Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
nvdmedium

cve-2026-89444

A flaw in the Linux kernel's Dell WMI system management driver caused the plaintext BIOS admin password to be written into the kernel log when setting a BIOS attribute. An attacker with access to kernel logs could read that password and use it to change BIOS settings. The advisory does not state a severity rating. This could be relevant where this Dell platform driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-89442

The Linux kernel's ISST driver has a flaw in the clos_assoc ioctl where a user-supplied socket ID is not properly validated, allowing an out-of-bounds array access or a NULL pointer dereference. An attacker able to invoke this interface could crash the kernel or potentially corrupt memory, though the advisory does not state a specific severity rating. This could be relevant where the Linux kernel ISST driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-89443

A Linux kernel driver for Intel Speed Select Technology (ISST) on the platform/x86 subsystem did not validate a user-supplied level value in two performance mask ioctls, allowing an out-of-bounds read from a per-level offset table. An attacker able to issue these ioctls with an invalid level could trigger the out-of-bounds read, which the advisory addresses by adding bounds checks and rejecting disabled SST-PP levels. This could be relevant where the Linux ISST platform/x86 driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-89441

The Linux kernel's via-sdmmc driver has a flaw where a card-detect work item can still run after the device is removed, causing it to access memory that has already been freed. An attacker able to trigger this condition could cause a use-after-free, which may crash the system or potentially be exploited for further compromise. The advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, since the affected driver is a generic kernel component rather than an automotive-specific one. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-89439

The advisory describes a NULL pointer check added for sst_inst[] in the platform/x86 ISST component, which is a Linux kernel driver for Intel Speed Select Technology. This could be relevant where the Linux kernel is deployed in automotive systems, though the advisory does not confirm any automotive deployment. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-89440

The Linux kernel's via-sdmmc driver fails to release the SD card-detect interrupt and cancel its associated work when device probe fails, leaving a handler that can run against freed memory. An attacker able to trigger this probe failure could cause the kernel to dereference freed memory, potentially leading to a crash or other memory-corruption effects. The advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-89438

The Linux kernel's ISST driver for Intel Speed Select Technology did not validate the maximum CLOS ID and logical CPU ID used to calculate MMIO offsets, so an attacker could potentially trigger out-of-bounds memory access. This could be relevant where the Linux kernel is deployed in automotive systems, though the advisory does not confirm any automotive deployment. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-89436

The Linux kernel's panasonic-laptop driver contains a heap buffer overflow where a sentinel value is written one element past the end of an allocated array, triggered on certain hardware whose ACPI firmware reports an off-by-one package count. An attacker able to influence that firmware data could cause a silent 4-byte heap overflow, which on kernels without UBSan goes undetected and may lead to memory corruption. The advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-89437

The advisory describes a fix for a potential memory leak in the sar_probe() function of the platform/x86 int1092 driver, a Linux kernel component. If this driver is used in an automotive system, the memory leak could allow an attacker to gradually exhaust system memory, potentially degrading or disrupting the affected component, though the advisory does not state a severity rating. This could be relevant where the int1092 driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-81018

A memory leak exists in the Linux kernel's think-lmi driver, where system certificate signatures are not freed when the driver is removed. An attacker able to repeatedly load and unload the driver could exhaust memory over time, though the advisory does not state a severity rating. This could be relevant where the Linux kernel think-lmi driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-81016

The Linux kernel's AMD PMC platform driver for x86 systems fails to check return values from SMU S2D commands, so a failed command can leave the physical address uninitialised and cause the driver to map physical address zero, triggering a warning. An attacker or faulty firmware could trigger this failure path, though the advisory does not state a severity rating. This could be relevant where this AMD platform driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-81015

The Linux kernel's AMD PMC platform driver can leak its low-power s2idle handler registration and debugfs directory when the STB/S2D initialization step fails during device probe, leaving stale state that can corrupt a kernel list and trigger a kernel BUG on module reload or on the next s2idle transition. This is a kernel-level reliability and memory-safety defect rather than a remotely exploitable flaw, and the advisory does not state a severity rating. This could be relevant where the AMD PMC driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-81013

