Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
nvdmedium

cve-2026-93142

The Linux kernel's Renesas R-Car thermal driver had a probe error-handling flaw where it could dereference an invalid pointer if thermal zone registration failed. An attacker able to trigger this failure path could cause a crash or denial of service, though the advisory does not assign a specific severity score. This could be relevant where the R-Car thermal driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93141

A double-free vulnerability in the Linux kernel's USB gadget r8a66597 driver could be triggered when the usb_add_gadget_udc() call fails during probe, causing the ep0_req request to be freed twice. This could potentially lead to memory corruption or a system crash, though the advisory does not state a specific severity rating. This could be relevant where the Linux kernel USB gadget subsystem is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93139

The Linux kernel's AMD GPU driver (amdgpu) has a flaw where a loop only initializes part of an array on multi-XCC GPUs, leaving some entries uninitialized. This can cause null pointer dereferences when the driver accesses those entries, potentially crashing or destabilizing the system. The advisory does not state a severity rating. This could be relevant where the amdgpu driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93138

A race condition in the Linux kernel's BPF subsystem could let a concurrent caller read a partially initialized vmlinux BTF structure on weakly ordered architectures, because the pointer was published and re-read without proper memory ordering. The fix replaces the plain store and load with release and acquire semantics to ensure the parsed contents are visible before the pointer is used. The advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93136

A flaw in the Linux kernel's MHI endpoint bus code causes a device reference count leak when MHI device creation fails, leaving the device and its channels in an inconsistent state. An attacker able to trigger this error path could cause a resource leak that prevents proper cleanup, though the advisory does not state a severity rating. This could be relevant where the Linux MHI endpoint subsystem is deployed in automotive systems, such as in embedded or telematics hardware. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93134

A use-after-free vulnerability in the Linux kernel's printk subsystem could allow an attacker to access or corrupt memory when the kernel console is being used, potentially leading to a crash or other unpredictable behavior. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment units, telematics modules, or ECUs running Linux. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93133

A flaw in the Linux kernel's ACPI support for RISC-V processors could leave a variable uninitialized when a handle lookup fails, which the fix addresses by checking the return status and skipping the affected entry. The advisory does not state a severity rating or describe a concrete attacker impact beyond the uninitialized value. This could be relevant where Linux is deployed in automotive systems, but the advisory does not confirm any automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93132

The Linux kernel has a flaw in its ACPI support for RISC-V systems where a loop in the riscv_acpi_add_prt_dep() function mishandles error conditions, causing it to skip updating the entry pointer and potentially miss entries. An attacker able to trigger this code path could cause incorrect behavior in the affected kernel component, though the advisory does not state a specific severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93131

A race condition in the Linux kernel's dell-privacy driver allows a use-after-free when the priv structure is accessed without holding the list mutex, meaning an attacker could potentially crash the system or corrupt memory. This could be relevant where the Linux kernel is deployed in automotive systems, though the advisory does not confirm any automotive deployment. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93130

A resource leak in the Linux kernel's dell-wmi-base driver can occur when the module fails to load, because the SMBIOS request and privacy driver are not properly cleaned up. An attacker could potentially exploit this leak to cause resource exhaustion, though the advisory does not state a specific severity. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93129

A Linux kernel driver for Dell WMI platform features, dell-wmi-base, mishandles the ultra performance key by reading event data at the wrong index, which can cause a buffer overread. An attacker able to trigger this key event could potentially read beyond the intended buffer, though the advisory does not state a severity rating. This could be relevant where this Dell platform driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93128

A flaw in the Linux kernel's lg-laptop driver could let an event notification callback access the keyboard backlight LED even when it was never successfully registered, and the same unsafe access occurs during device removal. This could cause improper resource handling in affected Linux systems. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93126

The Linux kernel's qcom_q6v5_adsp remoteproc driver contains a reference leak where a device node reference obtained during carveout mapping is never released. An attacker able to trigger this code path could cause a resource leak that may lead to memory exhaustion or denial of service. The advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as infotainment or telematics units using Qualcomm ADSP remoteproc drivers. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93125

