Out-of-bounds read in Linux kernel - CVE-2026-80801
Published: September 5, 2026
Vulnerability identifier: #VU147126
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80801
CWE-ID: CWE-125
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to read out-of-bounds memory.
The vulnerability exists due to an out-of-bounds read in microread_target_discovered() when processing malformed NFC target discovery payloads. A remote attacker can send a malformed target discovery payload to read out-of-bounds memory.
Affected software
Linux kernel
How to mitigate CVE-2026-80801
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/18f02354ed229b8e4561b580812d026e7eb29c85
- https://git.kernel.org/stable/c/25519469972ef57c3edb1805dabd6c5612b90211
- https://git.kernel.org/stable/c/92a6f0201bb68391b5eba1b3f330af007d7323b6
- https://git.kernel.org/stable/c/953963b9ac5eecbb316617d337bfaa3d731e3c5e
- https://git.kernel.org/stable/c/c6de4241f2efbbab286efbb84a9c7190298b3052
- https://git.kernel.org/stable/c/cb298672282421159e53ab311fe49d204c8a52da
- https://git.kernel.org/stable/c/d0902a7c454326c6384c614226ab8987f3fd425d
- https://git.kernel.org/stable/c/dabfa26a208e56f4d8dbf26fddc48f188bdb0649
- https://git.kernel.org/stable/c/e6397fe7b8b5ef18e051f49612d40ff476c5f7d9