Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
cvelistv5medium

cve-2026-74680

The advisory addresses a fix in the Linux kernel for the cxacru USB ATM driver, specifically correcting the failure to properly terminate a receive URB (a data transfer request) when an error occurs during the cxacru_cm() function. An attacker could potentially exploit this error-handling flaw to cause a denial-of-service condition, such as a system crash or resource leak, though the advisory does not state a specific severity rating. This could be relevant where the cxacru driver is deployed in automotive systems that use USB-based ATM connectivity, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74678

This advisory addresses a fix for a memory leak in the Linux kernel's USB network driver for AX88179/AX88178A devices, where an attacker could potentially cause a denial of service by exhausting system memory through repeated network transmissions. The affected component is a USB Ethernet adapter driver, which could be relevant where such adapters are deployed in automotive systems for in-vehicle networking or diagnostics. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74677

This advisory addresses a use-after-free vulnerability in the Linux kernel's USB iPhone Ethernet driver (ipheth), where a race condition during device disconnection could allow an attacker to exploit freed memory. The technical impact is potential system instability or arbitrary code execution, though the advisory does not state a specific severity rating. This could be relevant where the Linux kernel with this driver is deployed in automotive systems, such as infotainment or telematics units using USB tethering, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74676

The advisory describes a Linux kernel patch that adds a permission check for the KDSKBMETA ioctl, which is a keyboard control operation. An attacker could potentially exploit the missing permission check to manipulate keyboard settings without proper authorization, though the advisory does not specify a severity rating. This could be relevant where Linux is deployed in automotive systems, such as infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74675

The advisory addresses a vulnerability in the Linux kernel related to stabilizing a TTY reference in the kbd_keycode function, which could be exploited by an attacker to cause a system issue. The affected component is the kernel's keyboard handling code, and the technical impact involves potential instability or security concerns, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74673

The advisory addresses a fix for an information leak in the evdev_pass_values() function within the Linux kernel's evdev subsystem, which handles input device events. An attacker could potentially exploit this flaw to access sensitive data from kernel memory, with the severity level not explicitly stated in the provided text. This could be relevant where the Linux kernel's evdev component is deployed in automotive systems, such as for handling touchscreens or input controls, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74672

This advisory addresses a vulnerability in the Linux kernel's memory management subsystem, specifically involving the mm/vmalloc component and a use-after-free issue related to ptdump. An attacker could potentially exploit this flaw to cause a system crash or gain unauthorized access, with the severity not explicitly stated in the provided text. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74670

The advisory addresses a vulnerability in the Linux kernel's IPVS (IP Virtual Server) component, where the estimator is not stopped after a disabled calculation phase. An attacker could potentially exploit this flaw to cause a denial-of-service condition by disrupting the system's load-balancing functionality. The severity is not explicitly stated in the advisory. This could be relevant where IPVS is deployed in automotive systems, such as for network load balancing in vehicle infrastructure. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74671

The advisory describes a fix for an out-of-bounds read vulnerability in the xattr_verify() function of the Linux kernel's Integrity Measurement Architecture (IMA). An attacker could potentially exploit this flaw to read sensitive kernel memory, leading to information disclosure. The severity is not explicitly stated in the provided text. This could be relevant where the Linux kernel with IMA is deployed in automotive systems, such as in infotainment or control units; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74668

The advisory addresses a Linux kernel issue where the TX_RING send path fails to use a consistent hard_header_len, which could allow an attacker to exploit the packet handling mechanism. The technical impact is not detailed in the provided text, and no severity rating is given. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74669

This advisory addresses a Linux kernel issue where IPv4 options are not cleared after rebasing tunnel ICMP errors, which could allow an attacker to exploit the mishandled options in network traffic. The affected component is the Linux kernel's IPVS subsystem, and the technical impact involves potential security weaknesses in ICMP error processing, though no specific severity rating is provided. This could be relevant where the Linux kernel with IPVS is deployed in automotive systems, such as in vehicle networking or telematics infrastructure, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74667

