SB20260905163 - Use of Uninitialized Variable in Linux kernel nfc nci
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of Uninitialized Variable (CVE-ID: CVE-2026-80794)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of uninitialized stack memory in the RF discover and RF interface activated notification handlers when processing notifications with zero-length RF technology-specific parameters. A remote attacker can cause the kernel to process a notification reporting zero-length RF technology-specific parameters to disclose sensitive information.
The copied target data is exposed to user space through NFC_CMD_GET_TARGET.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0d4b5cfab6891a5ca0f6aef209beebba4bd7c095
- https://git.kernel.org/stable/c/1007a6b429d756513abd25bd00290908f2e89a4a
- https://git.kernel.org/stable/c/4bda9ef8392710f21e99027467f3f4afdfb5c99a
- https://git.kernel.org/stable/c/5bd00c0e1470d90d77a7c60242854257ddf14e00
- https://git.kernel.org/stable/c/7086dab72b3ed95df96842801e10e935cfeb27a3
- https://git.kernel.org/stable/c/7489f59d1ea2d3298aa41de7baf193e5e6e132f6
- https://git.kernel.org/stable/c/8cbe06c1e699c0a165dae5093a2550e65f914818
- https://git.kernel.org/stable/c/d6f743d3d388913135681cde051c08823730194f
- https://git.kernel.org/stable/c/fe69fed3495f676578d49414a069ad7d8468e2ce