Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
nvdhigh

cve-2026-80778

The advisory describes a vulnerability in the Linux kernel's futex/pi component, where a private futex owner from a different memory space could cause a use-after-free condition, potentially leading to system instability or unauthorized access. The affected component is the Linux kernel, which is a generic operating system core, and its automotive relevance is not confirmed by the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in vehicle infotainment or control units. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80775

The advisory describes a race condition in the Linux kernel's futex subsystem, which manages thread synchronization. An attacker could exploit this flaw to cause a use-after-free condition, potentially leading to memory corruption or a system crash. The affected component is the Linux kernel itself, which is a generic operating system component; this could be relevant where Linux is deployed in automotive systems, such as in infotainment or control units. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80767

A security fix addresses a use-after-free vulnerability in the enable_sensor function of a custom sensor component, where an attacker could potentially exploit the flaw to cause memory corruption or system instability. The advisory does not specify a severity rating or confirm any automotive deployment. This could be relevant where this sensor component is deployed in automotive systems, but the advisory does not confirm such use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80764

A vulnerability exists in the Linux kernel's Bluetooth subsystem involving a use-after-free issue in the HCI event handling that can occur during a reset. An attacker could potentially exploit this flaw to cause memory corruption or a system crash. The severity is not explicitly stated in the advisory. This could be relevant where the Linux Bluetooth stack is deployed in automotive systems, such as for in-vehicle infotainment or telematics. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80763

This advisory addresses a vulnerability in the Linux kernel's Bluetooth subsystem, specifically in the handling of LE Set CIG Parameters responses, where missing validation could allow an attacker to exploit the flaw. The technical impact involves potential memory corruption or system instability through a malformed Bluetooth packet, with severity not explicitly stated in the provided text. This could be relevant where Bluetooth functionality is deployed in automotive systems, such as for infotainment or telematics, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80762

The advisory addresses a use-after-free vulnerability in the Bluetooth HCI synchronization code within the Linux kernel, which could be exploited during system suspend operations. An attacker could potentially leverage this flaw to cause memory corruption or system instability, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel's Bluetooth stack is deployed in automotive systems, such as for in-vehicle infotainment or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80760

This vulnerability affects the Linux kernel's Bluetooth MGMT subsystem, where a malformed HCI command with a parameter length exceeding 255 bytes can cause the controller to misinterpret trailing data as the start of a new packet. An attacker could exploit this to disrupt Bluetooth communications or potentially inject malicious data. The advisory does not confirm automotive deployment, but this could be relevant where Linux-based Bluetooth stacks are deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdhigh

cve-2026-80759

The advisory addresses a vulnerability in the Linux kernel's Bluetooth driver, specifically in the firmware download process for the hci_aml component. An attacker could exploit a malformed or truncated firmware image to cause the driver to read past the intended memory boundaries, potentially leading to system instability or unauthorized access. The severity is not explicitly stated, but the fix involves adding validation checks to reject invalid firmware images. This could be relevant where the Linux kernel's Bluetooth stack is deployed in automotive systems, such as for in-vehicle infotainment or telematics. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-79390

Trueview TI8161 6.0.23.4 transmits MQTT communications in plaintext over TCP port 1883, allowing an unauthenticated attacker on the same network segment to intercept and obtain sensitive device information, operational data, and control-related details. This could be relevant where the Trueview TI8161 is deployed in automotive systems, such as fleet or telematics applications, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1120

Multiple vulnerabilities were found in the SUSE Linux kernel, which could allow an attacker to cause data integrity issues, bypass security policies, or trigger an unspecified security problem. The advisory does not confirm any automotive deployment, but the Linux kernel is a common component in embedded and automotive systems. This could be relevant where the SUSE Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1119

Multiple vulnerabilities have been discovered in the Linux kernel as packaged by Debian, which could allow an attacker to cause a denial of service, a breach of data confidentiality, and privilege escalation. The affected versions are Debian trixie releases prior to 6.12.107-1, and the fix is available through the vendor's security bulletin. This could be relevant where the Linux kernel is deployed in automotive systems, as it is a common component in such environments, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1118

Multiple vulnerabilities were found in the Red Hat Linux kernel, which could allow an attacker to execute arbitrary code, elevate privileges, or cause a remote denial of service. The advisory does not confirm any automotive deployment, so this could be relevant where the Red Hat Linux kernel is used in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1117

