Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
1962advisories found
cvelistv5medium
cve-2026-74711
This advisory addresses a type confusion vulnerability in the hwmon (pmbus) notification logic within the Linux kernel. An attacker could potentially exploit this flaw to cause unexpected behavior or a system compromise. This could be relevant where the Linux kernel with hwmon/pmbus support is deployed in automotive systems, such as for monitoring power management components. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74712
cvelistv5medium
cve-2026-74709
cvelistv5medium
cve-2026-74710
cvelistv5medium
cve-2026-74708
cvelistv5medium
cve-2026-74706
cvelistv5medium
cve-2026-74707
cvelistv5medium
cve-2026-74703
cvelistv5medium
cve-2026-74701
The advisory addresses a vulnerability in the Linux kernel's Open vSwitch (net/openvswitch) component, specifically a missing check for Ethernet header length in the key_extract() function. An attacker could exploit this flaw to cause undefined behavior or a system crash, with the severity not explicitly stated in the provided text. This could be relevant where Open vSwitch is deployed in automotive systems, such as for network virtualization in vehicle or fleet infrastructure, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74700
This advisory addresses a vulnerability in the Linux kernel's network traffic classifier (net/sched: cls_api), where a failure to always acquire a required lock when destroying classifiers could allow an attacker to cause a denial of service. The severity is not explicitly stated in the provided text. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74698
cvelistv5medium
cve-2026-74697
This advisory addresses a data corruption issue in the bnxt_en network driver for Broadcom chips, where disabling EOP (End of Packet) for TPA (Transparent Packet Aggregation) is required to prevent data corruption. An attacker could potentially exploit this flaw to cause data integrity problems in network communications. This could be relevant where the bnxt_en driver is deployed in automotive systems, such as in-vehicle networking or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74695
This advisory addresses a vulnerability in the Linux kernel's netfilter flow table component, where an existing socket buffer destination is not properly dropped before a new one is set, potentially allowing an attacker to exploit incorrect network packet routing. The technical impact could include network traffic manipulation or disruption, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel's netfilter component is deployed in automotive systems, such as in-vehicle networking or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74696
This advisory addresses a fix in the Linux kernel for TCP Fast Open (TFO) queue length accounting during socket migration across reuseport. An attacker could potentially exploit this accounting flaw to disrupt network connections or resource management. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74692
This advisory addresses a race condition in the Linux kernel's SMC (Shared Memory Communications) networking component, where a time-of-check-to-time-of-use flaw exists between the smc_listen_out() function and the closing of a listener socket. An attacker could potentially exploit this race to cause a system crash or other undefined behavior. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel with SMC support is deployed in automotive systems, such as in infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74693
This advisory addresses a vulnerability in the Linux kernel's Prestera network switch driver, where the firmware header length is not properly validated. An attacker could potentially exploit this flaw to cause a denial of service or other undefined behavior in systems using this driver. The severity is not explicitly stated in the advisory. This could be relevant where the Prestera driver is deployed in automotive systems, such as in-vehicle networking hardware, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74690
This advisory addresses a use-after-free vulnerability in the s390/ism driver within the Linux kernel, where the sba and ieq structures are improperly freed during device exit, potentially allowing an attacker to exploit the freed memory. The affected component is the IBM System z (s390) ISM driver, which is not explicitly confirmed to be in automotive systems, so this could be relevant where the s390/ism driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory. The advisory does not state a severity rating, but the technical impact is a use-after-free condition that could lead to memory corruption or system instability.
cvelistv5medium
cve-2026-74691
This advisory addresses a vulnerability in the Linux kernel's Thunderbolt driver, where DMA paths are not properly torn down before stopping the rings. An attacker could potentially exploit this flaw to cause a denial of service or other unspecified impacts. The severity is not explicitly stated in the advisory. This could be relevant where Thunderbolt networking is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74689
This advisory addresses a vulnerability in the Linux kernel's ATM networking component, specifically a slab-out-of-bounds read in the vcc_setsockopt() function. An attacker could potentially exploit this flaw to read out-of-bounds memory, leading to information disclosure or system instability. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel's ATM networking is deployed in automotive systems, such as in telematics or infotainment units. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74687
This advisory addresses a vulnerability in the Linux kernel's watchdog driver for AT91SAM9 microcontrollers, where the watchdog timer can be re-armed during teardown, potentially causing unintended system behavior. An attacker could exploit this flaw to disrupt the system's watchdog functionality, which is used to reset or monitor system health. The severity is not explicitly stated in the advisory. This could be relevant where AT91SAM9-based hardware is deployed in automotive systems, such as in embedded control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74688
The advisory addresses a vulnerability in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation, specifically involving the clearing of a control chunk transport when it is being removed. An attacker could potentially exploit this flaw to cause a denial of service or other unspecified technical impacts, though the advisory does not provide a severity rating. This could be relevant where SCTP is deployed in automotive systems, such as for telematics or in-vehicle networking, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74686
cvelistv5medium
cve-2026-74684
This advisory addresses a vulnerability in the Linux kernel's network tap driver, where the network device is not set before parsing the virtio net header in the tap_get_user_xdp() function. An attacker could potentially exploit this flaw to cause incorrect packet handling or a system crash, with the severity not explicitly stated in the provided text. This could be relevant where the Linux tap driver is deployed in automotive systems, such as for virtualized network interfaces in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74683
This advisory addresses a vulnerability in the Linux kernel's evdev subsystem, where the event type index is not properly sanitized when fetching event masks. An attacker could potentially exploit this flaw to cause unintended behavior or a security issue in systems using this component. This could be relevant where evdev is deployed in automotive systems, such as in-vehicle infotainment or embedded Linux platforms, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74681