region that does not allow unaligned access. The fix replaces that copy routine with a safer one. This could be relevant where this Qualcomm Wi-Fi chipset and driver are deployed in automotive systems, since the crash also breaks modem recovery. Confirm applicability through the product SBOM or dependency inventory.
certfr_avishigh
certfr-2026-avi-1192
Multiple vulnerabilities in ISC BIND, a DNS server component, could allow a remote attacker to cause a denial of service, compromise data integrity, and bypass security policy. This could be relevant where BIND is deployed in automotive systems, for example in vehicle back-end, telematics, or connected-infrastructure DNS services, though the advisory does not confirm an automotive deployment. Confirm applicability through the product SBOM or dependency inventory.
certfr_avishigh
certfr-2026-avi-1182
A vulnerability in F5 NGINX Open Source (versions up to 1.30.5 and 1.31.x before 1.31.6) could let a remote attacker cause a denial of service and compromise data integrity. This could be relevant where NGINX is deployed in automotive systems, such as backend or telematics infrastructure. Confirm applicability through the product SBOM or dependency inventory.
certfr_avishigh
certfr-2026-avi-1180
A vulnerability in strongSwan versions before 6.1.0 allows a remote attacker to cause a denial of service. This could be relevant where strongSwan is deployed in automotive systems, since it is an IPsec VPN component that may be used in connected vehicle or telematics environments. Confirm applicability through the product SBOM or dependency inventory.
certfr_avishigh
certfr-2026-avi-1172
Multiple vulnerabilities have been discovered in Apple products including iOS, iPadOS, macOS, Safari, Xcode, tvOS, watchOS and visionOS, and they could allow an attacker to achieve remote arbitrary code execution, privilege escalation and remote denial of service, along with data confidentiality and integrity impacts and security policy bypass. This could be relevant where Apple platforms or components are deployed in automotive systems, such as in-vehicle infotainment, telematics or fleet management environments. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89772
A flaw in the Linux kernel's btrfs filesystem affects how data is protected during writeback, and an attacker with a program that has a file memory-mapped could modify data while it is being written, potentially causing data corruption, lost writes, or invalid checksums. This could be relevant where the Linux kernel with btrfs is deployed in automotive systems, such as in infotainment or telematics units, though the advisory does not confirm any specific automotive deployment. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89762
The Linux kernel's AppArmor security module contains a use-after-free vulnerability in credential handling that could allow an attacker to access freed memory, potentially leading to a system crash or other memory corruption. This could be relevant where the Linux kernel with AppArmor is deployed in automotive systems, including ECUs or telematics units running Linux. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89761
The Linux kernel's AppArmor security module contains an out-of-bounds write vulnerability in how it handles label vectors, which an unprivileged local attacker could trigger by writing to a specific system file or through a system call, potentially causing memory corruption. This could be relevant where the Linux kernel with AppArmor is deployed in automotive systems, though the advisory does not confirm any automotive deployment. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89760
The Linux kernel has a memory-management flaw in how hibernation swap slots are freed, which can cause silent memory corruption, process crashes, or data instability across unrelated applications, typically while uswsusp is preparing a hibernation image. This could be relevant where the Linux kernel is deployed in automotive systems, since the affected component is a general-purpose operating system kernel rather than an automotive-specific product. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89758
The Linux kernel memory-management code can mishandle a specific non-present huge-page entry created when an HMM-based GPU driver migrates memory to device memory, potentially causing a kernel crash or incorrectly removing an unrelated live page from the LRU list. This could be relevant where the Linux kernel is deployed in automotive systems, particularly those using HMM-based GPU drivers. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89754
The Linux kernel memory-management pagewalk code can, under specific conditions, leave an internal state flag set incorrectly, causing duplicate callbacks and an out-of-bounds write that a local attacker could trigger to corrupt kernel memory. The advisory rates this as a kernel memory-safety bug demonstrated by a local fuzzer, and it is fixed in the kernel. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89750
A use-after-free vulnerability exists in the Linux kernel's user_events tracing subsystem, where a failed memory allocation during process forking can leave a stale pointer that later causes memory corruption. An attacker could potentially trigger this flaw to cause a crash or other memory-safety issues, though the advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89746
