Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
cvelistv5medium

cve-2026-74615

This advisory addresses a Linux kernel issue in the VXLAN networking component, where the ageing timer is not disarmed on a device that is down. An attacker could potentially exploit this to cause improper resource management or network instability, though the advisory does not specify a severity rating. This could be relevant where VXLAN is deployed in automotive systems for in-vehicle or vehicle-to-infrastructure networking, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74616

This advisory addresses a vulnerability in the Linux kernel's XDP (eXpress Data Path) component, where cloned packets that overrun the skb_shared_info tailroom are rejected. An attacker could potentially exploit this flaw to cause a denial of service or other unspecified impacts, with the severity not explicitly stated in the provided text. This could be relevant where the Linux kernel is deployed in automotive systems, such as in vehicle infotainment or network processing units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74614

This advisory addresses a vulnerability in the Linux kernel's vsock/virtio component, which handles virtual socket communication in virtualized environments. An attacker could potentially exploit a race condition related to reading virtqueues under worker locks, leading to system instability or unauthorized access. The severity is not explicitly stated in the advisory. This could be relevant where vsock/virtio is deployed in automotive systems, such as in-vehicle virtualization or telematics platforms. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74613

This advisory addresses a vulnerability in the Linux kernel's vsock/virtio component, where the RX queue could be refilled after teardown, potentially leading to system instability or exploitation. The affected component is a generic Linux kernel feature, and its automotive relevance is inferred from possible deployment in embedded systems. This could be relevant where vsock/virtio is deployed in automotive systems, and an attacker could exploit this flaw to cause a denial of service or other technical impact, with severity not explicitly stated in the advisory. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74611

This advisory addresses a Linux kernel vulnerability in the TLS subsystem, specifically a bug in the receive path that fails to restore the message iterator before a TLS 1.3 optimistic retry, which could lead to incorrect data handling or a system crash. The severity is not explicitly stated in the provided text, but the flaw affects the kernel's TLS implementation, which is a core networking component. This could be relevant where Linux is deployed in automotive systems, such as for in-vehicle networking or telematics, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74612

This advisory addresses a fix in the Linux kernel for the veth network driver, specifically correcting packet length accounting after XDP fragment adjustments. An attacker could potentially exploit this flaw to cause incorrect packet handling, leading to network disruption or other unspecified technical impacts. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel with veth is deployed in automotive systems, such as in-vehicle networking or telematics. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74610

This advisory addresses a Linux kernel issue where a full plaintext sk_msg ring is not pushed in the TLS subsystem, which could allow an attacker to exploit the flaw. The technical impact involves potential data handling or security weaknesses in TLS operations, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74609

This advisory addresses a Linux kernel vulnerability in the TIPC networking module, specifically a missing lock protection when reading a link pointer in the tipc_node_link_down() function. An attacker could potentially exploit this race condition to cause a system crash or other undefined behavior. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel with TIPC is deployed in automotive systems, such as in-vehicle infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74607

The advisory addresses a vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) subsystem, specifically involving the SVM (Secure Virtual Machine) implementation where accesses to the owner and mirror list are serialized with a separate lock. An attacker could potentially exploit this issue to cause a security impact, though the advisory does not specify the exact technical consequences or severity rating. This could be relevant where Linux KVM is deployed in automotive systems, such as in virtualization for infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74608

This advisory addresses a use-after-free vulnerability in the Linux kernel's CIFS client, specifically in the function cifs_try_adding_channels(). An attacker could potentially exploit this flaw to cause memory corruption or a system crash. This could be relevant where the Linux CIFS client is deployed in automotive systems, such as for in-vehicle infotainment or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74606

This advisory addresses a use-after-free vulnerability in the eventfs component of the Linux kernel, where an attacker could potentially exploit the flaw to cause memory corruption or a system crash. The affected component is part of the Linux kernel, which is widely used in various systems, and this could be relevant where the Linux kernel is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74605

This advisory addresses a Linux kernel issue in the eventfs component, where the use of a children field for RCU head and missing memory barriers could lead to incorrect synchronization. An attacker could potentially exploit this to cause memory corruption or a system crash, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74602

cvelistv5medium

cve-2026-74601

This advisory addresses a vulnerability in the Linux kernel's ring-buffer implementation, specifically related to per-CPU buffer swapping. An attacker could potentially exploit this flaw to cause incorrect buffer handling, leading to system instability or unauthorized access. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74599

This advisory addresses a Linux kernel vulnerability in the mm/ptdump component, which is used for page table dumping. An attacker could potentially exploit this issue to cause instability or a denial of service by freeing page tables while they are being accessed. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74600

The advisory addresses a Linux kernel issue in the mm/page_table_check component, specifically skipping special zero mappings. An attacker could potentially exploit this flaw to bypass page table checks, leading to memory corruption or system instability. The severity is not explicitly stated in the provided text. This could be relevant where Linux is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74598

This advisory addresses a vulnerability in the Linux kernel's IPv6 implementation, specifically a flaw in validating the length of the Route Information option. An attacker could exploit this to cause a denial of service or other unspecified technical impact. This could be relevant where Linux-based IPv6 networking is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74597

This advisory addresses a vulnerability in the Linux kernel's ip6_tunnel component, specifically a failure to clear the skb2->cb[] data structure in the ip6ip6_err() function. An attacker could potentially exploit this flaw to cause incorrect handling of error packets in IPv6 tunnels, leading to system instability or a denial-of-service condition. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74595

This advisory addresses a Linux kernel vulnerability in the fscrypt file encryption component, specifically in the fscrypt_ioctl_set_policy() function, where the owner check uses the mount idmap. An attacker could potentially exploit this flaw to bypass ownership verification when setting encryption policies, leading to unauthorized access or manipulation of encrypted files. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel with fscrypt is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74596

cvelistv5medium

cve-2026-74594

This advisory addresses a Linux kernel vulnerability in the PSI (Pressure Stall Information) subsystem, specifically a failure to properly shut down the rtpoll_timer when a cgroup is freed, which could lead to a use-after-free condition. An attacker could potentially exploit this to cause a system crash or gain elevated privileges, though the advisory does not specify a severity rating. This could be relevant where Linux is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74593

cvelistv5medium

cve-2026-74591

cvelistv5medium

cve-2026-74592

This advisory describes a Linux kernel change that adds new security hooks for file truncation operations. An attacker could potentially exploit the lack of these hooks to bypass security controls that monitor or restrict file modification, though the advisory does not specify a severity rating or a direct automotive impact. This could be relevant where Linux is deployed in automotive systems, such as in infotainment or control units, but the advisory does not confirm such use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74590