Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
1962advisories found
nvdhigh
cve-2026-89463
A use-after-free flaw in the Linux kernel's ucs1002 power-supply driver can let an attacker trigger memory corruption when the driver is unbound, because a delayed work item can run after the driver's data has been freed. The advisory does not state a severity score. This could be relevant where the ucs1002 driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89460
The Linux kernel's s390 cpum_cf performance-monitoring code can crash the kernel with a NULL pointer dereference when CPUs are brought online during a perf run, because per-CPU event structures are only created for CPUs that were online at event creation. An attacker or operator able to trigger CPU hotplug while a per-task perf event is active could cause a kernel panic, representing a denial-of-service condition. This could be relevant where the Linux kernel is deployed in automotive systems, particularly on s390-based platforms, though the advisory does not confirm automotive deployment; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-89455
The Linux kernel's PLDA PCIe controller driver contains a use-after-free vulnerability in its interrupt teardown code, where event IRQs can be freed after the domain they belong to has already been removed. An attacker able to trigger this teardown path could cause the kernel to dereference freed memory, potentially leading to a crash or other memory-corruption effects. The advisory does not state a severity rating. This could be relevant where the PLDA PCIe controller driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-81017
A flaw in the Linux kernel's Chrome OS sensor hub driver allows a malformed event from the embedded controller to trigger an out-of-bounds read and write of a sensor state array, because the sensor number in the event is not validated before use. An attacker able to supply such a malformed event could corrupt or read memory beyond the intended array. The advisory does not state a severity rating. This could be relevant where this Linux kernel driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-81008
A use-after-free flaw in the Linux kernel's interconnect framework can be triggered when a memory allocation fails during path setup, leaving corrupted internal lists that a later operation may access, potentially causing a crash or memory corruption. This could be relevant where the Linux interconnect framework is deployed in automotive systems, for example in embedded or vehicle control platforms. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-81003
The Linux kernel's AF_IUCV networking code did not verify that incoming frames arrived on the correct network device before delivering them to a socket, allowing frames from one device or namespace to reach sockets bound elsewhere. An attacker could exploit this to exhaust accept queues and cause a denial of service, inject data into existing connections, spoof peer identity, or kill established connections, and the advisory notes AF_IUCV over HiperSockets has no per-connection authentication. This could be relevant where the Linux kernel's IUCV/HiperSockets networking is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-81002
A flaw in the Linux kernel's XDP zero-copy packet handling lets a specially crafted AF_XDP packet redirected through cpumap cause an out-of-bounds memory write, which can crash the kernel. The advisory does not state an automotive connection; this could be relevant where the Linux kernel is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-81001
The Linux kernel's SLIP serial-line driver contains a use-after-free vulnerability in sl_sync() where a network device pointer stored in the slip_devs[] table can be dereferenced after the device has been freed, because the table holds no reference and the teardown path runs without the lock that slip_open() relies on. An attacker able to trigger this race could cause a use-after-free read, which the advisory reports as a KASAN-detected memory-safety bug in the kernel. This could be relevant where the Linux kernel is deployed in automotive systems, but the advisory does not confirm any automotive deployment; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-81000
A flaw in the Linux kernel's TUN/TAP network driver lets an attacker who can influence headroom settings, for example through Open vSwitch, cause memory to be allocated incorrectly, potentially allowing data to be placed outside the intended buffer. The advisory does not confirm automotive use, but this could be relevant where the Linux TUN/TAP driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80997
The Linux kernel's IPA driver, which handles modem network traffic on some mobile platforms, had a bug where the modem transmit queue could become permanently stalled after a runtime power resume, causing cellular data to stop working entirely, including receive traffic. An attacker or normal operation could trigger this condition, resulting in a denial of service on the affected data path, though the advisory does not assign a formal severity score. This could be relevant where the Linux IPA driver is deployed in automotive systems with cellular modems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80995
The Linux kernel's MCTP networking code contains a use-after-free vulnerability in mctp_route_lookup() where the route's device reference is not held while being accessed, allowing an unprivileged local user to trigger a memory corruption condition on the receive/forwarding path without special privileges. This could be relevant where the Linux kernel's MCTP subsystem is deployed in automotive systems, particularly in-vehicle networks using MCTP for ECU communication. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80994
The Linux kernel's Open vSwitch networking component contains a use-after-free vulnerability in how it handles deletion of network flow entries, where a memory pointer can be accessed after it has been freed. An attacker could trigger this race condition to cause a system crash, and the advisory describes it as a real but short-window memory-safety flaw. This could be relevant where the Linux kernel with Open vSwitch is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80991
