Out-of-bounds write in Linux kernel - CVE-2026-80795
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause a slab out-of-bounds write.
The vulnerability exists due to a missing bounds check in nci_target_auto_activated() when processing RF_INTF_ACTIVATED_NTF notifications after repeated discovery cycles. A local user can trigger repeated NFC discovery cycles with auto-activated targets to cause a slab out-of-bounds write.
The target list remains populated when RF_DISCOVER_RSP re-enters NCI_DISCOVERY.
Affected software
How to mitigate CVE-2026-80795
External References
- https://git.kernel.org/stable/c/0dc59de0075f88404a0f4a2b5233104ef459fbb2
- https://git.kernel.org/stable/c/129032c0616d83a5e3e304f6ebf88f14ba01e5f7
- https://git.kernel.org/stable/c/24761d3a5f692df5f7d848caeabcb2afd10917aa
- https://git.kernel.org/stable/c/2f08dbce3b37624ec6b424d759336a99586170ec
- https://git.kernel.org/stable/c/50e87e1c0e18d791dcd7dccf30f9a2f3e2cf3951
- https://git.kernel.org/stable/c/94530ffabfca57e9bff1d207106010014cc84032
- https://git.kernel.org/stable/c/ac200079db50af81e6b04d058b33ec92901d8edd
- https://git.kernel.org/stable/c/afd8605fb43becb892311102844955c3b127fc7e
- https://git.kernel.org/stable/c/d7083f41c21b30582e91b2e6de4d54dce74f6f9c