[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84204-en":3,"doc-seo-84204-105":30,"detail-sidebar-cat-0-en-105":84},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84204,962075114765,"Quinn","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Monitoring Vulnerabilities in Next-Generation Automotive Operating Systems","Software-defined vehicles (SDVs) integrate complex interconnected hardware and software, creating major security challenges centered on software vulnerabilities. Existing vulnerability assessment tools are insufficient for operating system weaknesses and for efficiently analyzing diverse software stacks in realistic environments. The work presents a released, dockerized vulnerability assessment approach that combines systematic vulnerability discovery using public CVE databases and exploitability-risk evaluation. Results quantify threat breadth and highlight practical constraints, informing directions to build more resilient SDVs.","Monitoring Vulnerabilities in Next-Generation Automotive Operating Systems  \nDimitri Simon∗ , Badis Hammi∗ , Joaquin Garcia-Alfaro∗ , Herv Debar∗  \n∗ SAMOVAR, Tlcom SudParis, Institut Polytechnique de Paris, 91120 Palaiseau, France [dimitri.simon@telecom-sudparis.eu](dimitri.simon@telecom-sudparis.eu) ; [badis.hammi@telecom-sudparis.eu](badis.hammi@telecom-sudparis.eu)[ ](badis.hammi@telecom-sudparis.eu)joaquin.garcia [alfaro@telecom-sudparis.eu](alfaro@telecom-sudparis.eu) ; [herve.debar@telecom-sudparis.eu](herve.debar@telecom-sudparis.eu)  \narXiv :2607 .07226v 1 [ cs .CR] 8 Jul 2026  \nAbstract—Software-defined vehicles (SDVs) are revolutionizing transportation by integrating complex, interconnected hardware, and software systems. This evolution introduces significant security challenges. We present a comprehensive security analysis for SDVs, focusing on software vulnerabilities. We note that existing vulnerability assessment tools fall short in addressing operating systems vulnerabilities, particularly when it comes to efficiently analyzing diverse software stacks in realistic environments. We present and release a vulnerability assessment solution that efficiently addresses these limitations. Our approach combines systematic vulnerability discovery, leveraging public Common Vulnerabilities and Exposures (CVE) databases, within a dockerized development environment that evaluates exploitability risks. The results reveal both breadth of potential threats and the practical constraints we faced during exploitation. We discuss the implications for industry and research, and propose directions for building more resilient SDVs.1  \nIndex Terms—Software-Defined Vehicle (SDV), Vulnerability Scanner, Cybersecurity, Pentesting, Common Vulnerabilities and Exposures (CVE).  \nI. INTRODUCTION  \nThe automotive industry is undergoing a radical transformation across both hardware and software domains. Architecturally, manufacturers are migrating from distributed legacy Electronic Control Units (ECU) toward zonal Electrical/Electronic (E/E) topologies and consolidated high-performance computers (HPCs) to accommodate the vastly increased data volumes generated by advanced sensors (e.g., cameras, radar, LiDAR, and so on) and domain controllers. Concurrently, the software landscape is shifting from proprietary, monolithic firmware toward the Software-Defined Vehicle (SDV)2 paradigm, where vehicles are increasingly built on open, Portable Operating System Interface (POSIX)-compatible platforms that support virtualization, containerization, and OverThe-Air (OTA) updates and software delivery, supplanting isolated vendor-specific stacks. This transition toward POSIXcompatible platforms has been driven by initiatives such as  \n1The VERA source code, along with the associated proof-of-concepts (PoCs) and exploit implementations, is publicly available in a dedicated repository at: [https://github.com/EternalDreamer01/vera](https://github.com/EternalDreamer01/vera)  \n2A Software-Defined Vehicle (SDV) is a vehicle in which the majority of functionality is implemented, managed, and continuously enhanced through software, allowing features to evolve independently of fixed hardware. In SDVs, software spans the entire vehicle ecosystem, from infotainment and connectivity to safety-critical and autonomous driving functions, enabling scalability, rapid feature deployment, and lifecycle updates.  \nFig. 1: Hardware-software stack within next-generation SDVs  \nAutomotive Grade Linux (AGL),3 Android Automotive OS (AAOS),4 and Red Hat In-Vehicle OS (RHIVOS) .5  \nThis convergence accelerates feature deployment and interoperability. more precisely, the adoption of POSIX-compliant architectures further enables portability across hardware platforms, simplifies integration of third-party software, facilitates reuse of open-source components, and streamlines development through standardised Application Programming Interfaces (APIs) and tooling. However, these advances al","cbCainCMyEcqcUqe","https://ap.wps.com/l/cbCainCMyEcqcUqe","pdf",2082472,5,1,19,"English","en",105,"# Introduction\n## Context and research questions","[{\"question\":\"How does the proposed solution evaluate vulnerabilities and exploitability risk?\",\"answer\":\"It performs systematic vulnerability discovery leveraging public Common Vulnerabilities and Exposures (CVE) databases inside a dockerized development environment, then evaluates exploitability risk based on that setup.\"}]",1784193924,48,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":79,"head_meta":81,"extra_data":83,"updated_unix":28},"monitoring-vulnerabilities-in-next-generation-automotive-operating-systems","",{"@graph":36,"@context":78},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/monitoring-vulnerabilities-in-next-generation-automotive-operating-systems/84204/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72],{"name":73,"@type":74,"acceptedAnswer":75},"How does the proposed solution evaluate vulnerabilities and exploitability risk?","Question",{"text":76,"@type":77},"It performs systematic vulnerability discovery leveraging public Common Vulnerabilities and Exposures (CVE) databases inside a dockerized development environment, then evaluates exploitability risk based on that setup.","Answer","https://schema.org",{"og:url":52,"og:type":80,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":82,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":85},[86,90,94,98,102,107,112,115,120,123,127],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":87,"show_sort_weight":88,"slug":89},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":91,"show_sort_weight":92,"slug":93},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Comic",60,"comic",{"id":103,"doc_module":4,"doc_module_name":46,"category_name":104,"show_sort_weight":105,"slug":106},6,"Technology",50,"technology",{"id":108,"doc_module":4,"doc_module_name":46,"category_name":109,"show_sort_weight":110,"slug":111},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":113,"slug":114},30,"research-report",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},9,"Religion & Spirituality",20,"religion-spirituality",{"id":118,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":118,"slug":122},"World Cup","world-cup",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":124,"slug":126},10,"Lifestyle","lifestyle",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":20,"slug":129},"General","general"]