The Linux kernel's ravb Ethernet driver has a race condition in its PTP clock teardown where an interrupt handler can use the clock after it has been freed, leading to a use-after-free. An attacker able to trigger this race could potentially cause memory corruption or a system crash. The advisory does not state a severity rating. This could be relevant where the ravb driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80986
The Linux kernel's SMC-Rv2 networking code contains an out-of-bounds read in smc_llc_save_add_link_rkeys() that is triggered on every SMC-Rv2 link addition when the device has max_recv_sge equal to 1, causing a kernel memory access beyond the allocated 72-byte queue entry. An attacker able to trigger this code path could cause a kernel out-of-bounds read, which the advisory reports as a KASAN-detected slab-out-of-bounds bug. This could be relevant where the Linux kernel's SMC-R networking stack is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80985
A flaw in the Linux kernel's SMC-Rv2 networking code lets an attacker send a specially crafted message that causes the system to read and act on stale data beyond the intended message boundary, potentially deleting or installing remote memory keys it should not. This could be relevant where the Linux kernel's SMC networking stack is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80981
The Linux kernel's SMC networking code contains a use-after-free flaw in smc_llc_srv_add_link(), where a pointer into a freed queue entry is read after that entry is released. An attacker able to trigger this code path could cause a memory-safety violation, which the advisory demonstrates via a KASAN slab-use-after-free report, though no severity rating is stated. This could be relevant where the Linux kernel's SMC subsystem is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80982
A use-after-free vulnerability in the Linux kernel's net/smc subsystem allows a race condition during connection close to free memory that is still referenced, which an attacker could potentially exploit to corrupt memory or crash the system. This could be relevant where the Linux kernel's SMC networking component is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80979
A use-after-free vulnerability in the Linux kernel's SMC networking subsystem could let an attacker crash the system or potentially execute code by triggering a race condition during connection teardown. The flaw affects the net/smc component, which is a generic kernel networking module rather than an automotive-specific product. This could be relevant where the Linux kernel's SMC networking is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80977
A flaw in the Linux kernel networking code could let an attacker corrupt shared packet memory when Open vSwitch forwards cloned packets, potentially causing data to be decrypted in place over memory the system does not exclusively own. The advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80976
The Linux kernel's IPv6 segment routing (seg6) decapsulation code fails to reset the IPv6 control block after removing outer headers, leaving stale offset data that can cause an out-of-bounds read. An unprivileged local user can trigger this by injecting a crafted packet through a local SID, potentially causing a kernel crash or memory corruption. The advisory does not state a severity score. This could be relevant where the Linux kernel is deployed in automotive systems, such as in IVI units, telematics gateways, or ECUs running Linux. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80975
The Linux kernel's qnap-mcu driver has a flaw where a command timeout can leave a pointer to a stack buffer that a late or unsolicited reply from the MCU then writes into, corrupting memory that has already been left behind. An attacker able to trigger this timing condition could corrupt kernel memory, though the advisory does not state a severity rating. This could be relevant where this driver is deployed in automotive or embedded systems using QNAP MCU hardware; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80971
A use-after-free vulnerability exists in the Linux kernel's ALSA bcd2000 USB audio driver, where disconnecting the device frees memory that a still-open MIDI stream can later write to, potentially causing a crash or memory corruption. This could be relevant where the Linux kernel's bcd2000 driver is deployed in automotive systems, though the advisory does not confirm any automotive deployment. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80962
The Linux kernel's dm-pcache device-mapper target fails to validate geometry fields read from on-disk cache metadata, allowing an out-of-bounds read and write. An attacker who can supply the cache device during a table load, which requires CAP_SYS_ADMIN privileges, could exploit an oversized segment count or out-of-range segment id to access memory beyond the intended buffer. This could be relevant where the Linux kernel and dm-pcache are deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80960
A flaw in the Linux kernel's dm-pcache device-mapper target allows a user with CAP_SYS_ADMIN who supplies the cache device to trigger an out-of-bounds write into kernel heap memory at table load, because the on-media seg_num value is never validated against the actual device size. The advisory does not state a severity rating. This could be relevant where the Linux kernel's dm-pcache target is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-80952
The Linux kernel i3c master driver has a flaw in its device unregister path where a device descriptor is cleared too early, allowing kernel stack memory to leak through generated device identifiers and creating a potential use-after-free. An attacker able to trigger or race this unregister path could read leaked kernel memory or cause memory corruption. The advisory does not state a severity rating. This could be relevant where the Linux i3c subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.