SB20260905156 - Out-of-bounds read in Linux kernel nfc
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-80800)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read out-of-bounds memory.
The vulnerability exists due to an out-of-bounds read in nfc_llcp_connect_sn() when processing received CONNECT and CC PDUs. A remote attacker can send a malformed NFC LLCP PDU to read out-of-bounds memory.
LLCP link activation occurs automatically after NFC-DEP.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0cfbdb0e13ab5b0765d77f96af67eb879cbc9736
- https://git.kernel.org/stable/c/1964addc8dd535a05d5d3b55b4d1ac19ae31aa65
- https://git.kernel.org/stable/c/22e5177ba1196a0b272a6a46c2575eb940a939c4
- https://git.kernel.org/stable/c/389986fd79e4d43f971a03b512645a1bb63c982f
- https://git.kernel.org/stable/c/55c68ac93e7dacc0f5f608b9c39dd4ff48cf28e8
- https://git.kernel.org/stable/c/65a0ec7783b06068dda6745dd689bf4a91ee64aa
- https://git.kernel.org/stable/c/b2ebdfe3d5b76e91f267a61cbc3f9a0e3f77071e
- https://git.kernel.org/stable/c/e18d044bab6d3d0280639098c3fe6621692cbfe2
- https://git.kernel.org/stable/c/e87527b506c40db9af528714b7b1240918eb80fc