Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
1962advisories found
cvelistv5medium
cve-2026-74680
The advisory addresses a fix in the Linux kernel for the cxacru USB ATM driver, specifically correcting the failure to properly terminate a receive URB (a data transfer request) when an error occurs during the cxacru_cm() function. An attacker could potentially exploit this error-handling flaw to cause a denial-of-service condition, such as a system crash or resource leak, though the advisory does not state a specific severity rating. This could be relevant where the cxacru driver is deployed in automotive systems that use USB-based ATM connectivity, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74678
This advisory addresses a fix for a memory leak in the Linux kernel's USB network driver for AX88179/AX88178A devices, where an attacker could potentially cause a denial of service by exhausting system memory through repeated network transmissions. The affected component is a USB Ethernet adapter driver, which could be relevant where such adapters are deployed in automotive systems for in-vehicle networking or diagnostics. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74677
This advisory addresses a use-after-free vulnerability in the Linux kernel's USB iPhone Ethernet driver (ipheth), where a race condition during device disconnection could allow an attacker to exploit freed memory. The technical impact is potential system instability or arbitrary code execution, though the advisory does not state a specific severity rating. This could be relevant where the Linux kernel with this driver is deployed in automotive systems, such as infotainment or telematics units using USB tethering, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74676
The advisory describes a Linux kernel patch that adds a permission check for the KDSKBMETA ioctl, which is a keyboard control operation. An attacker could potentially exploit the missing permission check to manipulate keyboard settings without proper authorization, though the advisory does not specify a severity rating. This could be relevant where Linux is deployed in automotive systems, such as infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74675
The advisory addresses a vulnerability in the Linux kernel related to stabilizing a TTY reference in the kbd_keycode function, which could be exploited by an attacker to cause a system issue. The affected component is the kernel's keyboard handling code, and the technical impact involves potential instability or security concerns, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74673
The advisory addresses a fix for an information leak in the evdev_pass_values() function within the Linux kernel's evdev subsystem, which handles input device events. An attacker could potentially exploit this flaw to access sensitive data from kernel memory, with the severity level not explicitly stated in the provided text. This could be relevant where the Linux kernel's evdev component is deployed in automotive systems, such as for handling touchscreens or input controls, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74672
This advisory addresses a vulnerability in the Linux kernel's memory management subsystem, specifically involving the mm/vmalloc component and a use-after-free issue related to ptdump. An attacker could potentially exploit this flaw to cause a system crash or gain unauthorized access, with the severity not explicitly stated in the provided text. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74670
The advisory addresses a vulnerability in the Linux kernel's IPVS (IP Virtual Server) component, where the estimator is not stopped after a disabled calculation phase. An attacker could potentially exploit this flaw to cause a denial-of-service condition by disrupting the system's load-balancing functionality. The severity is not explicitly stated in the advisory. This could be relevant where IPVS is deployed in automotive systems, such as for network load balancing in vehicle infrastructure. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74671
The advisory describes a fix for an out-of-bounds read vulnerability in the xattr_verify() function of the Linux kernel's Integrity Measurement Architecture (IMA). An attacker could potentially exploit this flaw to read sensitive kernel memory, leading to information disclosure. The severity is not explicitly stated in the provided text. This could be relevant where the Linux kernel with IMA is deployed in automotive systems, such as in infotainment or control units; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74668
The advisory addresses a Linux kernel issue where the TX_RING send path fails to use a consistent hard_header_len, which could allow an attacker to exploit the packet handling mechanism. The technical impact is not detailed in the provided text, and no severity rating is given. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74669
This advisory addresses a Linux kernel issue where IPv4 options are not cleared after rebasing tunnel ICMP errors, which could allow an attacker to exploit the mishandled options in network traffic. The affected component is the Linux kernel's IPVS subsystem, and the technical impact involves potential security weaknesses in ICMP error processing, though no specific severity rating is provided. This could be relevant where the Linux kernel with IPVS is deployed in automotive systems, such as in vehicle networking or telematics infrastructure, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74667
