SB20260905154 - Out-of-bounds read in Linux kernel nfc
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-80798)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read memory out of bounds.
The vulnerability exists due to insufficient length validation in the LLCP receive path when processing an LLCP PDU shorter than the LLCP header. A remote attacker can send a crafted undersized LLCP PDU to read memory out of bounds.
LLCP link activation occurs automatically after NFC-DEP.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3793d768b40f38bb97265dd5b9a8b8655c4e1b1d
- https://git.kernel.org/stable/c/95674f506c6376d6722a23144c9acd26609771ed
- https://git.kernel.org/stable/c/a7b9b449f5a5132221fff6adc11a9431ab8cd914
- https://git.kernel.org/stable/c/ae5f20f5842f440b72d030e3a34fe182dd8eae42
- https://git.kernel.org/stable/c/d3d90243393c48146911c67fd3792b549d21d9e6
- https://git.kernel.org/stable/c/e6ec76a68dce04884dfeccfe5a5f0e9f67c0ec82
- https://git.kernel.org/stable/c/e969e98410051b1ef8cc318bfe0c7e3f24ec766d
- https://git.kernel.org/stable/c/eab47618e282602197db287ecbd1b09d356a2515
- https://git.kernel.org/stable/c/f36cffea24bf3e2cc29a00d4b51dbcadc087d810