SB20260905151 - Out-of-bounds write in Linux kernel nfc nci
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-80795)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a slab out-of-bounds write.
The vulnerability exists due to a missing bounds check in nci_target_auto_activated() when processing RF_INTF_ACTIVATED_NTF notifications after repeated discovery cycles. A local user can trigger repeated NFC discovery cycles with auto-activated targets to cause a slab out-of-bounds write.
The target list remains populated when RF_DISCOVER_RSP re-enters NCI_DISCOVERY.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0dc59de0075f88404a0f4a2b5233104ef459fbb2
- https://git.kernel.org/stable/c/129032c0616d83a5e3e304f6ebf88f14ba01e5f7
- https://git.kernel.org/stable/c/24761d3a5f692df5f7d848caeabcb2afd10917aa
- https://git.kernel.org/stable/c/2f08dbce3b37624ec6b424d759336a99586170ec
- https://git.kernel.org/stable/c/50e87e1c0e18d791dcd7dccf30f9a2f3e2cf3951
- https://git.kernel.org/stable/c/94530ffabfca57e9bff1d207106010014cc84032
- https://git.kernel.org/stable/c/ac200079db50af81e6b04d058b33ec92901d8edd
- https://git.kernel.org/stable/c/afd8605fb43becb892311102844955c3b127fc7e
- https://git.kernel.org/stable/c/d7083f41c21b30582e91b2e6de4d54dce74f6f9c