This advisory addresses a vulnerability in the Linux kernel's packet-socket transmit path, where the MAC header is not properly reset. An attacker could potentially exploit this flaw to cause incorrect packet handling or other unspecified technical impacts. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74666

This advisory addresses a packet processing issue in Linux, where synchronizing pressure clearing with ring reconfiguration could be exploited. An attacker could potentially disrupt network packet handling, leading to system instability or denial of service. This could be relevant where Linux is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74664

This advisory addresses a vulnerability in Open vSwitch, a virtual network switch component. An attacker could exploit mismatched update reply IDs to cause incorrect network behavior, potentially disrupting network communications. The severity is not explicitly stated in the advisory. This could be relevant where Open vSwitch is deployed in automotive systems, such as in-vehicle networking or telematics infrastructure. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74663

This advisory addresses a vulnerability in the Linux kernel's network scheduler (net/sched) that fails to reject overly deep qdisc hierarchies. An attacker could exploit this to cause a denial-of-service condition by exhausting system resources. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74662

The advisory addresses a vulnerability in the Linux kernel's IP fragment handling, specifically related to publishing queues before arming a timer. An attacker could potentially exploit this flaw to cause a denial-of-service condition or other unspecified impacts on systems running the affected Linux kernel. The severity is not explicitly stated in the provided text. This could be relevant where Linux is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74659

This advisory addresses a vulnerability in the Linux kernel's network bridge MRP (Media Redundancy Protocol) implementation, where uninitialised bytes can be sent on the wire. An attacker could potentially exploit this to leak sensitive information from kernel memory over the network. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle networking or telematics units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74658

This advisory addresses a race condition in the Linux kernel's futex subsystem, which could allow an attacker to exploit improper handling of robust futexes during process exit. The technical impact is a potential privilege escalation or system instability, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74657

This advisory addresses a fix in the Linux kernel for the IPv4 routing function fib_nlmsg_size(), specifically correcting how it calculates message sizes for RTA_VIA nexthops. An attacker could potentially exploit this flaw to cause incorrect memory allocation, leading to a system crash or denial of service. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74655

This advisory addresses a fix for a TX DMA buffer flush issue in the Qualcomm GENI serial driver within the Linux kernel. An attacker could potentially exploit this flaw to cause improper data transmission handling, leading to system instability or denial of service. The severity is not explicitly stated in the advisory. This could be relevant where the Qualcomm GENI serial driver is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74654

The advisory addresses a Linux kernel issue in the serial 8250_dma driver, where stale RX state is not cleared on shutdown, potentially allowing an attacker to exploit the affected component. The technical impact involves improper handling of DMA receive data, which could lead to system instability or security risks, though the advisory does not specify a severity rating. This could be relevant where the 8250_dma serial driver is deployed in automotive systems, such as in-vehicle communication or telematics modules, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74652

cvelistv5medium

cve-2026-74651

This advisory addresses an out-of-bounds read vulnerability in the rtw_get_wpa_ie() function within the rtl8723bs Wi-Fi driver in the Linux kernel staging tree. An attacker could potentially exploit this flaw to read unintended memory, which may lead to information disclosure or a system crash. The severity is not explicitly stated in the advisory. This could be relevant where the rtl8723bs driver is deployed in automotive systems, such as for in-vehicle Wi-Fi connectivity, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74650

This advisory addresses an out-of-bounds read vulnerability in the WMM_param_handler() function of the rtl8723bs Wi-Fi driver in the Linux kernel. An attacker could potentially exploit this flaw to read sensitive information or cause a system crash, with the severity not explicitly stated in the provided text. This could be relevant where the rtl8723bs driver is deployed in automotive systems, such as for in-vehicle Wi-Fi connectivity, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74647

This advisory addresses a vulnerability in the Linux kernel's fastrpc component, where a buffer is removed from a list prior to an unmap operation. An attacker could potentially exploit this flaw to cause a use-after-free condition, leading to system instability or privilege escalation. The severity is not explicitly stated in the advisory. This could be relevant where fastrpc is deployed in automotive systems, as it is a component used for inter-process communication on Qualcomm platforms. Confirm applicability through the product SBOM or dependency inventory.