-

CVE-2026-80794

Medienbericht

nfc: nci: fix uninit-value in the RF discover/activated NTF handlers

In the Linux kernel, the following vulnerability has been resolved:

nfc: nci: fix uninit-value in the RF discover/activated NTF handlers

nci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each
parse a notification into an on-stack struct (nci_rf_discover_ntf /
nci_rf_intf_activated_ntf) that is not initialised. The RF
technology-specific parameters are only extracted when
rf_tech_specific_params_len is non-zero, so a notification that reports a
zero length leaves the rf_tech_specific_params union uninitialised - and
both handlers then pass it to nci_add_new_protocol(), which reads it:

 - discover:  nci_add_new_target() -> nci_add_new_protocol();
 - activated: nci_target_auto_activated() -> nci_add_new_protocol().

nci_add_new_protocol() uses nfca_poll->nfcid1_len as both a branch
condition and a memcpy() length and copies nfcid1/sens_res/sel_res into
ndev->targets, which is later exposed to user space via NFC_CMD_GET_TARGET.

  BUG: KMSAN: uninit-value in nci_add_new_protocol+0x624/0x6c0
   nci_add_new_protocol+0x624/0x6c0
   nci_ntf_packet+0x25b2/0x3c30
   nci_rx_work+0x318/0x5d0
   process_scheduled_works+0x84b/0x17a0
   worker_thread+0xc10/0x11b0
   kthread+0x376/0x500
  Local variable ntf.i created at:
   nci_ntf_packet+0xbc2/0x3c30

Zero-initialise both on-stack notifications so the union reads back as
zero when no technology-specific parameters are present.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20
Version < 1007a6b429d756513abd25bd00290908f2e89a4a
Status affected
Version e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20
Version < 4bda9ef8392710f21e99027467f3f4afdfb5c99a
Status affected
Version e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20
Version < fe69fed3495f676578d49414a069ad7d8468e2ce
Status affected
Version e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20
Version < 7489f59d1ea2d3298aa41de7baf193e5e6e132f6
Status affected
Version e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20
Version < 7086dab72b3ed95df96842801e10e935cfeb27a3
Status affected
Version e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20
Version < 0d4b5cfab6891a5ca0f6aef209beebba4bd7c095
Status affected
Version e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20
Version < 5bd00c0e1470d90d77a7c60242854257ddf14e00
Status affected
Version e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20
Version < d6f743d3d388913135681cde051c08823730194f
Status affected
Version e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20
Version < 8cbe06c1e699c0a165dae5093a2550e65f914818
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.3
Status affected
Version 0
Version < 3.3
Status unaffected
Version <= 5.10.*
Version 5.10.269
Status unaffected
Version <= 5.15.*
Version 5.15.218
Status unaffected
Version <= 6.1.*
Version 6.1.185
Status unaffected
Version <= 6.6.*
Version 6.6.154
Status unaffected
Version <= 6.12.*
Version 6.12.106
Status unaffected
Version <= 6.18.*
Version 6.18.47
Status unaffected
Version <= 7.1.*
Version 7.1.11
Status unaffected
Version <= 7.2.*
Version 7.2.1
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.093
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/1007a6b429d756513abd25bd00290908f2e89a4a
https://git.kernel.org/stable/c/4bda9ef8392710f21e99027467f3f4afdfb5c99a
https://git.kernel.org/stable/c/fe69fed3495f676578d49414a069ad7d8468e2ce
https://git.kernel.org/stable/c/7489f59d1ea2d3298aa41de7baf193e5e6e132f6
https://git.kernel.org/stable/c/7086dab72b3ed95df96842801e10e935cfeb27a3
https://git.kernel.org/stable/c/0d4b5cfab6891a5ca0f6aef209beebba4bd7c095
https://git.kernel.org/stable/c/5bd00c0e1470d90d77a7c60242854257ddf14e00
https://git.kernel.org/stable/c/d6f743d3d388913135681cde051c08823730194f
https://git.kernel.org/stable/c/8cbe06c1e699c0a165dae5093a2550e65f914818