The advisory describes a heap out-of-bounds read in the hp-bioscfg driver within the Linux kernel's platform/x86 subsystem, triggered when an empty password is written. An attacker able to trigger this condition could read memory beyond the intended buffer, potentially exposing sensitive data, though the advisory does not state a severity rating. This could be relevant where the hp-bioscfg driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-81014

The advisory describes a heap out-of-bounds read in the hp-bioscfg driver's sk_store() and kek_store() functions, which an attacker could potentially exploit to read memory outside the intended buffer. The advisory does not state a severity rating. This could be relevant where the hp-bioscfg driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-81012

A flaw in the Linux kernel's hp-bioscfg driver, used for HP BIOS configuration on certain HP systems, can write one byte past the end of a fixed-size buffer when a converted string exactly fills it. An attacker able to trigger this path could cause a one-byte out-of-bounds write, which may lead to memory corruption or a crash; the advisory does not state a severity rating. This could be relevant where this HP BIOS configuration component is deployed in automotive or embedded systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-81010

A flaw in the Linux kernel's io_uring waitid handling could let a callback run in the wrong task context, causing incorrect child-process lookup and potentially exposing or corrupting process information. The advisory does not confirm any automotive deployment; this could be relevant where the Linux kernel is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-81011

The Linux kernel's hp-bioscfg driver for HP BIOS configuration attributes passes an incorrect element count to its package parsers, causing them to use a string length instead of the real package size as a bound. This is currently safe, but an upcoming change that accepts shorter packages would turn it into an out-of-bounds heap read, which the fix prevents by forwarding the validated count. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-81009

A flaw in the Linux kernel's io_uring query interface allows an attacker to request nearly 4 GiB of memory zeroing through a size value that is not properly capped, and this is reachable without setting up a ring via IORING_REGISTER_QUERY. The fix rejects sizes larger than PAGE_SIZE. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-81007

The Linux kernel IPMI IPMB driver, which may be used in embedded or automotive-adjacent systems, contains a flaw where the ipmb_write function reads message fields before validating the length byte, allowing a zero or short write to read uninitialized stack bytes or underflow the block write length. An attacker able to trigger such a write could potentially access unintended memory contents or cause incorrect behavior, though the advisory does not state a severity rating. This could be relevant where the Linux kernel IPMI IPMB driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-81006

The Linux kernel IPMI subsystem has a flaw where, if registering an interface fails partway through, it leaves a sysfs file (nr_msgs) registered after the underlying interface memory is freed, creating a use-after-free condition. An attacker able to trigger this registration failure could potentially exploit the dangling reference, though the advisory does not state a severity rating. This could be relevant where the Linux kernel's IPMI subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-81004

A flaw in the Linux kernel's IPMI message handler can leave scheduled work running when an IPMI interface fails during startup, and that work must be cancelled before the interface is freed. An attacker able to trigger this startup error could cause the kernel to access freed memory, which may lead to a crash or other memory-corruption effects. The advisory does not state a severity rating. This could be relevant where the Linux kernel's IPMI subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-81005

The advisory describes a NULL pointer dereference in the IPMI subsystem that occurs after a failed registration, which could allow an attacker to crash or destabilize the affected system. This could be relevant where IPMI is deployed in automotive systems, since IPMI is typically a server management interface rather than a vehicle component. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80999

The advisory describes a Linux kernel change in the net: dsa: realtek driver that switches the reset GPIO to gpiod_set_value_cansleep, addressing how the reset line is driven for Realtek DSA switch chips. The advisory does not state a specific attacker capability or a severity rating, so no exploit impact or severity level can be reported from the supplied text. This could be relevant where Realtek DSA switch components are deployed in automotive systems, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80998

A flaw in the Linux kernel's bnxt network driver can cause a transmit queue to stall when a software UDP segmentation offload path exits early without notifying the network hardware, potentially halting outbound traffic on affected interfaces. An attacker able to trigger this condition could cause a denial of service through the stalled queue, though the advisory does not assign a specific severity rating. This could be relevant where the bnxt driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80996

The advisory describes a Linux kernel networking fix in the L2TP layer that stops multicast notification errors from being propagated. It does not state a severity, an attacker capability, or any automotive connection. This could be relevant where the Linux kernel L2TP component is deployed in automotive systems, but the advisory does not confirm any such deployment. Confirm applicability through the product SBOM or dependency inventory.