Out-of-bounds read in Linux kernel - CVE-2026-80799
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to read out-of-bounds memory or cause a denial of service.
The vulnerability exists due to improper bounds checking and integer wraparound in the nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() functions when processing remote LLCP general bytes. A remote attacker can send malformed TLV data to trigger out-of-bounds reads or infinite parsing loops.
Affected software
How to mitigate CVE-2026-80799
External References
- https://git.kernel.org/stable/c/2c1456fe09ab1a5a9fe1d8339ca6d509589b56e1
- https://git.kernel.org/stable/c/2d239590d1845a706304833d40dd6d4fec20ad88
- https://git.kernel.org/stable/c/382eaa770335acf4f16a5a55524500f2bb4207df
- https://git.kernel.org/stable/c/78b20c8eeacd2e44a2d8a4cb5316d3c521d90911
- https://git.kernel.org/stable/c/7f6f3d087c67a4346189ef2c36481455bbc59a74
- https://git.kernel.org/stable/c/875285a165fd3b402de2ab3be0deb355d6f4caf5
- https://git.kernel.org/stable/c/9c47d667963542c3cf8e3007b7f10c0904d08238
- https://git.kernel.org/stable/c/a209334ed929941b20810c17c3a507445b0a7c85
- https://git.kernel.org/stable/c/e84cdfdc4a6c88e8b751144458f2e04e24415a28