Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
cve-2026-74656
This advisory addresses a use-after-free vulnerability in the Linux kernel's IPv4 routing code, specifically in the function fib_nhc_update_mtu(). An attacker could potentially exploit this flaw to cause memory corruption or a system crash, though the advisory does not state a specific severity rating. This could be relevant where Linux-based systems are deployed in automotive environments, such as infotainment or telematics units, but the advisory does not confirm any automotive impact. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74649
The advisory addresses a missing shared-key authentication challenge length check in the rtl8723bs Wi-Fi driver, which could allow an attacker to exploit this flaw. The technical impact is not detailed in the advisory, and no severity rating is provided. This could be relevant where the rtl8723bs driver is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74648
The advisory addresses a vulnerability in the Linux kernel's rtl8723bs driver, specifically a missing validation of monitor transmit frame lengths. An attacker could exploit this flaw to cause undefined behavior or a system crash, with the severity not explicitly stated in the provided text. This could be relevant where the rtl8723bs driver is deployed in automotive systems, such as for Wi-Fi connectivity in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74640
cve-2026-74639
cve-2026-74637
This advisory addresses a use-after-free vulnerability in the Linux kernel's performance event subsystem, specifically when a group leader is detached from its sibling events. An attacker could potentially exploit this flaw to cause memory corruption, leading to system instability or privilege escalation. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74629
cve-2026-74589
This advisory addresses a use-after-free vulnerability in the Linux kernel's BPF sockmap functionality, which could allow an attacker to exploit a flaw in the send verdict path. The technical impact is that an attacker could potentially cause memory corruption or a system crash, with the severity not explicitly stated in the provided text. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
cve-2026-74587
This advisory addresses a use-after-free vulnerability in the Linux kernel's SCTP networking component, specifically involving cached ASCONF chunks. An attacker could potentially exploit this flaw to cause memory corruption or a system crash, with the severity not explicitly stated in the provided text. This could be relevant where the Linux kernel with SCTP is deployed in automotive systems, such as for in-vehicle networking or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74583
This advisory addresses a use-after-free vulnerability in the Linux kernel's network traffic classifier (cls_route), where an attacker could potentially exploit the flaw to cause memory corruption or a system crash. The affected component is part of the Linux kernel, which could be relevant where this kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.
certfr-2026-avi-1066
certfr-2026-avi-1065
certfr-2026-avi-1064
certfr-2026-avi-1069
certfr-2026-avi-1068
cve-2026-76023
cve-2026-74578
cve-2026-85517
The advisory describes a vulnerability in the Vehicle Management System version 1.0, specifically involving its SQL database backup file. An attacker can remotely access this file to disclose sensitive information. The severity is not explicitly rated, but the exploit has been published, and the affected product is directly related to automotive vehicle management.
cve-2026-82550
Linux Foundation Magma version 1.9.0 contains a security flaw in its NGSetupRequest Handler, specifically involving improper input validation of the NG-IoT-DefaultPagingDRX argument, which could be exploited remotely by an attacker. The vulnerability has been publicly disclosed, and the project has not yet responded to the issue report. This could be relevant where Magma is deployed in automotive or road-transport systems, as it is a network core platform, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
cve-2026-82547
Linux Foundation Magma 1.9.0 contains a vulnerability in its Registration Complete Message Handler, specifically in the file tasks/amf/amf_fsm.cpp, which involves improper authentication. An attacker can exploit this remotely, and the exploit has been publicly disclosed, potentially allowing unauthorized access or actions. This could be relevant where Magma is deployed in automotive systems, such as in fleet or telematics networks, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
cve-2026-62381
luci-lib-px5g, a component of the OpenWrt LuCI web interface, contains a heap-based buffer overflow in its certificate-signing code when handling a 2040-bit RSA key, causing a one-byte write beyond the allocated memory. An attacker could potentially exploit this through the Lua interface, though remote exploitability depends on how the application embeds it. This could be relevant where OpenWrt LuCI is deployed in automotive systems, such as routers or gateways in vehicles; confirm applicability through the product SBOM or dependency inventory.
cve-2026-74871
openssl_encrypt versions before 1.4.6 have a key derivation flaw in sequential XOR mode where the last stage cancels out, allowing attackers to bypass memory-hard key derivation and crack passwords offline at SHA-256 speed instead of the intended cost. This could be relevant where openssl_encrypt is deployed in automotive systems, such as for securing embedded data or communications, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-53551
This vulnerability affects the 5G core network infrastructure used in automotive telematics and connected vehicle services, specifically the free5GC Authentication Server Function (AUSF) that handles subscriber authentication for cellular connectivity. An unauthenticated attacker can send malformed authentication requests containing null bytes, causing the system to crash with HTTP 500 errors and leak internal stack traces, which can be exploited at scale to deny service to all vehicles attempting to authenticate on the network. The severity is high because it enables a denial-of-service attack on the entire subscriber base, though it is fixed in version 1.4.5 and requires immediate patching of affected 5G core deployments.
cve-2026-56758
This vulnerability affects the IEC 61850 communication protocol library used in electric vehicle charging stations, substation automation, and smart grid systems that manage vehicle-to-grid energy transfer. An attacker could send a specially crafted connection request to trigger an out-of-bounds read, potentially causing a denial of service or leaking sensitive memory contents from the device. The severity is high because it could disrupt charging infrastructure or grid communication systems that vehicles rely on for energy management.