Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
1962advisories found
nvdmedium
cve-2026-80851
The advisory addresses a vulnerability in the Linux kernel related to the serialization of PDP context updates, which could be exploited by an attacker to cause a technical impact. This could be relevant where Linux is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80847
The advisory addresses a Linux kernel networking issue where the TCP Maximum Segment Size (MSS) is not properly clamped to a minimum value, which could allow an attacker to manipulate network communications. This could be relevant where Linux is deployed in automotive systems, such as in infotainment or telematics units, potentially enabling disruption of data transmission. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80846
The advisory addresses a vulnerability in the Linux kernel's xfrm subsystem, which handles IPsec security associations, specifically involving the dropping of ESP-in-TCP packets that lack an ingress device. An attacker could potentially exploit this flaw to bypass security controls or cause network disruption, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80845
The advisory describes a fix for a lock-ordering deadlock in the Linux kernel's XFRM subsystem, which handles IPsec security associations. An attacker could potentially trigger a race condition between NAT keepalive processing and security association deletion, causing the system to hang or crash. This could be relevant where Linux is deployed in automotive systems, such as in vehicle gateways or infotainment units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80843
This advisory addresses a memory leak in the Linux kernel's xfrm subsystem, which handles IPsec security associations. An attacker could potentially exploit this flaw to exhaust system memory, leading to a denial-of-service condition. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80841
The advisory addresses a Linux kernel issue in the net/packet component, where the TX_RING memory is freed prematurely before associated socket buffers finish using it. An attacker could potentially exploit this use-after-free condition to cause memory corruption or a system crash. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel's packet socket functionality is deployed in automotive systems, such as for network diagnostics or telematics. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80840
This advisory addresses a Linux kernel vulnerability in the IPv6 segment routing (seg6) implementation, where the IPv4 control block is not cleared during IP-in-IP decapsulation. An attacker could potentially exploit this flaw to cause memory corruption or other undefined behavior, leading to system instability or a security breach. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80838
The advisory describes a vulnerability in the Linux kernel's VXLAN networking component, where a bulk flush operation can temporarily leave a forwarding database (FDB) entry with no remote destinations, allowing an attacker to trigger an invalid memory pointer that could be read from or written to during packet processing. The technical impact is potential memory corruption or system instability, though the advisory does not state a specific severity rating. This could be relevant where the Linux kernel's VXLAN feature is deployed in automotive systems, such as for in-vehicle network virtualization or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80837
This advisory addresses a vulnerability in the Linux kernel's netfilter component, specifically related to nf_tables and the handling of packet path object notifications. An attacker could potentially exploit this flaw to cause a denial of service or other unspecified technical impacts on systems running the affected kernel. This could be relevant where the Linux kernel with netfilter is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80836
The advisory addresses a Linux kernel vulnerability in the virtio crypto driver, where the result length of an asymmetric key operation (akcipher) is not properly bounded. An attacker could potentially exploit this flaw to cause memory corruption or other undefined behavior, with the severity not explicitly stated in the provided text. This could be relevant where the virtio crypto component is deployed in automotive systems, such as in virtualized environments for in-vehicle infotainment or other embedded platforms. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80835
The advisory describes a bug in the Linux kernel's qcom-rng driver, which manages a hardware random number generator (RNG) on Qualcomm chips. Because the driver exposed the hardware through two interfaces that could run concurrently, an attacker could cause the RNG to output repeated or non-random values, weakening security. The fix removes the problematic crypto_rng interface, and while the advisory does not confirm automotive use, Qualcomm components are common in vehicles, so this could be relevant where the qcom-rng driver is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80832
This advisory addresses a fix in the Linux kernel for a buffer underallocation issue in the CCM (Counter with CBC-MAC) cryptographic mode within the Qualcomm Crypto Engine (qce) driver. An attacker could potentially exploit this memory handling flaw to cause a system crash or other undefined behavior. The advisory does not specify a severity rating or confirm automotive deployment, but this could be relevant where the Linux kernel with the qce driver is used in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80831
This advisory addresses a fix in the Linux kernel's mxs-dcp cryptographic driver, correcting an issue with source scatterlist length access. An attacker could potentially exploit this flaw to cause incorrect memory access or other undefined behavior in the cryptographic operations. The severity is not explicitly stated in the advisory. This could be relevant where the mxs-dcp driver is deployed in automotive systems, such as in embedded hardware used for secure communications or data integrity. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80830
