Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
nvdmedium

cve-2026-80809

The advisory addresses a vulnerability in the Linux kernel's ocfs2 filesystem, specifically a missing metadata reservation for large extended attributes. An attacker could potentially exploit this flaw to cause a denial of service or other system instability. This could be relevant where the ocfs2 filesystem is deployed in automotive systems, such as in embedded Linux-based infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80808

This advisory addresses a Linux kernel ext4 filesystem issue where the system stops retrying saturated extended attribute (xattr) cache entries. An attacker could potentially exploit this to cause a denial of service or other unspecified impacts on systems using ext4. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel with ext4 is deployed in automotive systems, such as infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80807

The advisory addresses a vulnerability in the nilfs2 file system, specifically a failure to reject an invalid block index in a garbage collection ioctl operation. An attacker could potentially exploit this flaw to cause a system crash or other undefined behavior, though the advisory does not state a specific severity rating. This could be relevant where nilfs2 is deployed in automotive systems, such as in embedded storage for infotainment or data logging, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80805

The advisory addresses a vulnerability in the Linux xfs filesystem, where an attribute entry pointer is not validated before field access, potentially allowing an attacker to exploit this flaw. The technical impact could involve memory corruption or unauthorized access, though the advisory does not specify a severity rating. This could be relevant where the Linux xfs filesystem is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80804

The advisory describes a bug in the Linux kernel's XFS filesystem where an error during a transaction roll fails to restore a memory-allocation context, potentially causing a system deadlock (circular lock dependency). An attacker could exploit this to crash the system, though no severity rating is provided. This could be relevant where the Linux kernel with XFS is deployed in automotive systems, such as infotainment or telematics units; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80803

This advisory addresses a vulnerability in the Linux kernel's NFC (Near Field Communication) subsystem, where the SENSF_RES length is not properly clamped to the destination buffer, potentially allowing an attacker to exploit this flaw. The technical impact could involve memory corruption or related issues, though the advisory does not specify a severity rating. This could be relevant where Linux-based NFC components are deployed in automotive systems, such as for keyless entry or infotainment, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80802

This advisory addresses a vulnerability in the Linux kernel's NFC (Near Field Communication) subsystem, where the device-reported read length is not properly bounded and an skb (network buffer) leak can occur. An attacker could potentially exploit this flaw to cause a denial of service or other unspecified technical impacts. This could be relevant where the Linux kernel's NFC subsystem is deployed in automotive systems, such as for keyless entry or infotainment, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80801

This advisory addresses a validation issue in the NFC microread component, where target discovery payload lengths are not properly checked. An attacker could exploit this flaw to cause unintended behavior, potentially leading to a security compromise. The severity is not explicitly stated in the advisory. This could be relevant where the NFC microread component is deployed in automotive systems, such as for keyless entry or infotainment, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80800

This advisory addresses a vulnerability in the Linux kernel's NFC (Near Field Communication) subsystem, specifically in the LLCP protocol's handling of the connect_sn TLV, where a missing bound check could allow an attacker to cause a crash or other undefined behavior. The technical impact is a potential denial of service or memory corruption, though no severity rating is explicitly stated in the provided text. This could be relevant where the Linux kernel's NFC stack is deployed in automotive systems, such as for keyless entry or infotainment, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80799

This advisory addresses an out-of-bounds read and an 8-bit offset wrap vulnerability in the NFC (Near Field Communication) LLCP TLV parsers within the Linux kernel. An attacker could exploit these flaws to cause memory access issues, potentially leading to a system crash or other undefined behavior. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel's NFC subsystem is deployed in automotive systems, such as for keyless entry or infotainment; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80798

A security advisory addresses a vulnerability in the Linux kernel's NFC (Near Field Communication) LLCP protocol, where malformed packets shorter than the required header are not properly rejected. An attacker could exploit this flaw to potentially cause a denial of service or other unspecified impacts on systems using this NFC component. This could be relevant where the Linux NFC stack is deployed in automotive systems, such as for keyless entry or infotainment, but the advisory does not confirm vehicle use; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80797

The advisory addresses a vulnerability in the Linux kernel's NFC (Near Field Communication) PN533 driver, where fragmented socket buffers are not properly purged during cleanup, potentially allowing an attacker to exploit this flaw. The technical impact involves a security issue in the driver's memory handling, though the advisory does not specify a severity rating or detail the exact consequences. This could be relevant where the PN533 driver is deployed in automotive systems for NFC-based features, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80796

The advisory addresses a Linux kernel vulnerability in the NFC (Near Field Communication) NCI subsystem, where missing data length checks in activation parameter extractors could allow an attacker to exploit malformed data. The technical impact is potential memory corruption or other security issues, though the advisory does not specify a severity rating. This could be relevant where the Linux NFC stack is deployed in automotive systems, such as for keyless entry or infotainment, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80794

