Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
cvelistv5medium

cve-2026-74745

This advisory addresses a deadlock vulnerability in the Linux kernel’s Broadcom bnxt Ethernet driver, where an attacker could potentially cause a system hang by triggering a race condition during interrupt handling. The affected component is a network driver, which could be relevant in automotive systems that use Linux-based infotainment or telematics units with this hardware. The issue is resolved by moving queue restart operations to an asynchronous task, and the severity is not explicitly rated in the advisory. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74742

This advisory addresses a bug in the Linux kernel's veth driver, a virtual Ethernet device commonly used in containers and virtualized environments. The flaw can cause a network transmit queue to become permanently stalled in multi-queue setups, preventing data from being sent and leading to network outages. The issue is rated as a vulnerability, and while the advisory does not confirm automotive use, this could be relevant where Linux-based veth networking is deployed in automotive systems, such as in-vehicle infotainment or telematics. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74743

A vulnerability in the Linux kernel affects macvlan network devices, which inherit header space requirements from their underlying lower network device. An attacker could exploit this to cause memory corruption, crashes, or system instability when the lower device requires extra space for headers or trailers. This could be relevant where macvlan is deployed in automotive systems, such as in-vehicle networking or telematics, and the severity is significant as it can lead to system crashes. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74741

This advisory addresses a NULL pointer dereference vulnerability in the Linux kernel driver for ngbe network devices, which can cause a system crash when the device operates in non-MSI-X interrupt mode. The issue arises because the driver incorrectly accesses an unallocated memory entry, and the fix corrects the interrupt vector selection and mask for legacy interrupt modes. The affected component is a network interface driver that could be deployed in automotive systems, so this could be relevant where ngbe-based Ethernet hardware is used in vehicles or related infrastructure. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74740

The advisory addresses a vulnerability in the Linux kernel's network traffic control subsystem, specifically a race condition that can cause a NULL pointer dereference when processing certain packet actions. An attacker could potentially exploit this flaw to crash the system, leading to a denial of service. The severity is not explicitly rated in the advisory, but the fix is a kernel-level correction. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74738

This advisory addresses a bug in the Linux kernel's regmap subsystem, specifically affecting the sdw-mbq component used for SoundWire MBQ register access. The vulnerability involves a missing optional callback that can cause the kernel to crash through a NULL function pointer when certain audio devices respond with a COMMAND_IGNORED status. The severity is not explicitly stated, but the issue could cause a system crash or denial of service. This could be relevant where the Linux kernel with the affected regmap component is deployed in automotive infotainment or audio systems, though the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74736

The advisory addresses a vulnerability in the Linux kernel's network traffic control component, specifically the cls_bpf classifier, where a device-bound BPF program could be incorrectly attached to a different network device. An attacker could exploit this mismatch to trigger a kernel warning or panic, potentially causing a denial of service. The severity is not explicitly rated, but the fix rejects such invalid attachments with an error. This could be relevant where the Linux kernel is deployed in automotive systems, such as for in-vehicle networking or telematics. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74734

The advisory describes a NULL pointer dereference bug in the Linux kernel's FireWire OHCI driver, which can cause a system crash during error handling when the driver's probe function fails early. An attacker could potentially trigger this crash, leading to a denial of service, though the advisory does not state a specific severity rating. This could be relevant where the FireWire OHCI driver is deployed in automotive systems, such as for in-vehicle multimedia or diagnostic interfaces, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74735

The advisory describes a fix in the Linux kernel for a reference-count leak in the L2TP networking component, which manages tunnel and session connections. If a user closes certain system files (like /proc/net/pppol2tp or debugfs entries) before fully reading them, the kernel fails to release internal references, potentially leading to resource exhaustion or instability. The severity is not explicitly rated, but the issue is a kernel bug fix. This could be relevant where Linux is deployed in automotive systems, such as in vehicle infotainment or telematics units using L2TP for network connections. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-78966

