Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
cvelistv5high

cve-2026-79378

An issue in the btm_acl_handle() function of Bestechnic BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows an attacker to cause a Denial of Service by sending a crafted L2CAP packet. This could be relevant where the BES2300 is deployed in automotive systems, such as in-vehicle Bluetooth audio components. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-20512

The advisory describes a privilege escalation vulnerability in the Audio HAL component of MediaTek chipsets, caused by improper input validation. An attacker who already has System privilege could exploit this to gain further elevated privileges locally, without requiring user interaction. This could be relevant where MediaTek chipsets are deployed in automotive systems, so confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-80865

The Linux kernel contains a vulnerability in the BPF subsystem where a missing access_ok check allows improper access to user-space pointers via get_user. An attacker could potentially exploit this to cause memory access errors or other undefined behavior. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80864

This advisory addresses a use-after-free vulnerability in the RDMA/rxe component of the Linux kernel, specifically triggered during a modify_qp operation related to IB_QP_MAX_DEST_RD_ATOMIC. An attacker could exploit this flaw to cause memory corruption, potentially leading to a system crash or unauthorized code execution. The severity is not explicitly stated in the advisory, but the technical impact involves a responder use-after-free. This could be relevant where the Linux kernel with RDMA/rxe is deployed in automotive systems, such as for high-performance in-vehicle networking or telematics. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80857

The advisory describes a use-after-free vulnerability in the Linux kernel's FUSE filesystem driver, where an attacker could potentially cause a system crash or memory corruption if a specific abort operation races with request processing. This could be relevant where the Linux kernel with FUSE is deployed in automotive systems, such as in infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80853

The advisory describes a bug in the Linux kernel's KVM subsystem affecting memory encryption operations for SEV and SEV-ES guests on AMD SNP-enabled hosts, where a temporary buffer not allocated as a full page can cause the kernel to crash with a page fault and panic. An attacker could potentially trigger this denial-of-service condition by causing the kernel to access a firmware-owned page during these operations. The severity is not explicitly rated, but the impact is a system crash. This could be relevant where Linux KVM with AMD SEV/SNP is deployed in automotive cloud or server infrastructure, though the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80852

The advisory describes a fix for an out-of-bounds write vulnerability in the tls_append_frag() function within the Linux kernel's TLS device implementation. An attacker could potentially exploit this flaw to cause memory corruption, which may lead to system instability or unauthorized code execution. This could be relevant where the Linux kernel's TLS functionality is deployed in automotive systems, such as in infotainment or connectivity modules, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80850

The advisory describes a use-after-free vulnerability in the Linux kernel's TCP-AO (TCP Authentication Option) feature, where a race condition during network configuration changes can cause freed memory to be accessed, potentially leading to a kernel crash or memory corruption. The affected component is the Linux kernel's TCP stack, which is a generic operating system component, not specifically an automotive product. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or connectivity modules, but the advisory does not confirm any automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80849

The advisory describes a use-after-free vulnerability in the Linux kernel's TCP Authentication Option (TCP-AO) implementation, where a freed memory object could be accessed during a reconnect to a different peer. An attacker could potentially exploit this flaw to cause memory corruption or a system crash, with the issue rated as a kernel security fix. This could be relevant where the Linux kernel with TCP-AO is deployed in automotive systems, such as for secure vehicle-to-vehicle or telematics communications, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80848

The advisory describes a use-after-free vulnerability in the Linux kernel's xfrm ESP-in-TCP implementation, which could be triggered during connection close. An attacker could potentially exploit this flaw to cause memory corruption or a system crash, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80844

This advisory addresses a vulnerability in the Linux kernel's xfrm AH6 module, which handles IPv6 authentication headers for network security. An attacker could exploit insufficient validation of routing header segments_left to potentially cause a denial of service or other unspecified impacts. The severity is not explicitly stated in the provided text. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or connectivity units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80842

This advisory addresses a use-after-free vulnerability in the Linux kernel's network bridge multicast handling, specifically involving a master VLAN's multicast context. An attacker could potentially exploit this flaw to cause memory corruption or a system crash, impacting system stability. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or connectivity modules, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80839

The Linux kernel contains a vulnerability in the batman-adv networking component, which handles multicast data in mesh networks. An attacker could exploit this flaw by sending a specially crafted multicast packet with an oversized offset, potentially causing the kernel to access memory beyond the intended data buffer. This could be relevant where batman-adv is deployed in automotive systems, such as for in-vehicle or vehicle-to-vehicle mesh communication, though the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80833

