Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
nvdmedium

cve-2026-80957

A flaw in the Linux kernel's dm-pcache component allows a forged on-media last-kset chain to loop indefinitely during replay, causing the system to hang. The advisory does not state an automotive connection, but this could be relevant where the Linux kernel is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80955

The Linux kernel's dm-pcache component contains a use-after-free vulnerability in kset_replay() where freed memory is accessed after cache_key_put() is called, and it also performs invalid segment operations on expired keys. An attacker could potentially exploit this memory corruption issue, though the advisory notes that mempool recycled memory is not immediately reclaimed in practice, making it a potential rather than guaranteed exploitable bug. This could be relevant where the Linux kernel dm-pcache component is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80953

A flaw in the Linux kernel's ADI I3C master driver allows a pending interrupt to access an uninitialized lock during device initialization, which could cause a crash or unpredictable behavior. An attacker able to trigger this interrupt timing could exploit the uninitialized lock, though the advisory does not state a severity rating. This could be relevant where the ADI I3C master driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80954

A flaw in the Linux kernel's I3C subsystem allowed a function to access device data without holding the required bus lock, which could cause unsafe memory access. An attacker able to trigger this code path could potentially crash the system or corrupt memory, though the advisory does not state a specific severity rating. This could be relevant where the Linux I3C subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80949

The advisory describes a memory leak in the brcmfmac Wi-Fi driver function brcmf_sdio_read_control(), which could allow an attacker to exhaust memory over time and degrade or disrupt the affected system. This could be relevant where the brcmfmac driver is deployed in automotive systems, since Broadcom Wi-Fi chipsets are sometimes used in in-vehicle connectivity modules. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80948

The Linux kernel's iwlwifi DVM wireless driver has a memory leak in iwl_op_mode_dvm_start() where certain error paths free nvm_data but fail to free eeprom_blob. An attacker able to trigger those error conditions could cause a small memory leak, though the advisory does not state a severity rating. This could be relevant where the iwlwifi DVM driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80946

The Linux kernel's FUSE subsystem, used for io-uring based request transport, could crash the system when copying request headers because the memory involved was not permitted for direct userspace copying. An attacker able to trigger this code path could cause a kernel panic, resulting in a denial of service. This could be relevant where the Linux kernel's FUSE and io-uring components are deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80945

A flaw in the Linux kernel's Intel Analytics Accelerator (IAA) crypto driver causes decompression results to be corrupted when a hardware error triggers a software fallback, because the destination buffer is still DMA-mapped at that point. An attacker able to trigger the hardware error path could cause incorrect decompression output rather than a crash or code execution. The advisory does not state a severity rating. This could be relevant where the Linux IAA crypto driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80942

A memory leak vulnerability exists in the Linux kernel's rtlwifi driver for the RTL8192DU Wi-Fi chip, where memory allocated during device initialization is not freed if a later initialization step fails. An attacker or normal operation triggering that error path could cause memory to remain allocated, potentially leading to resource exhaustion over repeated occurrences. The advisory does not state a severity rating. This could be relevant where the Linux kernel with this Wi-Fi driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80943

The Linux kernel's rtlwifi driver for the rtl8192du Wi-Fi chipset has a flaw where a specially crafted QoS TID value in an 802.11 header can cause an out-of-bounds array access, potentially leading to memory corruption or a crash. This could be relevant where this Wi-Fi chipset or driver is deployed in automotive systems, such as in-vehicle infotainment or telematics units using affected Linux kernels. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80941

The Linux kernel's rtw88 Wi-Fi driver contains a memory leak in the rtw_txq_push_skb() function, where a network packet (skb) is not freed on an error path, causing memory to be lost when the function fails. An attacker able to repeatedly trigger this error condition could gradually exhaust kernel memory, though the advisory does not state a severity rating. This could be relevant where the rtw88 Wi-Fi driver is deployed in automotive systems, such as in-vehicle infotainment or telematics units using affected Realtek Wi-Fi chipsets. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80940

The Linux kernel's rtw88 PCI Wi-Fi driver has a resource leak: if NAPI setup fails during device probe, the error path skips cleanup and leaves PCI resources allocated. An attacker able to trigger that failure could cause a resource leak, though the advisory does not state a severity rating. This could be relevant where the rtw88 PCI driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80938

The Linux kernel's mt7615 Wi-Fi driver could deadlock during suspend because the suspend routine held a mutex while waiting for a work item that itself needed that same mutex. This is a denial-of-service condition in the driver, resolved by flushing the work items before acquiring the mutex. This could be relevant where MediaTek mt7615 Wi-Fi hardware is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80939

