Out-of-bounds read in Linux kernel - CVE-2026-80800
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to read out-of-bounds memory.
The vulnerability exists due to an out-of-bounds read in nfc_llcp_connect_sn() when processing received CONNECT and CC PDUs. A remote attacker can send a malformed NFC LLCP PDU to read out-of-bounds memory.
LLCP link activation occurs automatically after NFC-DEP.
Affected software
How to mitigate CVE-2026-80800
External References
- https://git.kernel.org/stable/c/0cfbdb0e13ab5b0765d77f96af67eb879cbc9736
- https://git.kernel.org/stable/c/1964addc8dd535a05d5d3b55b4d1ac19ae31aa65
- https://git.kernel.org/stable/c/22e5177ba1196a0b272a6a46c2575eb940a939c4
- https://git.kernel.org/stable/c/389986fd79e4d43f971a03b512645a1bb63c982f
- https://git.kernel.org/stable/c/55c68ac93e7dacc0f5f608b9c39dd4ff48cf28e8
- https://git.kernel.org/stable/c/65a0ec7783b06068dda6745dd689bf4a91ee64aa
- https://git.kernel.org/stable/c/b2ebdfe3d5b76e91f267a61cbc3f9a0e3f77071e
- https://git.kernel.org/stable/c/e18d044bab6d3d0280639098c3fe6621692cbfe2
- https://git.kernel.org/stable/c/e87527b506c40db9af528714b7b1240918eb80fc