The advisory describes a fix in the Linux kernel that removes the sun8i-ss crypto driver's random number generator interface due to bugs, including a use-after-free vulnerability and a buffer overread issue. An attacker could potentially exploit these bugs to cause memory corruption or information disclosure. This could be relevant where the sun8i-ss driver is deployed in automotive systems, such as in embedded Linux platforms for security functions. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80829

This advisory addresses a vulnerability in the ALSA USB-audio driver for Linux, specifically an out-of-bounds write in the snd_usbmidi_novation_output() function. An attacker could exploit this flaw to cause memory corruption, potentially leading to system instability or arbitrary code execution, though the advisory does not specify a severity rating. This could be relevant where the Linux USB-audio driver is deployed in automotive systems, such as for in-vehicle infotainment or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80826

The advisory addresses a use-after-free vulnerability in the Linux kernel's USB driver for the Cypress c67x00 controller, specifically in the function c67x00_add_iso_urb(). An attacker could exploit this flaw to cause memory corruption, potentially leading to a system crash or arbitrary code execution, with the severity not explicitly stated in the provided text. This could be relevant where the c67x00 USB controller is deployed in automotive systems, such as for in-vehicle USB connectivity, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80825

The advisory describes a bug in the Linux kernel affecting the mt7925 Wi-Fi chipset driver, which could cause a system crash when forwarding network frames over a bridged connection. An attacker could potentially trigger this crash by sending specially crafted traffic to a device using this chipset, leading to a denial of service. This could be relevant where the mt7925 chipset is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80824

The advisory addresses a use-after-free vulnerability in the USB filesystem (usbfs) code within the Linux kernel, specifically in the usbdev_release() function, which could allow an attacker to exploit memory corruption. The affected component is the USB device handling in the kernel, and while no automotive connection is confirmed, this could be relevant where Linux-based USB stacks are deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory. The advisory does not state a specific severity rating.

nvdhigh

cve-2026-80818

The advisory describes a use-after-free vulnerability in the Linux kernel's Tegra241 command queue virtualization driver, where memory is freed before it is accessed during device teardown, potentially causing a system crash. The affected component is an IOMMU driver for NVIDIA Tegra hardware, which could be relevant in automotive systems that use this specific embedded processor platform. An attacker could potentially trigger a denial-of-service condition through system instability, though the advisory does not confirm actual automotive deployment. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80814

The advisory describes a fix for an overflow check in the rndis_host driver, which is part of the Linux kernel and handles Remote Network Driver Interface Specification (RNDIS) networking. An attacker could exploit this overflow to cause memory corruption or a system crash, with the severity not explicitly stated in the provided text. This could be relevant where the rndis_host driver is deployed in automotive systems, such as for USB-based network connections, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80813

The advisory describes a NULL pointer dereference vulnerability in the Linux kernel's NVMe target (nvmet) component, specifically in the function that handles Identify commands for listing active namespace IDs. An attacker could trigger a system crash (oops) by sending a crafted command, and the fix corrects a logical error in how command-set filtering is performed. The severity is not explicitly stated, but the impact is a denial-of-service through a kernel crash. This could be relevant where the Linux kernel's nvmet is deployed in automotive systems, such as for in-vehicle storage or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80810

The advisory describes a bug in the Linux kernel's io_uring subsystem, specifically in how it calculates memory sizes for registered buffers. An attacker could exploit this flaw to cause a buffer overflow, potentially leading to memory corruption or a system crash, with the issue affecting systems using very large memory pages (16G or more) on certain architectures like arm64 and powerpc. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80795

This advisory addresses an out-of-bounds write vulnerability in the NFC (Near Field Communication) NCI subsystem of the Linux kernel, specifically in the function nci_target_auto_activated(). An attacker could exploit this flaw to cause memory corruption, potentially leading to system instability or unauthorized code execution. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel with NFC support is deployed in automotive systems, such as for keyless entry or infotainment, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80792

This advisory addresses a use-after-free vulnerability in the Linux kernel's IPv6 networking code, specifically in the ip6_finish_output2() function. An attacker could potentially exploit this flaw to cause memory corruption or a system crash, impacting system availability. This could be relevant where Linux-based systems with IPv6 networking are deployed in automotive systems, such as infotainment or telematics units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80787

The advisory describes a use-after-free vulnerability in the Linux kernel's nvmet PCI endpoint function driver, where an I/O command can complete and free its memory before the driver reads certain data fields, potentially allowing memory corruption or a crash. The affected component is a generic kernel module for NVMe storage over PCIe, which could be relevant where this driver is deployed in automotive systems for data storage or processing. This could be relevant where the nvmet PCI endpoint function driver is deployed in automotive systems, and the stated severity is a kernel bug that could lead to system instability or unauthorized memory access. Confirm applicability through the product SBOM or dependency inventory.