Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
1962advisories found
nvdmedium
cve-2026-90360
A Linux kernel regulator-core flaw lets a delayed work item run during system suspend, so an I2C write to disable unused regulators can hit an already-suspended I2C adapter and trigger a kernel warning. The advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, since the affected regulator and I2C code is common in embedded platforms. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-90359
A flaw in the Linux kernel's BPF trampoline handling means that when a BPF program is attached to a function returning a value larger than 8 bytes, only half of the return value is preserved, so the value seen by the real caller can be corrupted and the attached program sees only part of it. This affects the fexit, fmod_ret and fsession attach types (including their _multi variants) and struct_ops, while fentry is unaffected; the advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, so confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-90357
A flaw in the Linux kernel's mt76 driver for the mt7915 Wi-Fi chipset can leave a TWT flow entry linked in an internal list when the firmware rejects the agreement, allowing that slot to be reused and its memory cleared while still referenced, which corrupts the list and leaves a dangling entry that is later traversed during station removal. An attacker able to trigger the rejected-agreement path could cause memory corruption and potentially a crash or other undefined behavior in the affected driver. The advisory does not state a severity rating. This could be relevant where the mt7915 Wi-Fi component is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-90355
A flaw in the Linux kernel's mt7996 Wi-Fi driver leaves the wireless device inoperative after a full chip reset because stale link state prevents the firmware from re-creating its internal records, and repeated resets also leak index resources until they are exhausted. This could be relevant where this MediaTek Wi-Fi chipset is deployed in automotive systems, such as in-vehicle infotainment or connectivity modules. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-90354
The Linux kernel's mt7915 Wi-Fi driver could call a hardware-initialization routine twice on certain non-WED dual-hif devices, causing an internal index to be incremented twice, a PCIe register to be written twice, and a device reference to be leaked. This could be relevant where the mt7915 Wi-Fi component is deployed in automotive systems, though the advisory does not confirm any automotive deployment. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-90352
A flaw in the Linux kernel's mt76 Wi-Fi driver for the mt7915 chipset causes a reference to be leaked when the device's interrupt setup fails during probing. An attacker generally cannot exploit this directly; the practical impact is a resource leak that could degrade or destabilize the affected system over time. The advisory does not state a severity rating. This could be relevant where this Wi-Fi chipset and driver are deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-90351
The Linux kernel mt7996 Wi-Fi driver could leave a MediaTek wireless chipset in an inconsistent state when the primary WED (Wireless Ethernet Dispatch) attach fails during device probing, because the driver still set up the secondary hif2 WED and re-enabled hwrro_mode, leading to a later crash. An attacker able to trigger this failure path could cause a denial of service through a kernel crash, though the advisory does not assign a specific severity score. This could be relevant where MediaTek mt7996 Wi-Fi hardware is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-90350
A flaw in the Linux kernel's mt76 Wi-Fi driver allows an out-of-range link identifier to be used when indexing an internal array, causing a read past the end of that array; this is reachable through certain MediaTek mt7996 driver functions. An attacker able to trigger those code paths could cause the driver to access unintended memory, though the advisory does not state a severity rating. This could be relevant where the mt76 driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-90346
A memory leak exists in the Linux kernel's nl80211 Wi-Fi subsystem, where a beacon parsing error during a color-change operation can leave allocated memory unreleased. An attacker able to trigger this error path could cause a resource leak, though the advisory does not state a severity rating. This could be relevant where the Linux kernel's nl80211 Wi-Fi component is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-90347
The Linux kernel's arm64 ptrace implementation has a flaw where a tracer can change the first syscall argument without it being properly re-checked by seccomp or audit, because the saved 'orig_x0' value is not kept in sync with x0 on syscall entry. An attacker able to use ptrace on an arm64 system could potentially bypass seccomp or audit filtering of syscall arguments. The advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-90345
A flaw in the Linux kernel's brcmfmac Wi-Fi driver can cause improper handling of P2P action frames when the P2P device virtual interface is not available, such as when userspace sends non-P2P public action frames through the primary interface or when an action-frame abort occurs before that interface is created. An attacker able to trigger these conditions could cause the driver to access an unavailable interface or saved information element, potentially leading to a crash or other undefined behavior, though the advisory does not state a specific severity rating. This could be relevant where the brcmfmac driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-90343
A flaw in the Linux kernel's Wi-Fi configuration layer (cfg80211) means that when a P2P or NAN wireless interface is shut down with a peer measurement request still pending, the request is freed without properly aborting it in the underlying driver, leaving stale state that the driver may later use when reporting a result. An attacker able to trigger this teardown path could cause the driver to act on a stale request, which may lead to a crash or other undefined behavior; the advisory does not state a severity rating. This could be relevant where Linux-based Wi-Fi components are deployed in automotive systems, such as in telematics or in-vehicle connectivity modules. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-90344