The Linux kernel's rtw89 PCI Wi-Fi driver lacked a shutdown callback, so during a warm reboot on arm64 platforms the rfkill polling work could still perform a memory-mapped I/O read after the PCIe link was torn down, causing a fatal asynchronous SError kernel panic. The fix adds a shutdown callback that sets a flag causing the rfkill poll handler to return early, preventing any further MMIO reads to the chip after shutdown begins. This could be relevant where the rtw89 Wi-Fi driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80936

The Linux kernel's mt7925 Wi-Fi driver fails to cancel a delayed power-save work item when the device is stopped, so if the device is torn down within that five-second window the timer fires afterward and triggers a kernel warning. This could be relevant where MediaTek mt7925 Wi-Fi hardware is deployed in automotive systems, since the flaw affects both the PCIe and USB driver variants. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80933

The Linux kernel mt7996 wifi driver fails to validate the size of default EEPROM firmware before parsing and copying it, so a truncated firmware file can cause the driver to read beyond the firmware buffer during variant validation or the fallback copy. An attacker able to supply a malformed firmware file could trigger an out-of-bounds read, and the advisory does not state a severity rating. This could be relevant where the mt7996 wifi component is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80934

The Linux kernel's mt7996/mt7992 Wi-Fi driver has a flaw where AddBA request frames leak a TX DMA mapping, roughly once per client (re)association. An attacker able to trigger continuous client reconnect churn could exhaust the WED swiotlb pool after about one to two days, causing DMA mapping failures for WED, the Wi-Fi MCU and other on-SoC consumers. This could be relevant where this Wi-Fi chipset is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80930

The advisory describes a change to the tpm_i2c_nuvoton driver that disables the interrupt request when a wait timeout occurs, affecting systems using a TPM connected over I2C. The advisory does not state a specific attacker capability or severity, so no impact or severity can be confirmed from the supplied text. This could be relevant where TPM I2C components are deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80929

A flaw in the Linux kernel allowed a non-root user to modify the global cad_pid setting by creating a child namespace, which should only be changeable by the root user. This could let a local attacker improperly alter a system-wide kernel control, though the advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80927

The Linux kernel timekeeping subsystem contains a vulnerability where a race condition in do_adjtimex() can cause uninitialized stack data to be used in calculations and indirectly leaked to userspace. An attacker able to trigger this race could potentially obtain leaked kernel memory contents, though the advisory does not assign a specific severity rating. This could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

csaf_microsoftmedium

cve-2026-74448

The advisory describes a fix for a QID bit leak in the amdkfd driver's pqm_create_queue() function, which is part of the Linux kernel's AMD GPU compute support. The advisory does not state a severity, attack scenario, or automotive impact, and it does not confirm that this component is used in vehicles or automotive systems. This could be relevant where the amdkfd driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

csaf_microsoftmedium

cve-2026-74445

The advisory describes a flaw in the Linux kernel's vmwgfx DRM driver where a DX_BIND_QUERY operation is not rejected when no DX context exists, which could let an attacker trigger improper handling in that graphics driver. The advisory does not state a severity rating or confirm any automotive deployment. This could be relevant where the Linux kernel with the vmwgfx driver is deployed in automotive systems, but the advisory does not confirm that. Confirm applicability through the product SBOM or dependency inventory.

csaf_microsoftmedium

cve-2026-74532

The advisory describes a Linux kernel Bluetooth driver issue in btintel where diagnostic TLV data is parsed without first validating its length, which could allow an attacker to trigger improper handling of malformed Bluetooth diagnostic data. This could be relevant where the affected Bluetooth component is deployed in automotive systems, since Bluetooth is sometimes used for in-vehicle connectivity. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-71646

The advisory describes a denial-of-service issue in a specific commit of the Robotics-STAR-Lab RACER component, where an attacker can trigger the flaw through the FastExplorationFSM::optTimerCallback() function in the swarm exploration manager code. No severity rating or automotive connection is stated in the advisory. This could be relevant where this robotics exploration component is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-62437

The advisory describes a memory leak vulnerability in Xen, a hypervisor that can run virtual machines. When a guest virtual machine is being shut down, a flaw in the cleanup process allows the guest's device model to re-establish IRQ tracking structures for assigned PCI devices, and at least one of these structures is not subsequently freed, leading to a memory leak. The severity is not explicitly rated, but the technical impact is a denial-of-service condition where an attacker could exhaust system memory over time. This could be relevant where Xen is deployed in automotive systems, such as for virtualization in infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.