Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
nvdhigh

cve-2026-80951

A flaw in the Linux kernel's I3C master driver lets a device write more data than a buffer can hold, causing an out-of-bounds write into memory. An attacker able to send oversized I3C traffic could corrupt kernel memory, though the advisory does not state a severity rating. This could be relevant where this I3C controller is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80950

The Linux kernel's Renesas I3C driver has a use-after-free flaw in which a timed-out transfer can be freed while an interrupt handler still accesses it, potentially causing a crash. This could be relevant where the Renesas I3C driver is deployed in automotive systems, since I3C is an embedded sensor and peripheral bus, but the advisory does not confirm any automotive deployment. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80947

The Linux kernel's rtl8xxxu Wi-Fi driver contains a use-after-free vulnerability in which a worker thread handling received network data can still run after the device is disconnected and its memory freed, potentially allowing an attacker to corrupt memory or crash the system under active traffic followed by a disconnect. The advisory does not state a severity rating. This could be relevant where the rtl8xxxu driver is deployed in automotive systems, since Linux-based Wi-Fi drivers may be used in in-vehicle infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80944

The Linux kernel's mwifiex Wi-Fi driver has a flaw where an interrupted command wait can leave a pointer to a caller's stack memory attached to a still-pending firmware command, allowing a late firmware response to write into that stale memory and corrupt the kernel stack, which was observed as a kernel panic during repeated Wi-Fi association and disassociation cycles. This could be relevant where the mwifiex driver is deployed in automotive systems, since the advisory notes testing on an i.MX8MP board with an 88W8997 chip, a combination used in embedded and automotive designs. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80937

The Linux kernel's mt7915 Wi-Fi driver fails to validate an address supplied by the device before copying a fixed 16-byte EFUSE block into a driver buffer, allowing a malicious or malfunctioning device to trigger an out-of-bounds write. This could be relevant where MediaTek mt7915 Wi-Fi hardware is deployed in automotive systems, such as in-vehicle infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80935

A flaw in the Linux kernel's mt7996 Wi-Fi driver lets a malicious or malfunctioning Wi-Fi device report an arbitrary EEPROM address, causing an out-of-bounds write of up to MT7996_EXT_EEPROM_BLOCK_SIZE bytes beyond the driver's EEPROM buffer. The advisory does not state a severity rating. This could be relevant where this Wi-Fi chipset is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80932

The Linux kernel's virtio vsock transport has a use-after-free flaw in its device-removal path, where work items are flushed in the wrong order and a receive work item can run after the underlying structure is freed, causing a crash (KASAN slab-use-after-free). An attacker able to trigger this race could cause memory corruption or a denial of service on the affected system. This could be relevant where the Linux kernel's virtio vsock component is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80931

The Linux kernel's DS28E17 1-Wire-to-I2C bridge driver fails to reject an oversized length value supplied by a downstream device during an I2C block read, allowing a read of up to roughly 222 bytes past a 34-byte buffer. An attacker controlling that device could trigger an out-of-bounds read, a memory-safety flaw the advisory treats as a vulnerability requiring a fix. This could be relevant where the DS28E17 bridge or this kernel driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80928

The Linux kernel's Smack security module contained a use-after-free flaw in smack_file_send_sigiotask() caused by accessing the wrong credential pointer for another task, which a KASAN test confirmed could trigger a use-after-free of the credential structure. An attacker able to exploit this race could potentially cause memory corruption or a system crash. The advisory does not state a severity rating. This could be relevant where the Linux kernel with Smack is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80926

The Linux kernel's ksmbd SMB server component contains a use-after-free vulnerability in its oplock break notification handling, which an authenticated client holding a durable batch oplock could exploit to access freed memory. This could be relevant where ksmbd is deployed in automotive systems, such as in-vehicle infotainment or telematics units exposing SMB file-sharing services. Confirm applicability through the product SBOM or dependency inventory.

csaf_microsofthigh

cve-2026-74501

A use-after-free vulnerability exists in the ALSA USB audio driver's ump_to_endpoint() function, which an attacker could exploit to cause memory corruption or a system crash. This could be relevant where the ALSA USB audio subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1164

Multiple vulnerabilities have been discovered in the SUSE Linux kernel, affecting products including SUSE Linux Enterprise Real Time, SUSE Linux Enterprise Server, SUSE Linux Enterprise Live Patching, and SUSE Linux Micro. An attacker could exploit some of these to achieve arbitrary code execution, privilege escalation, or remote denial of service, with the publisher not specifying a severity rating. This could be relevant where the SUSE Linux kernel is deployed in automotive systems, but the advisory does not confirm an automotive connection; confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1162

