SB20260905163 - Use of Uninitialized Variable in Linux kernel nfc nci



SB20260905163 - Use of Uninitialized Variable in Linux kernel nfc nci

Published: September 5, 2026

Security Bulletin ID SB20260905163
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Use of Uninitialized Variable (CVE-ID: CVE-2026-80794)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to use of uninitialized stack memory in the RF discover and RF interface activated notification handlers when processing notifications with zero-length RF technology-specific parameters. A remote attacker can cause the kernel to process a notification reporting zero-length RF technology-specific parameters to disclose sensitive information.

The copied target data is exposed to user space through NFC_CMD_GET_TARGET.


Remediation

Install update from vendor's website.