The advisory describes a fix in the Linux kernel for the USB core, specifically adding a lock to the usb_wakeup_notification() function. An attacker could potentially exploit a race condition or synchronization issue in USB wakeup handling, though the advisory does not specify a concrete attack scenario or severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units that use USB connections. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80827
This advisory addresses a vulnerability in the Linux kernel's USB serial option driver, where an out-of-bounds read can occur in an interrupt callback. An attacker could potentially exploit this flaw to read sensitive memory, leading to information disclosure or a system crash. This could be relevant where the Linux kernel with this driver is deployed in automotive systems, such as for telematics or infotainment, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80823
This advisory addresses a vulnerability in the Linux kernel's NFC (Near Field Communication) driver, specifically in the st21nfca component, where the ATR_REQ length is not properly validated against the received frame. An attacker could exploit this flaw to cause a buffer-related issue, potentially leading to system instability or unauthorized access. This could be relevant where the st21nfca NFC driver is deployed in automotive systems, such as for keyless entry or infotainment, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80822
The advisory describes a null-check fix in the mailbox driver for the Microchip IPC SBI component, where a devm_kasprintf() call could return null and lead to a null pointer dereference. An attacker able to trigger that condition could potentially cause a crash or denial of service, though the advisory does not state a severity rating. This could be relevant where the Microchip IPC SBI mailbox driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80821
The advisory describes a fix in the Linux kernel for the NVMe Target PCI endpoint function driver, where a failure during completion queue setup causes a memory leak of the queue and a controller reference. An attacker who can send crafted commands over a PCI connection could repeatedly trigger this failure, exhausting system resources. This could be relevant where the Linux kernel's NVMe target PCI endpoint function is deployed in automotive systems, such as for in-vehicle data storage or processing; confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80820
The advisory addresses a vulnerability in the Linux kernel's XFS filesystem, specifically a livelock issue that can occur during filesystem scrubbing when encountering a circular unlinked list. An attacker could potentially exploit this to cause a denial-of-service condition by making the system hang or become unresponsive during the scrub operation. The severity is not explicitly stated in the advisory, but the issue affects the XFS component, which could be relevant where XFS is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80819
This advisory addresses a Bluetooth RFCOMM vulnerability in the Linux kernel, where a missing mutex lock during deferred setup acceptance could allow an attacker to exploit the flaw. The technical impact is not detailed in the provided text, and no severity rating is given. This could be relevant where the Linux kernel with Bluetooth RFCOMM is deployed in automotive systems, such as for in-vehicle infotainment or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80817
A race condition in the Linux kernel's iommufd component can cause a system crash (NULL pointer dereference) when a memory-mapping operation overlaps with an IOAS change request, potentially allowing a local attacker to trigger a denial of service. The advisory does not state any automotive-specific deployment, but this kernel component could be relevant where iommufd is used in automotive systems that rely on Linux for IOMMU management. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80816
The advisory addresses a bug in the Linux kernel's ALSA FCP driver, which manages audio class devices, where a shared USB request block could cause a system crash or hang during device initialization or after suspend. An attacker could potentially exploit this to disrupt system stability, though no severity rating is stated. This could be relevant where Linux-based systems with audio class devices are deployed in automotive infotainment or telematics, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80815
The advisory describes a bug fix in the Linux kernel affecting the ALSA scarlett2 driver, which manages USB audio interfaces for Scarlett2 devices. The issue involves improper handling of a notification endpoint, which could lead to a system crash when the driver initializes or resumes. This could be relevant where such USB audio hardware is deployed in automotive infotainment or embedded systems, but the advisory does not confirm any automotive use. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80812
The advisory addresses a vulnerability in the Linux kernel's ALSA dummy sound driver, where a manually bound device could provide an invalid card index, potentially causing out-of-bounds memory access. An attacker exploiting this could trigger a system crash or other undefined behavior, with the fix adding a sanity check to correct the invalid value. This could be relevant where the Linux kernel is deployed in automotive systems, such as for in-vehicle infotainment or audio processing, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-80811
The Linux kernel contains a memory leak vulnerability in the io_uring subsystem, specifically affecting the handling of asynchronous commands such as NVMe passthrough workloads. An attacker could exploit this to cause memory exhaustion and system instability, though the advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics platforms. Confirm applicability through the product SBOM or dependency inventory.