Out-of-bounds read in Linux kernel - CVE-2026-80823
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose kernel memory or cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the st21nfca_tm_recv_atr_req() and st21nfca_tm_send_atr_res() ATR_REQ handling path when handling ATR_REQ frames whose declared length exceeds the received frame length. A remote attacker can send a short ATR_REQ frame with an oversized declared length to disclose kernel memory or cause a denial of service.
Exploitation requires an RF peer.
Affected software
How to mitigate CVE-2026-80823
External References
- https://git.kernel.org/stable/c/0f344944c506b4f02d2b098489f7268b438c369e
- https://git.kernel.org/stable/c/2c1ad291f4cdc357f9527b688c6fda9c6ffa7890
- https://git.kernel.org/stable/c/304f5b414f4051d324b8c4a3ab0e79f7dc7e150e
- https://git.kernel.org/stable/c/5cdcca5d62a66eda6b774110a44cba67bc1a8d1d
- https://git.kernel.org/stable/c/785df00bb3ae3206674a43284eb06dac575b5c64
- https://git.kernel.org/stable/c/9635507fe82949e429b3cd938876a9917125b151
- https://git.kernel.org/stable/c/bfcca5f42c9aa4eadef1e5fe7bb23783d7fcc96d
- https://git.kernel.org/stable/c/dd26d30f40c43ad9cfe2f25c6ea0ead1dd51d5aa
- https://git.kernel.org/stable/c/f33cecf69095c43be88567fef92b180b858f7369