The Linux kernel tracing subsystem contains a use-after-free vulnerability in its histogram trigger handling, where registering two same-named triggers on different events leaves a dangling pointer that a later trigger can dereference. An attacker with local access to the tracing interface can trigger a kernel panic, crashing the system. This could be relevant where the Linux kernel is deployed in automotive systems, such as in ECUs or telematics units running an affected kernel version. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89742
A use-after-free vulnerability in the Linux kernel's RapidIO mport character device driver (mport_cdev) allows a local user to trigger memory corruption by racing a mapping release against a DMA request cleanup, potentially causing a crash or other undefined behavior. The advisory does not state a severity score. This could be relevant where RapidIO mport hardware and this kernel driver are deployed in automotive or embedded systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89739
The Linux kernel's USB dwc3 gadget driver contains a use-after-free vulnerability in dwc3_gadget_free_endpoints, where a delayed work item can still be pending or running when the endpoint memory is freed during gadget removal. An attacker able to trigger this race condition could cause the kernel to access freed memory, which may lead to a crash or potentially other memory-corruption effects. The advisory does not state a severity rating. This could be relevant where the Linux dwc3 USB gadget driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89736
A use-after-free vulnerability exists in the Linux kernel's USB gadget audio driver (u_audio), where disconnecting a sound card can free memory while userspace applications still hold open ALSA control file descriptors, allowing those applications to trigger memory corruption. An attacker able to access or close those open descriptors could cause a use-after-free, which is a memory corruption issue. This could be relevant where the Linux USB gadget audio subsystem is deployed in automotive systems, for example in embedded or in-vehicle USB audio functions. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89733
The Linux kernel USB gadget UVC driver has a use-after-free vulnerability where error handling in uvc_function_bind() and uvc_function_unbind() leaves dangling pointers after freeing memory, which an attacker could potentially exploit to corrupt memory or execute code. This could be relevant where the Linux USB gadget UVC driver is deployed in automotive systems, such as in-vehicle infotainment or camera subsystems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89729
A flaw in the Linux kernel's HID sensor-hub driver allows a malicious HID descriptor to trigger an out-of-bounds write when a feature field advertises a large size but the caller supplies a small buffer, potentially corrupting memory. This could be relevant where the Linux HID sensor-hub component is deployed in automotive systems, since a crafted HID device could exploit the flaw to write beyond the intended buffer. The advisory does not state a severity rating. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89728
The Linux kernel's Renesas I3C controller driver contains an out-of-bounds access bug that occurs when the I3C bus is empty during Dynamic Address Assignment, allowing the driver to read or write beyond the intended device bitmask. This could be relevant where the Renesas I3C controller driver is deployed in automotive systems, since I3C is an embedded sensor and peripheral bus used in some automotive and embedded designs. The advisory does not state a severity rating. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89725
The Linux kernel's STM32 CEC driver contains an out-of-bounds write: a connected CEC peer can keep sending bytes without ending its message, pushing a length counter past the fixed 16-byte buffer and writing attacker-controlled data into surrounding memory. This is reachable in normal operation without local privileges, and the advisory does not state a severity score. This could be relevant where the STM32 CEC driver is deployed in automotive systems, since CEC is a consumer-electronics control protocol rather than an automotive bus. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89724
A flaw in the Linux kernel's vicodec media driver lets a crafted video frame trigger an out-of-bounds write in the FWHT encoder, corrupting adjacent kernel heap memory. This could be relevant where the Linux kernel's vicodec media component is deployed in automotive systems, such as in infotainment or camera-processing platforms. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89723
The Linux kernel's nilfs2 file system has a flaw where truncating a file can leave an intermediate B-tree node block behind, causing an out-of-bounds memory access when the log writer later processes it incorrectly. An attacker able to trigger this condition could cause a memory corruption or crash, though the advisory does not state a severity rating. This could be relevant where the Linux kernel with nilfs2 is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.