This advisory addresses a vulnerability in the Linux kernel's packet-socket transmit path, where the MAC header is not properly reset. An attacker could potentially exploit this flaw to cause incorrect packet handling or other unspecified technical impacts. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74666
This advisory addresses a packet processing issue in Linux, where synchronizing pressure clearing with ring reconfiguration could be exploited. An attacker could potentially disrupt network packet handling, leading to system instability or denial of service. This could be relevant where Linux is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74664
This advisory addresses a vulnerability in Open vSwitch, a virtual network switch component. An attacker could exploit mismatched update reply IDs to cause incorrect network behavior, potentially disrupting network communications. The severity is not explicitly stated in the advisory. This could be relevant where Open vSwitch is deployed in automotive systems, such as in-vehicle networking or telematics infrastructure. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74663
This advisory addresses a vulnerability in the Linux kernel's network scheduler (net/sched) that fails to reject overly deep qdisc hierarchies. An attacker could exploit this to cause a denial-of-service condition by exhausting system resources. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74662
The advisory addresses a vulnerability in the Linux kernel's IP fragment handling, specifically related to publishing queues before arming a timer. An attacker could potentially exploit this flaw to cause a denial-of-service condition or other unspecified impacts on systems running the affected Linux kernel. The severity is not explicitly stated in the provided text. This could be relevant where Linux is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74659
This advisory addresses a vulnerability in the Linux kernel's network bridge MRP (Media Redundancy Protocol) implementation, where uninitialised bytes can be sent on the wire. An attacker could potentially exploit this to leak sensitive information from kernel memory over the network. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle networking or telematics units. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74658
This advisory addresses a race condition in the Linux kernel's futex subsystem, which could allow an attacker to exploit improper handling of robust futexes during process exit. The technical impact is a potential privilege escalation or system instability, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74657
This advisory addresses a fix in the Linux kernel for the IPv4 routing function fib_nlmsg_size(), specifically correcting how it calculates message sizes for RTA_VIA nexthops. An attacker could potentially exploit this flaw to cause incorrect memory allocation, leading to a system crash or denial of service. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74655
This advisory addresses a fix for a TX DMA buffer flush issue in the Qualcomm GENI serial driver within the Linux kernel. An attacker could potentially exploit this flaw to cause improper data transmission handling, leading to system instability or denial of service. The severity is not explicitly stated in the advisory. This could be relevant where the Qualcomm GENI serial driver is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74654
The advisory addresses a Linux kernel issue in the serial 8250_dma driver, where stale RX state is not cleared on shutdown, potentially allowing an attacker to exploit the affected component. The technical impact involves improper handling of DMA receive data, which could lead to system instability or security risks, though the advisory does not specify a severity rating. This could be relevant where the 8250_dma serial driver is deployed in automotive systems, such as in-vehicle communication or telematics modules, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74652
cvelistv5medium
cve-2026-74651
This advisory addresses an out-of-bounds read vulnerability in the rtw_get_wpa_ie() function within the rtl8723bs Wi-Fi driver in the Linux kernel staging tree. An attacker could potentially exploit this flaw to read unintended memory, which may lead to information disclosure or a system crash. The severity is not explicitly stated in the advisory. This could be relevant where the rtl8723bs driver is deployed in automotive systems, such as for in-vehicle Wi-Fi connectivity, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74650
This advisory addresses an out-of-bounds read vulnerability in the WMM_param_handler() function of the rtl8723bs Wi-Fi driver in the Linux kernel. An attacker could potentially exploit this flaw to read sensitive information or cause a system crash, with the severity not explicitly stated in the provided text. This could be relevant where the rtl8723bs driver is deployed in automotive systems, such as for in-vehicle Wi-Fi connectivity, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74647
This advisory addresses a vulnerability in the Linux kernel's fastrpc component, where a buffer is removed from a list prior to an unmap operation. An attacker could potentially exploit this flaw to cause a use-after-free condition, leading to system instability or privilege escalation. The severity is not explicitly stated in the advisory. This could be relevant where fastrpc is deployed in automotive systems, as it is a component used for inter-process communication on Qualcomm platforms. Confirm applicability through the product SBOM or dependency inventory.