Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
nvdmedium

cve-2026-80779

The advisory describes a fix in the Linux kernel for the ionic network driver, where a hardware timestamp receive queue could incorrectly reference a transmit queue partner, potentially causing an out-of-bounds memory read and write. An attacker could exploit this flaw to cause memory corruption or a system crash, though the advisory does not state a specific severity rating. This could be relevant where the ionic driver is deployed in automotive systems using Linux-based networking, but the advisory does not confirm any automotive use; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80777

The advisory addresses a race condition in the Linux kernel's futex/pi component during process execution, where an incorrect memory check could allow a flaw in handling private futexes. An attacker could potentially exploit this to cause undefined behavior or security issues, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm vehicle use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80776

The advisory describes a race condition in the Linux kernel's futex subsystem that can cause a task performing a private hash resize to remain blocked in an uninterruptible sleep indefinitely, potentially leading to a kernel panic due to the hung-task detector. The fix serializes state reads to eliminate the race. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80774

The advisory describes a bug in the Linux kernel's HID driver for ASUS devices, where a missing check could cause a kernel crash when a non-USB device is incorrectly treated as USB. An attacker could potentially trigger this crash, leading to a denial of service. This could be relevant where the Linux kernel is deployed in automotive systems, such as infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80773

The advisory describes a bug fix in the Linux kernel's HID (Human Interface Device) subsystem for Huawei devices, where a missing check could allow a crafted device to cause a kernel crash (a "kernel splat"). The affected component is the kernel's HID driver code, which is a generic software layer that could be deployed in automotive systems for handling input devices. This could be relevant where the Linux kernel is used in automotive infotainment or control systems, and an attacker with physical or remote access to such a system could potentially trigger a denial-of-service condition. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80772

The Linux kernel contains a vulnerability in its HID (Human Interface Device) driver for Nintendo Joy-Con and Pro Controllers, where a malicious or spoofed controller can send a short input report that passes a weak length check, causing the driver to read beyond the report's declared size and leak internal kernel memory to userspace through the controller's IMU (inertial measurement unit) data. The advisory does not confirm automotive deployment, but this could be relevant where Linux-based systems with HID support for gaming controllers are deployed in automotive infotainment or embedded systems. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80770

The advisory describes a fix in the Linux kernel for the HID (Human Interface Device) subsystem, specifically addressing a failure to stop device I/O before calling hid_hw_stop during probe failure. An attacker could potentially exploit this flaw to cause a system crash or denial of service. This could be relevant where the Linux kernel's HID subsystem is deployed in automotive systems, such as infotainment or control units using HID devices. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80769

The advisory describes a bug fix in the Linux kernel's HID driver for Rapoo devices, where a missing check could cause a kernel crash when a non-USB device is incorrectly treated as USB. An attacker could potentially trigger this flaw to cause a system error or denial of service. The severity is not explicitly rated, but the issue is described as causing a kernel splat. This could be relevant where the Linux kernel is deployed in automotive systems, such as infotainment or control units using Rapoo HID devices. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80768

The advisory addresses a fix for a stack-use-after-return write vulnerability in the FT260 HID driver's I2C read race condition within the Linux kernel. An attacker could potentially exploit this flaw to cause memory corruption or a system crash, though the advisory does not specify a severity rating. This could be relevant where the FT260 driver is deployed in automotive systems, such as for I2C communication in embedded components, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80766

The advisory describes a fix for a use-after-free vulnerability in the Linux kernel's HID (Human Interface Device) uclogic driver, specifically involving the inrange_timer. An attacker could potentially exploit this flaw to cause memory corruption or a crash, though the advisory does not state a specific severity rating. This could be relevant where the Linux kernel with the uclogic driver is deployed in automotive systems, such as infotainment or control units using HID devices. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80765

This advisory addresses a vulnerability in the Linux kernel's Hyper-V driver, specifically a missing bounds check when validating initial device information. An attacker could potentially exploit this flaw to cause a denial of service or other undefined behavior within the affected system. This could be relevant where the Linux kernel with Hyper-V drivers is deployed in automotive systems, such as in-vehicle infotainment or telematics units that run virtualized environments; confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80761

The advisory describes a Linux kernel Bluetooth issue where the sockaddr structure is not zeroed before being returned in the getname function, potentially exposing uninitialized memory data. An attacker could exploit this to leak sensitive information from kernel memory through a Bluetooth connection. The severity is not explicitly stated in the advisory. This could be relevant where Linux Bluetooth stacks are deployed in automotive systems, such as for infotainment or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-80758

The advisory describes a use-after-free vulnerability in the Linux kernel's futex subsystem, where a race condition can cause a task to read memory from a freed hash allocation, potentially leading to system instability or exploitation. The affected component is the Linux kernel, which is a generic operating system component, so this could be relevant where Linux is deployed in automotive systems, such as in infotainment or control units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-80588

