Out-of-bounds read in Linux kernel - CVE-2026-80798
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to read memory out of bounds.
The vulnerability exists due to insufficient length validation in the LLCP receive path when processing an LLCP PDU shorter than the LLCP header. A remote attacker can send a crafted undersized LLCP PDU to read memory out of bounds.
LLCP link activation occurs automatically after NFC-DEP.
Affected software
How to mitigate CVE-2026-80798
External References
- https://git.kernel.org/stable/c/3793d768b40f38bb97265dd5b9a8b8655c4e1b1d
- https://git.kernel.org/stable/c/95674f506c6376d6722a23144c9acd26609771ed
- https://git.kernel.org/stable/c/a7b9b449f5a5132221fff6adc11a9431ab8cd914
- https://git.kernel.org/stable/c/ae5f20f5842f440b72d030e3a34fe182dd8eae42
- https://git.kernel.org/stable/c/d3d90243393c48146911c67fd3792b549d21d9e6
- https://git.kernel.org/stable/c/e6ec76a68dce04884dfeccfe5a5f0e9f67c0ec82
- https://git.kernel.org/stable/c/e969e98410051b1ef8cc318bfe0c7e3f24ec766d
- https://git.kernel.org/stable/c/eab47618e282602197db287ecbd1b09d356a2515
- https://git.kernel.org/stable/c/f36cffea24bf3e2cc29a00d4b51dbcadc087d810