Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
cvelistv5medium

cve-2026-74711

This advisory addresses a type confusion vulnerability in the hwmon (pmbus) notification logic within the Linux kernel. An attacker could potentially exploit this flaw to cause unexpected behavior or a system compromise. This could be relevant where the Linux kernel with hwmon/pmbus support is deployed in automotive systems, such as for monitoring power management components. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74712

cvelistv5medium

cve-2026-74709

cvelistv5medium

cve-2026-74710

cvelistv5medium

cve-2026-74708

cvelistv5medium

cve-2026-74706

cvelistv5medium

cve-2026-74707

cvelistv5medium

cve-2026-74703

cvelistv5medium

cve-2026-74701

The advisory addresses a vulnerability in the Linux kernel's Open vSwitch (net/openvswitch) component, specifically a missing check for Ethernet header length in the key_extract() function. An attacker could exploit this flaw to cause undefined behavior or a system crash, with the severity not explicitly stated in the provided text. This could be relevant where Open vSwitch is deployed in automotive systems, such as for network virtualization in vehicle or fleet infrastructure, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74700

This advisory addresses a vulnerability in the Linux kernel's network traffic classifier (net/sched: cls_api), where a failure to always acquire a required lock when destroying classifiers could allow an attacker to cause a denial of service. The severity is not explicitly stated in the provided text. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74698

cvelistv5medium

cve-2026-74697

This advisory addresses a data corruption issue in the bnxt_en network driver for Broadcom chips, where disabling EOP (End of Packet) for TPA (Transparent Packet Aggregation) is required to prevent data corruption. An attacker could potentially exploit this flaw to cause data integrity problems in network communications. This could be relevant where the bnxt_en driver is deployed in automotive systems, such as in-vehicle networking or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74695

This advisory addresses a vulnerability in the Linux kernel's netfilter flow table component, where an existing socket buffer destination is not properly dropped before a new one is set, potentially allowing an attacker to exploit incorrect network packet routing. The technical impact could include network traffic manipulation or disruption, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel's netfilter component is deployed in automotive systems, such as in-vehicle networking or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74696

This advisory addresses a fix in the Linux kernel for TCP Fast Open (TFO) queue length accounting during socket migration across reuseport. An attacker could potentially exploit this accounting flaw to disrupt network connections or resource management. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74692

This advisory addresses a race condition in the Linux kernel's SMC (Shared Memory Communications) networking component, where a time-of-check-to-time-of-use flaw exists between the smc_listen_out() function and the closing of a listener socket. An attacker could potentially exploit this race to cause a system crash or other undefined behavior. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel with SMC support is deployed in automotive systems, such as in infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74693

This advisory addresses a vulnerability in the Linux kernel's Prestera network switch driver, where the firmware header length is not properly validated. An attacker could potentially exploit this flaw to cause a denial of service or other undefined behavior in systems using this driver. The severity is not explicitly stated in the advisory. This could be relevant where the Prestera driver is deployed in automotive systems, such as in-vehicle networking hardware, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74690

This advisory addresses a use-after-free vulnerability in the s390/ism driver within the Linux kernel, where the sba and ieq structures are improperly freed during device exit, potentially allowing an attacker to exploit the freed memory. The affected component is the IBM System z (s390) ISM driver, which is not explicitly confirmed to be in automotive systems, so this could be relevant where the s390/ism driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory. The advisory does not state a severity rating, but the technical impact is a use-after-free condition that could lead to memory corruption or system instability.

cvelistv5medium

cve-2026-74691

This advisory addresses a vulnerability in the Linux kernel's Thunderbolt driver, where DMA paths are not properly torn down before stopping the rings. An attacker could potentially exploit this flaw to cause a denial of service or other unspecified impacts. The severity is not explicitly stated in the advisory. This could be relevant where Thunderbolt networking is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74689

This advisory addresses a vulnerability in the Linux kernel's ATM networking component, specifically a slab-out-of-bounds read in the vcc_setsockopt() function. An attacker could potentially exploit this flaw to read out-of-bounds memory, leading to information disclosure or system instability. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel's ATM networking is deployed in automotive systems, such as in telematics or infotainment units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74687

This advisory addresses a vulnerability in the Linux kernel's watchdog driver for AT91SAM9 microcontrollers, where the watchdog timer can be re-armed during teardown, potentially causing unintended system behavior. An attacker could exploit this flaw to disrupt the system's watchdog functionality, which is used to reset or monitor system health. The severity is not explicitly stated in the advisory. This could be relevant where AT91SAM9-based hardware is deployed in automotive systems, such as in embedded control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74688

The advisory addresses a vulnerability in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation, specifically involving the clearing of a control chunk transport when it is being removed. An attacker could potentially exploit this flaw to cause a denial of service or other unspecified technical impacts, though the advisory does not provide a severity rating. This could be relevant where SCTP is deployed in automotive systems, such as for telematics or in-vehicle networking, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74686

cvelistv5medium

cve-2026-74684

This advisory addresses a vulnerability in the Linux kernel's network tap driver, where the network device is not set before parsing the virtio net header in the tap_get_user_xdp() function. An attacker could potentially exploit this flaw to cause incorrect packet handling or a system crash, with the severity not explicitly stated in the provided text. This could be relevant where the Linux tap driver is deployed in automotive systems, such as for virtualized network interfaces in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74683

This advisory addresses a vulnerability in the Linux kernel's evdev subsystem, where the event type index is not properly sanitized when fetching event masks. An attacker could potentially exploit this flaw to cause unintended behavior or a security issue in systems using this component. This could be relevant where evdev is deployed in automotive systems, such as in-vehicle infotainment or embedded Linux platforms, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74681