SB20260905121 - Out-of-bounds read in Linux kernel nfc st21nfca driver
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-80823)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose kernel memory or cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the st21nfca_tm_recv_atr_req() and st21nfca_tm_send_atr_res() ATR_REQ handling path when handling ATR_REQ frames whose declared length exceeds the received frame length. A remote attacker can send a short ATR_REQ frame with an oversized declared length to disclose kernel memory or cause a denial of service.
Exploitation requires an RF peer.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0f344944c506b4f02d2b098489f7268b438c369e
- https://git.kernel.org/stable/c/2c1ad291f4cdc357f9527b688c6fda9c6ffa7890
- https://git.kernel.org/stable/c/304f5b414f4051d324b8c4a3ab0e79f7dc7e150e
- https://git.kernel.org/stable/c/5cdcca5d62a66eda6b774110a44cba67bc1a8d1d
- https://git.kernel.org/stable/c/785df00bb3ae3206674a43284eb06dac575b5c64
- https://git.kernel.org/stable/c/9635507fe82949e429b3cd938876a9917125b151
- https://git.kernel.org/stable/c/bfcca5f42c9aa4eadef1e5fe7bb23783d7fcc96d
- https://git.kernel.org/stable/c/dd26d30f40c43ad9cfe2f25c6ea0ead1dd51d5aa
- https://git.kernel.org/stable/c/f33cecf69095c43be88567fef92b180b858f7369