Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
cve-2026-74646
This advisory addresses a locking issue in the Linux kernel's fastrpc driver, which manages remote procedure calls for Qualcomm-based hardware. An attacker could potentially exploit the missing lock when memory mappings are moved during an interrupted invoke, leading to a race condition that may cause system instability or unauthorized access. The severity is not explicitly stated in the advisory. This could be relevant where the fastrpc driver is deployed in automotive systems, such as in-vehicle infotainment or telematics units using Qualcomm chipsets. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74644
cve-2026-74643
cve-2026-74641
The advisory addresses a vulnerability in the ALSA usx2y driver for Linux, specifically bounding the hwdep mmap fault offset. An attacker could potentially exploit this flaw to cause memory-related issues, such as a crash or unauthorized access, within the affected component. The severity is not explicitly stated in the advisory. This could be relevant where the ALSA usx2y driver is deployed in automotive systems, such as for audio processing in infotainment units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74642
cve-2026-74638
This advisory addresses a fix in the Linux kernel's DRM V3D graphics driver, which serializes scheduler timeout handlers to prevent potential race conditions. An attacker could potentially exploit this flaw to cause instability or a denial-of-service condition, though the advisory does not specify a severity rating. This could be relevant where the V3D driver is deployed in automotive systems, such as in-vehicle infotainment or graphics processing units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74636
This advisory addresses a race condition in the Linux kernel's tracing subsystem between the functions update_event_fields and event_define_fields. An attacker could potentially exploit this race to cause a system crash or other undefined behavior, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74634
cve-2026-74635
The advisory addresses a vulnerability in the Linux kernel's fbdev bitblit component, specifically a missing bound check for glyph indexes in the bit_cursor() function. An attacker could potentially exploit this flaw to cause memory corruption or a system crash, with the severity not explicitly stated in the provided text. This could be relevant where the Linux kernel's framebuffer console is deployed in automotive systems, such as in-vehicle infotainment or display units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74633
cve-2026-74632
This advisory addresses a race condition in the Linux kernel's memory management subsystem, specifically in the handling of huge zero pages. An attacker could potentially exploit this flaw to cause a system crash or other memory-related instability. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74630
This advisory addresses a vulnerability in the Linux kernel's IPv6 networking code, specifically preventing the in6_dev_get() function from incorrectly resurrecting a network device structure. An attacker could potentially exploit this flaw to cause a denial-of-service condition by manipulating network operations. The severity is not explicitly stated in the provided text. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74631
This advisory addresses a fix in the Linux kernel for a lifetime imbalance in the SMC (Shared Memory Communications) receive splice path, which could be exploited by an attacker to cause a system crash or other instability. The affected component is the kernel's networking stack, which is a generic software element, so this could be relevant where Linux is deployed in automotive systems, such as in infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74628
This advisory addresses a use-after-free vulnerability in the Linux kernel's X.25 networking protocol, where the socket could be freed while its timers are still active. An attacker could potentially exploit this flaw to cause a system crash or execute arbitrary code, with the severity not explicitly stated in the provided text. This could be relevant where the Linux kernel's X.25 networking stack is deployed in automotive systems, such as for legacy telematics or industrial communication, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74626
This advisory addresses a vulnerability in the Linux kernel's NTB (Non-Transparent Bridge) network driver, where a failure to allocate memory could reduce the receive queue depth, potentially impacting network performance or reliability. An attacker could exploit this to degrade network operations, though the advisory does not specify a severity rating. This could be relevant where the NTB driver is deployed in automotive systems for high-speed data transfer between processors, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74627
cve-2026-74625
This advisory addresses a vulnerability in the Linux kernel's netfilter bridge component, where a template connection tracking entry is not properly released on non-IP network paths. An attacker could potentially exploit this flaw to cause a denial of service by exhausting system resources. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel's netfilter bridge is deployed in automotive systems, such as in-vehicle networking or gateway devices. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74624
This advisory addresses a vulnerability in the Linux kernel's netfilter connection tracking component, where invalid log messages are deferred until after a lock is released. An attacker could potentially exploit this issue to cause a denial of service or other unspecified impacts, with the severity not explicitly stated in the provided text. This could be relevant where the Linux kernel's netfilter component is deployed in automotive systems, such as in vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74622
This advisory addresses a vulnerability in the Linux kernel's network subsystem where free receive (RX) pages of consumed but not refilled buffers are not properly handled. An attacker could potentially exploit this flaw to cause a denial-of-service condition by exhausting system resources. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74623
The advisory addresses a Linux kernel issue where stranded TX buffers are not freed during network ring deinitialization in the Atlantic network driver. An attacker could potentially exploit this to cause memory exhaustion or resource leaks, impacting system stability. The severity is not explicitly stated in the advisory. This could be relevant where the Atlantic network driver is deployed in automotive systems, such as in-vehicle networking or telematics. Confirm applicability through the product SBOM or dependency inventory.
cve-2026-74621
This advisory addresses a memory leak in the Linux kernel's network traffic control subsystem, specifically in the act_ct module, where a packet buffer is not properly released when header checks reject a packet. An attacker could exploit this flaw to exhaust system memory over time, potentially leading to a denial-of-service condition, though the advisory does not specify a severity rating. This could be relevant where Linux-based systems with this networking component are deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
cve-2026-74620
This advisory addresses a vulnerability in the Linux kernel's network traffic control components, specifically the act_gact and act_police modules, where a missing range check on the fallback control action could allow an attacker to exploit the system. The technical impact is that a local attacker could potentially cause a denial of service or other undefined behavior by manipulating network packet handling rules. This could be relevant where Linux-based systems with these networking components are deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.