The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on behalf of root user (due to additional vulnerabilities), then he/she is also able to load custom kernel modules to the kernel space and execute code in the kernel context. Such a flaw can lead to taking control over the entire system. First identified on Nissan Leaf ZE1 manufactured in 2020.
History

Tue, 17 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 16 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Bosch
Bosch infotainment System Ecu
Vendors & Products Bosch
Bosch infotainment System Ecu

Sun, 15 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
Description The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on behalf of root user (due to additional vulnerabilities), then he/she is also able to load custom kernel modules to the kernel space and execute code in the kernel context. Such a flaw can lead to taking control over the entire system. First identified on Nissan Leaf ZE1 manufactured in 2020.
Title Absence of Kernel Module Signature Verification on Linux System of Infotainment ECU
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASRG

Published: 2026-02-15T10:46:23.570Z

Updated: 2026-02-17T20:07:40.053Z

Reserved: 2025-04-03T15:32:43.282Z

Link: CVE-2025-32060

cve-icon Vulnrichment

Updated: 2026-02-17T20:07:36.981Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-15T11:15:54.023

Modified: 2026-02-18T17:52:22.253

Link: CVE-2025-32060

cve-icon Redhat

No data.