This advisory affects Google Chrome versions prior to 152.0.7977.65, where a flaw in the QUIC networking protocol allows a remote attacker to bypass web origin policy using a crafted HTML page, rated as Medium severity. This could be relevant where Chrome is deployed in automotive systems, such as infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium

cve-2026-78893

The advisory describes a medium-severity information leak in the QUIC protocol within Google Chrome versions prior to 152.0.7977.65, where a remote attacker could exploit a crafted HTML page to leak sensitive information. This could be relevant where Chrome or its QUIC implementation is deployed in automotive systems, such as in infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74733

This advisory addresses a fix in the Linux kernel for the pca953x GPIO driver, specifically correcting a lock issue in the interrupt synchronization function. An attacker could potentially exploit this flaw to cause a denial of service or system instability by disrupting the driver's interrupt handling. The severity is not explicitly stated in the advisory. This could be relevant where the pca953x GPIO expander is deployed in automotive systems, such as for controlling sensors or actuators, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74732

This advisory addresses a fix in the Linux kernel's AMD display driver, specifically adding a check for timing generator operations in the dce110_set_avmute function. An attacker could potentially exploit the missing check to cause a system crash or denial of service, though the advisory does not specify a severity rating. This could be relevant where AMD display hardware is deployed in automotive infotainment or digital cockpit systems, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74730

The advisory addresses a vulnerability in the Linux kernel's NFS (Network File System) component, specifically involving the failure to properly pin the 'struct nfs_server' during a FREE_STATEID call. An attacker could potentially exploit this flaw to cause a use-after-free condition, leading to system instability or a crash. The severity is not explicitly stated in the advisory. This could be relevant where NFS is deployed in automotive systems, such as in-vehicle infotainment or telematics units that use Linux-based storage services. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74731

cvelistv5medium

cve-2026-74728

cvelistv5medium

cve-2026-74726

This advisory addresses a Linux kernel vulnerability in the bonding driver, specifically in the bond_alb_monitor function where the primary_is_promisc setting is re-checked under RTNL. An attacker could potentially exploit this issue to cause incorrect network behavior or a denial of service in systems using bonded network interfaces. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74725

The advisory describes a fix for a use-after-free vulnerability in the Linux kernel's "enic" driver, specifically in the "tx_hang_reset" function, which occurs when a device is removed. An attacker could potentially exploit this flaw to cause memory corruption or a system crash, though the advisory does not state a severity rating. This could be relevant where the enic driver is deployed in automotive systems, such as in networking components for vehicles, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74723

This advisory addresses a vulnerability in the btrfs filesystem's LZO compression handling, where inline extents without valid headers are rejected. An attacker could potentially exploit this flaw to cause a denial of service or other system instability. The severity is not explicitly stated in the advisory. This could be relevant where btrfs is deployed in automotive systems, such as in embedded storage or infotainment platforms. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74721

cvelistv5medium

cve-2026-74719

This advisory addresses a vulnerability in the Linux kernel's SMC (Shared Memory Communications) networking component, specifically a fix for a queue entry overwrite issue in the SMC link layer control event handler. An attacker could potentially exploit this flaw to corrupt data or cause a denial of service by manipulating link control messages. This could be relevant where the Linux kernel with SMC is deployed in automotive systems, such as in telematics or infotainment platforms, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74720

This advisory addresses a vulnerability in the Linux kernel's Berkeley Packet Filter (BPF) subsystem, specifically related to preserving pointer state for commuted arithmetic operations. An attacker could potentially exploit this flaw to manipulate pointer arithmetic, which may lead to incorrect memory access or other security impacts. The severity is not explicitly stated in the provided text. This could be relevant where the Linux kernel with BPF is deployed in automotive systems, such as for network filtering or telematics. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74718

The advisory addresses a fix for a net namespace reference leak in the devlink reload function within the Linux kernel. An attacker could potentially exploit this leak to cause resource exhaustion or system instability, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel's devlink component is deployed in automotive systems, such as for network management in vehicles, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74715

This advisory addresses a fix in the Linux kernel for a reference imbalance in conntrack kfuncs related to BPF (Berkeley Packet Filter). An attacker could potentially exploit this flaw to cause a denial-of-service condition by disrupting network connection tracking. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in vehicle infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74713

This advisory addresses a vulnerability in the Linux kernel's vhost_iotlb component, specifically in the bound map allocation within the add_range function. An attacker could potentially exploit this flaw to cause a denial of service or other system-level impacts, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.