Use of Uninitialized Variable in Linux kernel - CVE-2026-80794

 

Use of Uninitialized Variable in Linux kernel - CVE-2026-80794

Published: September 5, 2026


Vulnerability identifier: #VU147132
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80794
CWE-ID: CWE-457
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to use of uninitialized stack memory in the RF discover and RF interface activated notification handlers when processing notifications with zero-length RF technology-specific parameters. A remote attacker can cause the kernel to process a notification reporting zero-length RF technology-specific parameters to disclose sensitive information.

The copied target data is exposed to user space through NFC_CMD_GET_TARGET.


Affected software

Linux kernel

How to mitigate CVE-2026-80794

Install security update from vendor's repository.


External References

Related Security Bulletins