The Linux kernel's BPF verifier contains a flaw where an argument named rdonly_buf_size or rdwr_buf_size is not properly bounded, allowing a value larger than 32 bits to be truncated instead of rejected. An attacker could exploit this to make the verifier record an incorrect memory size of roughly 4 GiB for a returned allocation, potentially bypassing later access checks. The advisory does not state a severity rating. This could be relevant where the Linux kernel's BPF subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93124

The Linux kernel's asus-wireless platform driver can be force-bound to a device it does not actually support, and in that case its probe routine still reports success, leaving a non-functional input device and storing a null ACPI companion pointer that later causes a null pointer dereference when the driver is unbound. The fix makes the driver fail probe with -ENODEV when the device does not match its ID table, checking this before allocating any driver state. The advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93123

A flaw in the Linux kernel's Qualcomm GENI serial driver can cause newly written serial data to be discarded when a stale DMA completion is processed after a buffer flush. An attacker or process able to trigger this timing condition could cause data loss or corruption of serial transmissions, though the advisory does not state a severity rating. This could be relevant where the Qualcomm GENI serial driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93122

The Linux kernel USB gadget UAC1/UAC2 configfs rate-list attributes fail to check how many sampling rates are supplied, so writing more than ten rates overflows fixed-size arrays in the driver. An attacker able to write to these configfs attributes could trigger an out-of-bounds write, which the advisory demonstrates via a UBSAN array-index-out-of-bounds report. This could be relevant where the Linux USB gadget UAC function is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93120

A flaw in the Linux kernel's USB gadget configfs code causes an out-of-bounds read when a stored OS descriptor signature fills its buffer without a NUL terminator, potentially exposing adjacent kernel memory through a configfs attribute. The advisory does not state a severity rating. This could be relevant where the Linux USB gadget subsystem is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93121

A flaw in the Linux kernel's USB gadget function filesystem (f_fs) driver causes incorrect cleanup of a fence object on two error paths, leading to undefined behavior. An attacker able to trigger these error conditions could potentially cause a system crash or other unpredictable behavior, though the advisory does not state a specific severity rating. This could be relevant where the Linux USB gadget subsystem is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93118

The Linux kernel's Aspeed USB device controller driver fails to check whether a DMA buffer allocation succeeded, so a failed allocation can be dereferenced during device probe. An attacker who can trigger that allocation failure could cause a crash or other unsafe behavior in the kernel. The advisory does not state a severity rating. This could be relevant where the Aspeed UDC driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93116

A flaw in the Linux kernel's asus-wmi driver causes resource leaks when the driver fails during initialization, because cleanup steps run out of order and skip releasing previously registered resources such as the input device, sysfs groups, backlight and rfkill. An attacker able to trigger these probe failures could exhaust kernel resources, though the advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93115

The Linux kernel's mlxbf-pmc platform driver for Mellanox BlueField systems can be forced to bind to a device that lacks an ACPI companion object, causing a NULL pointer dereference and a system crash. An attacker able to trigger this driver binding could crash the affected system, representing a denial-of-service condition. This could be relevant where the mlxbf-pmc driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93113

A flaw in the Linux kernel's Qualcomm camera clock controller driver (camcc-sc8280xp) causes a warning and leaves a power domain stuck in the "on" state when unused clocks are shut down. The advisory does not describe attacker-controlled exploitation or a stated severity, so no direct security impact is established. This could be relevant where this Qualcomm SC8280XP camera clock component is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93114

A flaw in the Linux kernel's Surface ACPI notification platform driver could let an attacker who force-binds the driver to a device lacking an ACPI companion trigger a NULL pointer dereference, crashing the system. The advisory does not state a severity rating. This could be relevant where this Linux kernel driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-93112

A flaw in the Linux kernel's BPF cpumask handling allowed the verifier to accept read-only cpumask pointers as writable destinations for bpf_cpumask_populate(), which writes to that destination. An attacker able to load BPF programs could potentially corrupt memory by writing through a pointer that should have been read-only. The advisory does not state a severity rating. This could be relevant where the Linux kernel's BPF subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.