The advisory addresses a vulnerability in the Linux kernel's Multipath TCP (MPTCP) implementation, where errors in the receive path can prevent the reclaiming of forward-allocated memory, potentially causing memory to grow unboundedly in drop scenarios. An attacker could exploit this to exhaust system memory, leading to denial of service. The severity is not explicitly stated, but the fix is a kernel patch. This could be relevant where Linux-based systems with MPTCP are deployed in automotive systems, such as for telematics or in-vehicle networking, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-80587

This advisory addresses a vulnerability in the Linux kernel's MPTCP (Multipath TCP) networking component, where certain incoming suboptions could be incorrectly combined, potentially allowing a remote peer to send malformed or conflicting data. An attacker could exploit this to cause unexpected behavior or a system crash, with the fix enforcing stricter rules to ignore invalid combinations. This could be relevant where Linux with MPTCP is deployed in automotive systems, such as for vehicle-to-infrastructure communication or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-80585

This advisory addresses a bug in the Linux kernel’s Multipath TCP (MPTCP) implementation, specifically in the handling of TCP Fast Open (TFO) connections. The flaw could cause a system warning and leave stale state that might trigger a state-confusion bug, potentially allowing an attacker to disrupt network connections. The severity is not explicitly rated in the advisory, but the issue is a kernel-level logic error. This could be relevant where Linux-based systems with MPTCP are deployed in automotive systems, such as for in-vehicle networking or telematics. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-80583

The advisory describes a bug in the Linux kernel's audio codec driver for the "lpass-tx-macro" component, where the "DEC0 MODE" to "DEC7 MODE" controls are accessed incorrectly, causing read operations to fail with an error on 64-bit systems with debug enabled. An attacker could potentially exploit this to cause a denial of service by disrupting audio control functionality, though the stated severity is not explicitly detailed. This could be relevant where the lpass-tx-macro audio codec is deployed in automotive infotainment or telematics systems, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-80584

This advisory affects the Linux kernel's s390/qeth driver, which handles network communication for IBM mainframe systems. An attacker with access to the ioctl interface could exploit insufficient buffer length validation to cause a memory corruption issue, potentially leading to a crash or unauthorized code execution. This could be relevant where the s390/qeth driver is deployed in automotive systems, such as in backend infrastructure or telematics servers, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-80581

This advisory addresses a vulnerability in the Linux kernel's Sound Open Firmware (SOF) driver, specifically in the IPC4 PCM pipeline trigger mechanism. The fix ensures that pipeline state changes continue even when an IPC timeout or firmware crash occurs, preventing the kernel from getting stuck in an incorrect internal state. An attacker could potentially exploit this issue to disrupt audio processing or cause system instability, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel with SOF is deployed in automotive infotainment or audio systems, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-80582

The Linux kernel has a vulnerability in the DRM shared memory helper that could cause a system crash when handling huge page mappings that exceed memory region boundaries. An attacker could potentially trigger this flaw to cause a denial of service through a kernel panic. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-80578

The advisory addresses a vulnerability in the Linux kernel's fbdev core, specifically in the fb_io_read() function, where a partial copy to a user buffer could cause the hardware read pointer to advance incorrectly, potentially leading to out-of-bounds I/O reads. An attacker could exploit this to trigger unintended hardware access, with the fix ensuring the function stops safely after a partial copy. This could be relevant where the Linux kernel's framebuffer device subsystem is deployed in automotive systems, such as for display or infotainment, and the severity is not explicitly rated in the advisory. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-80579

This advisory describes a vulnerability in the Linux kernel's framebuffer (fbdev) subsystem, where a user can trigger deletion of a video mode while a stale pointer to it remains, potentially allowing a later read operation to access freed memory. The affected component is a generic kernel feature, not specifically automotive, so this could be relevant where the Linux kernel's framebuffer is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-80576

The advisory addresses a vulnerability in the Linux kernel's amdgpu driver, which manages AMD graphics processing units (GPUs). An attacker could submit oversized command buffers (IBs) that corrupt control bits and destabilize command submission, potentially leading to system instability or unauthorized actions. The fix adds limits to reject such oversized submissions, and the severity is not explicitly stated in the advisory. This could be relevant where amdgpu is deployed in automotive systems, such as for in-vehicle infotainment or advanced driver-assistance displays, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-80577

This advisory addresses a NULL pointer dereference vulnerability in the Linux kernel's Panthor GPU driver, which manages graphics processing units. An attacker could potentially exploit this flaw to cause a system crash or denial of service when the driver processes firmware sections with zero-sized memory ranges. The severity is not explicitly rated in the advisory. This could be relevant where the Panthor driver is deployed in automotive systems, such as in-vehicle infotainment or advanced driver-assistance platforms using compatible ARM GPUs. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-80573

This advisory addresses a vulnerability in the Linux kernel's iforce driver, which handles input from force-feedback joysticks and wheels. An attacker could exploit missing packet length validation to cause the driver to read beyond the intended data, potentially leading to system instability or unauthorized access. This could be relevant where the iforce driver is deployed in automotive systems, such as in-vehicle infotainment or diagnostic equipment using such input devices. Confirm applicability through the product SBOM or dependency inventory.