The Linux kernel's mac80211 Wi-Fi subsystem contains a vulnerability where a channel switch announcement to channel 0 is mishandled, causing the system to fail to disconnect as it should. This can lead to a firmware crash on Intel devices. This could be relevant where the Linux kernel's mac80211 Wi-Fi stack is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2025-56566
MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext in non-volatile storage, and an attacker with physical access can extract this material from an SPI flash dump without authenticating or knowing the administrative password. This could be relevant where MikroTik firmware is deployed in automotive systems, for example in roadside, fleet or telematics networking equipment. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-43674
Apple has fixed an authentication flaw in iOS 27 and iPadOS 27 where an attacker with physical access to an unlocked device could view Wi-Fi passwords without authentication. The advisory does not state a severity rating. This could be relevant where Apple iOS or iPadOS devices are deployed in automotive systems, such as in-vehicle infotainment or fleet/telematics use. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-86891
An authorization issue in Apple macOS and watchOS could let a malicious app access Bluetooth device information, and Apple rates this as fixed through improved state management in the listed updates. This could be relevant where Apple macOS or watchOS devices are deployed in automotive systems, for example as connected host devices or in vehicle-adjacent workflows. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-84560
An authorization issue in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS could let an app gain unauthorized access to Bluetooth, and Apple rates the fix as an authorization flaw addressed through improved state management. This could be relevant where Apple platforms are deployed in automotive systems, for example in infotainment, telematics or companion-device integrations. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-89773
A flaw in the Linux kernel's AMD display driver causes HDCP configuration to run during a transition state where no valid stream context exists, which could lead to improper HDCP handling. An attacker could potentially exploit this to disrupt HDCP content protection, though the advisory does not state a specific severity or direct exploit impact. This could be relevant where the AMD display driver is deployed in automotive systems, so confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-89771
A race condition in the Linux kernel's ring-buffer code allows a subbuffer resize to occur at the same time as a read, which could cause incorrect memory access or a crash. This could be relevant where the Linux kernel is deployed in automotive systems, such as in ECUs, infotainment units, or telematics devices. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-89770
A flaw in the Linux kernel's iomap subsystem could cause a NULL pointer dereference when a block device has integrity protection verification disabled, because the code frees an integrity payload that was never allocated. An attacker able to trigger this code path could crash the affected system, though the advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-89769
The advisory describes a Linux kernel bug in the NXP PIT clocksource driver where an error path fails to release a registered interrupt, leaking the IRQ line and potentially leaving a dangling pointer that could cause a use-after-free if the interrupt fires. This could be relevant where the NXP PIT timer is deployed in automotive systems, since such timers may be used in embedded automotive platforms. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-89768
Microsoft has released a fix for a flaw involving the user path of nested backing files, which could allow an attacker to access or manipulate files outside the intended user path. The advisory does not state a severity rating or confirm any automotive deployment. This could be relevant where the affected component is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-89766
A race condition in the Linux kernel's pidfd namespace ioctls could let a local attacker read namespace information they should have been denied, by passing a credentials check before a target process completes a setuid execve and then reading the namespace afterward. The flaw is in the kernel's PIDFD_GET_*_NAMESPACE handling, which failed to hold the target task's exec_update_lock during the ptrace access check and namespace lookup, unlike the equivalent procfs paths. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-89767
A flaw in the Linux kernel's overlay filesystem causes a directory lock to be released twice when a casefold consistency check fails during directory creation, which can permanently block further directory creation under the affected parent. An unprivileged local user can trigger this condition, leading to a denial of service on the affected system. This could be relevant where the Linux kernel is deployed in automotive systems, but the advisory does not confirm an automotive deployment. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-89765
Microsoft addressed a Linux kernel issue in the timers/itimer code where an old itimerval structure was not zero-initialized before being copied to userspace, which could expose uninitialized kernel memory to a local user. The advisory does not state a severity rating or describe specific attacker capabilities beyond this information disclosure condition. This could be relevant where the Linux kernel is deployed in automotive systems, so confirm applicability through the product SBOM or dependency inventory.