This advisory addresses an uninitialized value vulnerability in the NFC (Near Field Communication) NCI subsystem of the Linux kernel, specifically in the handling of RF discover and activated notification handlers. An attacker could potentially exploit this flaw to cause a system crash or expose sensitive information by triggering the processing of malformed NFC data. This could be relevant where the Linux kernel's NFC subsystem is deployed in automotive systems, such as for keyless entry or infotainment features; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80793

This advisory addresses a vulnerability in the Linux kernel's IPv4 fragmentation handling, where undersized maximum transmission units (MTUs) are not properly rejected in the ip_do_fragment() function. An attacker could potentially exploit this flaw to cause a denial-of-service condition or other unspecified technical impacts on systems running the affected Linux kernel. The severity is not explicitly stated in the advisory. This could be relevant where Linux is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80791

The advisory addresses a vulnerability in the Linux kernel's nvmet-auth component, where the AUTH_RECEIVE response buffer is not zeroed, potentially exposing sensitive authentication data to an attacker. The technical impact involves information disclosure during NVMe authentication processes, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel's NVMe subsystem is deployed in automotive systems, such as in-vehicle storage or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80790

This advisory addresses a bug in the Linux kernel's nvmet-fc component, which handles NVMe over Fibre Channel storage protocols. The issue involves an invalid memory free operation in an error-handling path, which could potentially be exploited by an attacker to cause a system crash or other instability. The severity is not explicitly stated in the advisory. This could be relevant where nvmet-fc is deployed in automotive systems, such as in-vehicle data storage or telematics infrastructure, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80789

The advisory addresses a vulnerability in the Linux kernel's nvmet-tcp component, where the system fails to properly bound SGL data length before allocating command buffers. An attacker could exploit this flaw to cause a denial-of-service condition or potentially other impacts, with severity details not specified in the provided text. This could be relevant where nvmet-tcp is deployed in automotive systems, such as in-vehicle storage or telematics infrastructure, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80788

The advisory addresses a vulnerability in the Linux kernel's nvmet-tcp component, where oversized SGL allocations controlled by a remote attacker could trigger a warning. An attacker could potentially exploit this to cause a denial-of-service condition by crashing the system. This could be relevant where the Linux kernel with nvmet-tcp is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80786

The advisory describes a fix in the Linux kernel for the framebuffer device (fbdev) subsystem, which manages display output. The vulnerability involves user-invoked calls to the fb_set_var() function, where the fix ensures proper coordination with the framebuffer console (fbcon) during display mode changes. An attacker could potentially exploit this flaw to cause incorrect display state handling, though the advisory does not specify a concrete technical impact or severity rating. This could be relevant where the Linux kernel's fbdev subsystem is deployed in automotive systems, such as for in-vehicle infotainment displays. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80785

The advisory addresses a vulnerability in the Linux kernel's fbdev component, specifically a missing serialization of mode sysfs access with lock_fb_info(), which could allow an attacker to exploit race conditions. The technical impact is not detailed in the advisory, and no severity rating is provided. This could be relevant where fbdev is deployed in automotive systems, such as in-vehicle infotainment or display controllers, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80784

This advisory addresses a memory leak in the Linux kernel's Multipath TCP (MPTCP) subsystem, caused by a race condition during connection teardown that can occur when memory is allocated at the same time. An attacker could potentially exploit this flaw to exhaust system memory, leading to a denial-of-service condition, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel with MPTCP is deployed in automotive systems, such as for in-vehicle networking or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80783

The advisory addresses a Linux kernel vulnerability in the HID driver for Apple Magic Mouse devices, specifically preventing unbounded recursion in the magicmouse_raw_event() function. An attacker could potentially exploit this flaw to cause a denial-of-service condition through excessive recursion, though the advisory does not state a specific severity rating. This could be relevant where the Linux kernel with this HID driver is deployed in automotive systems, such as infotainment or telematics units using such input devices; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80781

The advisory addresses a vulnerability in the Linux kernel's HID (Human Interface Device) core, specifically an out-of-bounds read of the field->usage data in the hid_set_field() function. An attacker could exploit this flaw to read memory beyond intended boundaries, potentially leading to information disclosure or system instability. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units that process HID inputs. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80780

This advisory addresses a vulnerability in the Linux kernel's HID (Human Interface Device) subsystem, specifically an out-of-bounds write that can occur when the hid->inputs list is empty. An attacker could potentially exploit this flaw to cause memory corruption, which may lead to system instability or privilege escalation. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units that process HID inputs. Confirm applicability through the product SBOM or dependency inventory.