SB20260905153 - Memory leak in Linux kernel nfc pn533 driver
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Memory leak (CVE-ID: CVE-2026-80797)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to leak memory.
The vulnerability exists due to improper cleanup of queued fragment skbs in pn53x_common_clean() when a device is removed while transmit fragments are queued. An attacker with physical access can remove a device while transmit fragments are queued to leak memory.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/130b5ad4492f8e53d0398ee3af2b0e2388504d11
- https://git.kernel.org/stable/c/2f5d093194ec24d7c29b91bf7df014924e0f4ea1
- https://git.kernel.org/stable/c/4a52ec2457ff8c26206fcc20fa1972cc35a678c4
- https://git.kernel.org/stable/c/5718fc62198c38c2de5316020a90506f9e75e0bb
- https://git.kernel.org/stable/c/9319c3c4962efc8697246b563ea31c6d47f085aa
- https://git.kernel.org/stable/c/d63e85c5d5555fe6aa65155d3a09452597e163c3
- https://git.kernel.org/stable/c/e169277281373818ae1cedf976aa1e99118fb77d
- https://git.kernel.org/stable/c/e7ed2ea5590fbe2d3be39ee4fb0c758a12e31d0c
- https://git.kernel.org/stable/c/e95beff58b38c871c557bf84e528408283c2c0ad