Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
1962advisories found
cvelistv5high
cve-2026-80556
This advisory describes a use-after-free vulnerability in the Linux kernel's Atmel MCI driver, which manages MMC/SD card controllers. An attacker could potentially exploit a race condition to cause the system to use freed memory, leading to a crash or potential code execution. The severity is not explicitly rated, but the fix involves canceling pending work to prevent memory corruption. This could be relevant where the Atmel MCI driver is deployed in automotive systems, such as in embedded infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-80537
A flaw in the Linux kernel's XFS filesystem allows a crafted disk image to trigger a memory out-of-bounds write during system startup, potentially causing a crash or system compromise. This could be relevant where the Linux kernel with XFS is deployed in automotive systems, such as in infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-80536
This advisory describes a vulnerability in the Linux kernel's XFS filesystem, where a crafted disk image can cause a buffer overflow during system startup, potentially corrupting memory. An attacker who can get such an image mounted could exploit this to compromise the system. This could be relevant where Linux with XFS is deployed in automotive systems, such as in infotainment or telematics units; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-80525
This advisory describes a bug in the Linux kernel's audio driver for Sound Open Firmware (SOF), where cached configuration data for audio copier widgets becomes stale after a system suspend/resume cycle. An attacker could potentially trigger this flaw to cause firmware errors and crashes, leading to a denial of service. The severity is not explicitly rated in the advisory, but the impact is system instability. This could be relevant where Linux-based systems with SOF audio hardware are deployed in automotive infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-74752
The advisory describes a vulnerability in the Linux kernel's SCTP networking component, where a forged cookie can cause out-of-bounds reads or a 32-byte write past a buffer, potentially enabling a local privilege escalation. The severity is not explicitly rated, but the technical impact includes memory corruption and a privilege escalation primitive. This could be relevant where the Linux kernel's SCTP protocol is deployed in automotive systems, such as for in-vehicle networking or telematics; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-74748
A race condition in the Linux kernel's netfilter ipset component can cause a system crash when garbage collection and a set swap operation occur simultaneously. An attacker could potentially trigger this condition to cause a denial of service through a kernel panic. This could be relevant where Linux-based systems with ipset are deployed in automotive systems, such as network gateways or infotainment units; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-74746
The advisory addresses a vulnerability in the Linux kernel's netfilter flowtable component, where a race condition can cause a use-after-free memory error during flow installation. An attacker could exploit this to trigger memory corruption, potentially leading to system crashes or other undefined behavior. The severity is not explicitly rated, but the issue is fixed by changing the order of publishing flow entries. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-74739
The advisory addresses a vulnerability in the Linux kernel's network traffic control component, specifically the cls_u32 packet classifier. An attacker could trigger a slab-out-of-bounds memory read by exploiting how the classifier handles certain filter configurations, potentially leading to system instability or information disclosure. The severity is not explicitly stated, but the issue is fixed by a kernel patch. This could be relevant where the Linux kernel is deployed in automotive systems, such as in vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-74737
The advisory describes a bug fix in the Linux kernel for the TI AM65 CPSW Ethernet driver, where an incorrect extraction of a port identifier from packet metadata could cause a kernel crash due to out-of-bounds memory access. This could be relevant where this specific Ethernet driver is deployed in automotive systems, such as in vehicle networking or infotainment ECUs. The stated impact is a sporadic kernel crash, and the fix ensures only the correct lower bits of the tag are used. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2025-70293
An issue was discovered in Denx U-Boot before 2026.04, where an integer overflow in the ext4fs_get_bgdtable function causes under-allocation of a buffer used in a memcpy operation. This could allow an attacker to achieve arbitrary code execution, denial of service, or other unspecified impacts. This could be relevant where U-Boot is deployed in automotive systems, such as in vehicle bootloaders or embedded control units; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2025-70290
An issue was discovered in Denx U-Boot before 2026.04, where an integer overflow in its ZFS filesystem support can be triggered by malformed on-disk metadata. This could lead to incorrect memory allocation and out-of-bounds access, potentially causing a crash or arbitrary code execution during the boot process. Since U-Boot is a bootloader commonly used in embedded systems, this could be relevant where U-Boot is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
certfr_avishigh
certfr-2026-avi-1079
Multiple vulnerabilities were disclosed in OpenSSL, affecting versions 3.0.x through 4.0.x and 1.0.2x/1.1.1x, which could allow a remote attacker to cause a denial of service and bypass security policy. The advisory does not confirm automotive deployment, so this could be relevant where OpenSSL is used in automotive systems, and the severity is not explicitly rated. Confirm applicability through the product SBOM or dependency inventory.
