SB20260905154 - Out-of-bounds read in Linux kernel nfc



SB20260905154 - Out-of-bounds read in Linux kernel nfc

Published: September 5, 2026

Security Bulletin ID SB20260905154
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Out-of-bounds read (CVE-ID: CVE-2026-80798)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read memory out of bounds.

The vulnerability exists due to insufficient length validation in the LLCP receive path when processing an LLCP PDU shorter than the LLCP header. A remote attacker can send a crafted undersized LLCP PDU to read memory out of bounds.

LLCP link activation occurs automatically after NFC-DEP.


Remediation

Install update from vendor's website.