Multiple vulnerabilities were discovered in the Ubuntu Linux kernel, affecting several Ubuntu releases including 14.04 ESM, 16.04 ESM, 18.04 ESM, 20.04 ESM, 22.04 LTS, 24.04 LTS and 26.04 LTS. An attacker could exploit some of these to gain elevated privileges, cause a remote denial of service, or compromise data integrity, though the advisory does not specify a severity rating. This could be relevant where the Ubuntu Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1161

Multiple vulnerabilities were discovered in the Red Hat Linux kernel, and some of them allow an attacker to achieve arbitrary code execution, privilege escalation, and remote denial of service. The affected product is the Red Hat Linux kernel across numerous Red Hat Enterprise Linux and CodeReady Linux Builder distributions and architectures. The advisory does not specify a severity rating, but it lists impacts including remote denial of service, data integrity compromise, arbitrary code execution, security policy bypass, data confidentiality compromise, and privilege escalation. This could be relevant where the Red Hat Linux kernel is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1163

Multiple vulnerabilities were discovered in the Debian LTS Linux kernel, specifically versions of Debian LTS 12 bookworm prior to 6.1.187-1. An attacker could exploit some of these to gain elevated privileges, compromise data confidentiality, or cause a denial of service. The advisory does not specify a severity rating. This could be relevant where the Debian LTS Linux kernel is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-71640

An issue in ZJU-FAST-Lab EGO-Planner-v2, affecting all versions up to commit 5c99a95880401e2599638d567abc0e240396cb42, allows unsafe vehicle motion because the replanning pipeline improperly handles expired trajectory data. An attacker could exploit this to cause the vehicle to move unsafely. The advisory does not state a severity rating.

certfr_avishigh

certfr-2026-avi-1158

Multiple vulnerabilities have been discovered in Google Android versions 14, 15, 16, 16-qpr2 and 17 without the September 5, 2026 patch, and they could allow an attacker to achieve remote arbitrary code execution, privilege escalation, and impact data confidentiality, integrity, and availability. This could be relevant where Android is deployed in automotive systems, such as in-vehicle infotainment units or telematics components. Confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1136

Multiple vulnerabilities have been discovered in Xen, affecting all versions without the latest security patch. An attacker could exploit these flaws to cause remote denial of service, arbitrary code execution, and security policy bypass. This could be relevant where Xen is deployed in automotive systems, such as a hypervisor for embedded or vehicle infrastructure; confirm applicability through the product SBOM or dependency inventory.

csaf_microsofthigh

cve-2026-80229

OpenSSL has a use-after-free vulnerability in its provider functionality, which could allow an attacker to exploit memory handling errors. The advisory does not confirm automotive deployment, but OpenSSL is a widely used cryptographic library, so this could be relevant where OpenSSL is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

csaf_microsofthigh

cve-2026-80230

OpenSSL pinning bypass vulnerability affects curl, allowing an attacker to bypass certificate pinning. This could be relevant where curl is deployed in automotive systems, such as in telematics or infotainment, potentially enabling man-in-the-middle attacks. Confirm applicability through the product SBOM or dependency inventory.

csaf_microsofthigh

cve-2026-82208

A security advisory addresses a vulnerability in wolfSSL, a TLS library, where a CA-cache hit can override a certificate verification callback, potentially allowing an attacker to bypass expected certificate checks. The affected component is wolfSSL, which could be relevant where wolfSSL is deployed in automotive systems, such as in secure communications for vehicles or infrastructure. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-79379

A buffer overflow vulnerability exists in the SBC_DecodeFrames() function of the Bestechnic BES2300 Bluetooth Audio SoC firmware versions 3.x and earlier, fixed in version 5.0. An attacker could exploit this by sending a crafted frame to cause a Denial of Service (DoS). This could be relevant where the BES2300 is deployed in automotive systems, such as in-vehicle Bluetooth audio components; confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-79378

An issue in the btm_acl_handle() function of Bestechnic BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows an attacker to cause a Denial of Service by sending a crafted L2CAP packet. This could be relevant where the BES2300 is deployed in automotive systems, such as in-vehicle Bluetooth audio components. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-79376

An issue in the l2cap_handle_data() function of Bestechnic BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows an attacker to cause a Denial of Service (DoS) by sending a crafted L2CAP packet. The advisory does not confirm automotive deployment, but this SoC could be relevant where used in automotive audio or infotainment systems. Confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1133

Multiple vulnerabilities in Siemens industrial products, including SIMATIC HMI panels, SIMATIC AX Runtime, and Desigo CC, could allow an attacker to execute arbitrary code and elevate privileges. The advisory does not confirm automotive deployment, but these are industrial control components that could be relevant where such systems are used in automotive manufacturing or related infrastructure. Confirm applicability through the product SBOM or dependency inventory.