-

CVE-2026-80802

Medienbericht

nfc: fdp: bound the device-reported read length and fix an skb leak

In the Linux kernel, the following vulnerability has been resolved:

nfc: fdp: bound the device-reported read length and fix an skb leak

fdp_nci_i2c_read() takes the next packet length from two device-supplied
bytes and never validates it. The value is a u16 used as the
i2c_master_recv() count into a 261-byte on-stack buffer: a malicious,
counterfeit or malfunctioning controller (or an i2c bus interposer) can
drive it far past the buffer for a stack out-of-bounds write that
clobbers the canary and return address, or below the minimum frame size
(directly, or by truncating the computed sum) so the header/LRC strip
and the next length read run past a short receive. Reject a length
outside [FDP_NCI_I2C_MIN_PAYLOAD, FDP_NCI_I2C_MAX_PAYLOAD], as a
corrupted packet already is, and force resynchronization.

The same loop allocates one data skb per iteration and assumes a length
packet followed by a data packet; a device that sends two data packets
in one call leaks the first skb when the second allocation overwrites
it. Free a previously allocated skb before allocating the next.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version a06347c04c13e380afce0c9816df51f00b83faf1
Version < d9498ab9a78cb63d78dbe4f221d8cc6c91f285ee
Status affected
Version a06347c04c13e380afce0c9816df51f00b83faf1
Version < 1fc32327b927a6e2cde086f82575c29880844228
Status affected
Version a06347c04c13e380afce0c9816df51f00b83faf1
Version < 8d2c243b79854628ff076c38748c020042f02f57
Status affected
Version a06347c04c13e380afce0c9816df51f00b83faf1
Version < fc3c2bd5b1ec6c7cbc8a50e32d9bcec114f25463
Status affected
Version a06347c04c13e380afce0c9816df51f00b83faf1
Version < 0d723090645b82c1cb27cfd7ebf81f0e7c96bcae
Status affected
Version a06347c04c13e380afce0c9816df51f00b83faf1
Version < db7e464b350969c6ea8340de00d9796e5fd5123b
Status affected
Version a06347c04c13e380afce0c9816df51f00b83faf1
Version < e5eec121f2c3bc4c7022613bedd9121a8aa4c949
Status affected
Version a06347c04c13e380afce0c9816df51f00b83faf1
Version < 1aa3fc769b0c45bd19f8dab1697084c2b3f6d706
Status affected
Version a06347c04c13e380afce0c9816df51f00b83faf1
Version < 7ad21dcfeb5181af0c3ee2608808c0c0a5283aa1
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.4
Status affected
Version 0
Version < 4.4
Status unaffected
Version <= 5.10.*
Version 5.10.267
Status unaffected
Version <= 5.15.*
Version 5.15.218
Status unaffected
Version <= 6.1.*
Version 6.1.185
Status unaffected
Version <= 6.6.*
Version 6.6.154
Status unaffected
Version <= 6.12.*
Version 6.12.106
Status unaffected
Version <= 6.18.*
Version 6.18.47
Status unaffected
Version <= 7.1.*
Version 7.1.11
Status unaffected
Version <= 7.2.*
Version 7.2.1
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.093
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/d9498ab9a78cb63d78dbe4f221d8cc6c91f285ee
https://git.kernel.org/stable/c/1fc32327b927a6e2cde086f82575c29880844228
https://git.kernel.org/stable/c/8d2c243b79854628ff076c38748c020042f02f57
https://git.kernel.org/stable/c/fc3c2bd5b1ec6c7cbc8a50e32d9bcec114f25463
https://git.kernel.org/stable/c/0d723090645b82c1cb27cfd7ebf81f0e7c96bcae
https://git.kernel.org/stable/c/db7e464b350969c6ea8340de00d9796e5fd5123b
https://git.kernel.org/stable/c/e5eec121f2c3bc4c7022613bedd9121a8aa4c949
https://git.kernel.org/stable/c/1aa3fc769b0c45bd19f8dab1697084c2b3f6d706
https://git.kernel.org/stable/c/7ad21dcfeb5181af0c3ee2608808c0c0a5283aa1