Use of Uninitialized Variable in Linux kernel - CVE-2026-80794
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of uninitialized stack memory in the RF discover and RF interface activated notification handlers when processing notifications with zero-length RF technology-specific parameters. A remote attacker can cause the kernel to process a notification reporting zero-length RF technology-specific parameters to disclose sensitive information.
The copied target data is exposed to user space through NFC_CMD_GET_TARGET.
Affected software
How to mitigate CVE-2026-80794
External References
- https://git.kernel.org/stable/c/0d4b5cfab6891a5ca0f6aef209beebba4bd7c095
- https://git.kernel.org/stable/c/1007a6b429d756513abd25bd00290908f2e89a4a
- https://git.kernel.org/stable/c/4bda9ef8392710f21e99027467f3f4afdfb5c99a
- https://git.kernel.org/stable/c/5bd00c0e1470d90d77a7c60242854257ddf14e00
- https://git.kernel.org/stable/c/7086dab72b3ed95df96842801e10e935cfeb27a3
- https://git.kernel.org/stable/c/7489f59d1ea2d3298aa41de7baf193e5e6e132f6
- https://git.kernel.org/stable/c/8cbe06c1e699c0a165dae5093a2550e65f914818
- https://git.kernel.org/stable/c/d6f743d3d388913135681cde051c08823730194f
- https://git.kernel.org/stable/c/fe69fed3495f676578d49414a069ad7d8468e2ce