Out-of-bounds read in Linux kernel - CVE-2026-80798

 

Out-of-bounds read in Linux kernel - CVE-2026-80798

Published: September 5, 2026


Vulnerability identifier: #VU147123
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80798
CWE-ID: CWE-125
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to read memory out of bounds.

The vulnerability exists due to insufficient length validation in the LLCP receive path when processing an LLCP PDU shorter than the LLCP header. A remote attacker can send a crafted undersized LLCP PDU to read memory out of bounds.

LLCP link activation occurs automatically after NFC-DEP.


Affected software

Linux kernel

How to mitigate CVE-2026-80798

Install security update from vendor's repository.


External References

Related Security Bulletins