certfr_avishigh
certfr-2026-avi-1077
Multiple vulnerabilities were disclosed in Cisco IOS XE software, affecting several version lines, which could allow an attacker to bypass security policies and cause an unspecified security issue. The advisory does not state a severity rating or confirm automotive deployment, but Cisco IOS XE is a network operating system that could be used in automotive or fleet networking infrastructure. This could be relevant where Cisco IOS XE is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-74729
This advisory addresses a fix in the Linux kernel for a usercopy overflow in the Aspeed LPC snoop driver, which is used to monitor low-pin-count bus traffic. An attacker could potentially exploit this overflow to cause memory corruption or gain elevated privileges. This could be relevant where Aspeed LPC snoop functionality is deployed in automotive systems, such as in baseboard management controllers used for vehicle diagnostics or telematics. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-74727
cvelistv5high
cve-2026-74724
This advisory addresses a vulnerability in the Linux kernel's IPVS component, specifically an out-of-bounds write in the ip_vs_nat_icmp function. An attacker could exploit this flaw to cause memory corruption, potentially leading to system instability or unauthorized code execution. The severity is not explicitly stated in the advisory. This could be relevant where IPVS is deployed in automotive systems, such as for network load balancing in vehicle or fleet infrastructure. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-74716
cvelistv5high
cve-2026-74714
This advisory addresses a use-after-free vulnerability in the Linux kernel's BPF TCP iterator functionality, specifically in the function bpf_iter_tcp_established_batch(). An attacker could potentially exploit this flaw to cause memory corruption or a system crash. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-74705
This advisory addresses a use-after-free vulnerability in the UDP tunnel segmentation code within the Linux kernel, which could allow an attacker to exploit a memory safety flaw. The technical impact is that this flaw could potentially lead to system instability or unauthorized code execution, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-74702
cvelistv5high
cve-2026-74694
This advisory addresses a heap out-of-bounds read vulnerability in the Linux kernel's NCSI (Network Controller Sideband Interface) subsystem, specifically in the handling of the NCSI_CMD_SEND_CMD payload length. An attacker could exploit this flaw to read data beyond the intended memory buffer, potentially exposing sensitive information or causing a system crash. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel with NCSI support is deployed in automotive systems, such as for network management in vehicles, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-74682
This advisory addresses a vulnerability in the ALSA USB-audio driver within the Linux kernel, specifically an out-of-bounds write that can occur on Type II inbound USB request blocks. An attacker could exploit this flaw to cause memory corruption, potentially leading to system instability or arbitrary code execution. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel with USB audio support is deployed in automotive systems, such as infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high
cve-2026-74674
cvelistv5high
cve-2026-74665
cvelistv5high
cve-2026-74661
The advisory addresses a use-after-free vulnerability in the mac802154 Linux kernel component, specifically in its beacon worker, which could allow an attacker to exploit freed memory and potentially cause system instability or unauthorized access. The severity is not explicitly stated in the provided text, but the flaw affects the IEEE 802.15.4 wireless networking stack, which is used in low-power embedded devices. This could be relevant where mac802154 is deployed in automotive systems, such as for short-range wireless communication in vehicle sensors or telematics, though the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.