Multiple vulnerabilities have been found in the Linux kernel as used in Ubuntu 20.04 ESM and 18.04 ESM, allowing an attacker to cause an unspecified security issue. The severity is not specified by the publisher, and fixes are available via the vendor's security bulletin. This could be relevant where the Linux kernel is deployed in automotive systems, such as in embedded or infotainment platforms, but the advisory does not confirm vehicle impact. Confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1108

Multiple vulnerabilities were found in Curl versions 7.44.0 and later but before 8.22.0, affecting cURL and libcurl. An attacker could exploit these flaws to cause data confidentiality loss, data integrity loss, and security policy bypass, with the severity not specified by the vendor. This could be relevant where Curl is deployed in automotive systems, so confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-80725

The advisory describes a vulnerability in the Linux kernel's network packet aggregation (GRO) feature, where improper validation could allow crafted network frames to cause an out-of-bounds memory write or improper handling of large packets. An attacker could exploit this to corrupt memory or disrupt network traffic, with the issue affecting older stable kernel branches. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1091

Multiple vulnerabilities were found in the SUSE Linux kernel, affecting many SUSE enterprise and openSUSE products. An attacker could exploit these flaws to cause data confidentiality loss, data integrity loss, security policy bypass, and denial of service. This could be relevant where the SUSE Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1090

Multiple vulnerabilities were found in the Debian Linux kernel, which could allow an attacker to cause privilege escalation, data confidentiality breaches, and denial of service. The affected component is the Linux kernel as packaged in Debian trixie versions before 6.12.105-1, with the advisory noting these impacts but not specifying a severity rating. This could be relevant where the Debian Linux kernel is deployed in automotive systems, though the advisory does not confirm such use; confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1092

Multiple vulnerabilities were found in the Red Hat Linux kernel, which could allow an attacker to execute arbitrary code, elevate privileges, or cause a remote denial of service. The advisory does not confirm any automotive use, but this could be relevant where the Red Hat Linux kernel is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1093

Multiple vulnerabilities have been discovered in the Linux kernel as used in various Ubuntu releases. An attacker could exploit these flaws to elevate privileges, compromise data confidentiality, and compromise data integrity. This could be relevant where the Ubuntu Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-80589

This advisory addresses a Linux kernel vulnerability in the block layer, specifically a use-after-free bug that can occur when a disk device fails to initialize and is released while its timeout timer is still active. An attacker could potentially exploit this flaw to cause memory corruption or a system crash, with the issue being triggered in scenarios like NVMe device failures. The affected component is the Linux kernel's block subsystem, which is a core part of operating systems used in many computing environments, but the advisory does not confirm any specific automotive deployment. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units, but confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-80586

The advisory addresses a vulnerability in the Linux kernel's MPTCP (Multiprotocol Multipath TCP) implementation, where a remote peer could send a malformed data sequence signal (DSS) with an incorrect size, potentially leading to inconsistency or access to uninitialized data. An attacker could exploit this to cause system instability or unauthorized data exposure. The severity is not explicitly stated, but the fix involves resetting affected fields to prevent the issue. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-80575

This advisory describes a vulnerability in the Linux kernel's cs40l50-vibra driver, which handles haptic feedback effects. An attacker with access to the input subsystem could send specially crafted custom data that the driver fails to validate, potentially causing out-of-bounds memory reads or a crash. The severity is not explicitly rated, but the flaw involves improper length checks and memory access. This could be relevant where the cs40l50 haptic driver is deployed in automotive systems, such as infotainment or touchscreen controls. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-80570

This advisory addresses a heap buffer overflow vulnerability in the Linux kernel's Synaptics RMI4 driver, specifically in the F54 function used for touchscreen diagnostics. An attacker could exploit a failure condition to cause the driver to copy stale data into a smaller buffer, potentially leading to memory corruption. The fix ensures the report size is properly reset to zero on error. This could be relevant where the Synaptics RMI4 driver is deployed in automotive infotainment or touchscreen systems, though the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-80560

The advisory addresses a vulnerability in the Linux kernel's OpenRISC architecture, where an unprivileged task can craft a malicious signal frame to disable the data memory management unit, gaining read and write access to arbitrary physical memory and enabling local privilege escalation. This could be relevant where OpenRISC is deployed in automotive systems, such as embedded controllers or telematics units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-80558

This advisory addresses a vulnerability in the Linux kernel's libceph component, which handles communication with Ceph storage systems. A corrupted Ceph map could contain invalid OSD indices, potentially leading to out-of-bounds memory access when processing requests. This could be relevant where the Linux kernel with libceph is deployed in automotive systems, such as for data storage or telematics infrastructure, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.