Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
1962advisories found
cvelistv5medium
cve-2026-74615
This advisory addresses a Linux kernel issue in the VXLAN networking component, where the ageing timer is not disarmed on a device that is down. An attacker could potentially exploit this to cause improper resource management or network instability, though the advisory does not specify a severity rating. This could be relevant where VXLAN is deployed in automotive systems for in-vehicle or vehicle-to-infrastructure networking, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74616
This advisory addresses a vulnerability in the Linux kernel's XDP (eXpress Data Path) component, where cloned packets that overrun the skb_shared_info tailroom are rejected. An attacker could potentially exploit this flaw to cause a denial of service or other unspecified impacts, with the severity not explicitly stated in the provided text. This could be relevant where the Linux kernel is deployed in automotive systems, such as in vehicle infotainment or network processing units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74614
This advisory addresses a vulnerability in the Linux kernel's vsock/virtio component, which handles virtual socket communication in virtualized environments. An attacker could potentially exploit a race condition related to reading virtqueues under worker locks, leading to system instability or unauthorized access. The severity is not explicitly stated in the advisory. This could be relevant where vsock/virtio is deployed in automotive systems, such as in-vehicle virtualization or telematics platforms. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74613
This advisory addresses a vulnerability in the Linux kernel's vsock/virtio component, where the RX queue could be refilled after teardown, potentially leading to system instability or exploitation. The affected component is a generic Linux kernel feature, and its automotive relevance is inferred from possible deployment in embedded systems. This could be relevant where vsock/virtio is deployed in automotive systems, and an attacker could exploit this flaw to cause a denial of service or other technical impact, with severity not explicitly stated in the advisory. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74611
This advisory addresses a Linux kernel vulnerability in the TLS subsystem, specifically a bug in the receive path that fails to restore the message iterator before a TLS 1.3 optimistic retry, which could lead to incorrect data handling or a system crash. The severity is not explicitly stated in the provided text, but the flaw affects the kernel's TLS implementation, which is a core networking component. This could be relevant where Linux is deployed in automotive systems, such as for in-vehicle networking or telematics, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74612
This advisory addresses a fix in the Linux kernel for the veth network driver, specifically correcting packet length accounting after XDP fragment adjustments. An attacker could potentially exploit this flaw to cause incorrect packet handling, leading to network disruption or other unspecified technical impacts. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel with veth is deployed in automotive systems, such as in-vehicle networking or telematics. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74610
This advisory addresses a Linux kernel issue where a full plaintext sk_msg ring is not pushed in the TLS subsystem, which could allow an attacker to exploit the flaw. The technical impact involves potential data handling or security weaknesses in TLS operations, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74609
This advisory addresses a Linux kernel vulnerability in the TIPC networking module, specifically a missing lock protection when reading a link pointer in the tipc_node_link_down() function. An attacker could potentially exploit this race condition to cause a system crash or other undefined behavior. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel with TIPC is deployed in automotive systems, such as in-vehicle infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74607
The advisory addresses a vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) subsystem, specifically involving the SVM (Secure Virtual Machine) implementation where accesses to the owner and mirror list are serialized with a separate lock. An attacker could potentially exploit this issue to cause a security impact, though the advisory does not specify the exact technical consequences or severity rating. This could be relevant where Linux KVM is deployed in automotive systems, such as in virtualization for infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74608
This advisory addresses a use-after-free vulnerability in the Linux kernel's CIFS client, specifically in the function cifs_try_adding_channels(). An attacker could potentially exploit this flaw to cause memory corruption or a system crash. This could be relevant where the Linux CIFS client is deployed in automotive systems, such as for in-vehicle infotainment or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74606
This advisory addresses a use-after-free vulnerability in the eventfs component of the Linux kernel, where an attacker could potentially exploit the flaw to cause memory corruption or a system crash. The affected component is part of the Linux kernel, which is widely used in various systems, and this could be relevant where the Linux kernel is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74605
This advisory addresses a Linux kernel issue in the eventfs component, where the use of a children field for RCU head and missing memory barriers could lead to incorrect synchronization. An attacker could potentially exploit this to cause memory corruption or a system crash, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74602
cvelistv5medium
cve-2026-74601
This advisory addresses a vulnerability in the Linux kernel's ring-buffer implementation, specifically related to per-CPU buffer swapping. An attacker could potentially exploit this flaw to cause incorrect buffer handling, leading to system instability or unauthorized access. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74599
This advisory addresses a Linux kernel vulnerability in the mm/ptdump component, which is used for page table dumping. An attacker could potentially exploit this issue to cause instability or a denial of service by freeing page tables while they are being accessed. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74600
The advisory addresses a Linux kernel issue in the mm/page_table_check component, specifically skipping special zero mappings. An attacker could potentially exploit this flaw to bypass page table checks, leading to memory corruption or system instability. The severity is not explicitly stated in the provided text. This could be relevant where Linux is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74598
This advisory addresses a vulnerability in the Linux kernel's IPv6 implementation, specifically a flaw in validating the length of the Route Information option. An attacker could exploit this to cause a denial of service or other unspecified technical impact. This could be relevant where Linux-based IPv6 networking is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74597
This advisory addresses a vulnerability in the Linux kernel's ip6_tunnel component, specifically a failure to clear the skb2->cb[] data structure in the ip6ip6_err() function. An attacker could potentially exploit this flaw to cause incorrect handling of error packets in IPv6 tunnels, leading to system instability or a denial-of-service condition. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74595
This advisory addresses a Linux kernel vulnerability in the fscrypt file encryption component, specifically in the fscrypt_ioctl_set_policy() function, where the owner check uses the mount idmap. An attacker could potentially exploit this flaw to bypass ownership verification when setting encryption policies, leading to unauthorized access or manipulation of encrypted files. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel with fscrypt is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74596
cvelistv5medium
cve-2026-74594
This advisory addresses a Linux kernel vulnerability in the PSI (Pressure Stall Information) subsystem, specifically a failure to properly shut down the rtpoll_timer when a cgroup is freed, which could lead to a use-after-free condition. An attacker could potentially exploit this to cause a system crash or gain elevated privileges, though the advisory does not specify a severity rating. This could be relevant where Linux is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74593
cvelistv5medium
cve-2026-74591
cvelistv5medium
cve-2026-74592
This advisory describes a Linux kernel change that adds new security hooks for file truncation operations. An attacker could potentially exploit the lack of these hooks to bypass security controls that monitor or restrict file modification, though the advisory does not specify a severity rating or a direct automotive impact. This could be relevant where Linux is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm such use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium
cve-2026-74590