-

CVE-2026-80823

Medienbericht

nfc: st21nfca: validate ATR_REQ length against the received frame

In the Linux kernel, the following vulnerability has been resolved:

nfc: st21nfca: validate ATR_REQ length against the received frame

st21nfca_tm_recv_atr_req() checks that the received ATR_REQ frame is at
least ST21NFCA_ATR_REQ_MIN_SIZE and that the self-declared atr_req->length
is at least sizeof(struct st21nfca_atr_req), but never checks that
atr_req->length does not exceed the actual received length (skb->len).

st21nfca_tm_send_atr_res() then trusts the declared length:

	gb_len = atr_req->length - sizeof(struct st21nfca_atr_req);
	...
	memcpy(atr_res->gbi, atr_req->gbi, gb_len);

so an RF peer that sends a short frame but sets atr_req->length larger
than the frame makes gb_len exceed the general bytes actually present,
and the memcpy reads out of bounds past the received skb. Those bytes are
placed in the ATR_RES and sent back to the peer (kernel-memory disclosure
to a proximity attacker); a larger declared length is an out-of-bounds
read (DoS).

Reject frames whose declared length exceeds the received length. The
adjacent nfc_tm_activated() path in the same function already derives its
general-bytes length from skb->len rather than the declared field.

Found by 0sec (https://0sec.ai) using automated source analysis; the
missing bound is evident from source. Compile-tested.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1892bf844ea0261736bd5e75546fc996e9daeedf
Version < 785df00bb3ae3206674a43284eb06dac575b5c64
Status affected
Version 1892bf844ea0261736bd5e75546fc996e9daeedf
Version < 2c1ad291f4cdc357f9527b688c6fda9c6ffa7890
Status affected
Version 1892bf844ea0261736bd5e75546fc996e9daeedf
Version < dd26d30f40c43ad9cfe2f25c6ea0ead1dd51d5aa
Status affected
Version 1892bf844ea0261736bd5e75546fc996e9daeedf
Version < 9635507fe82949e429b3cd938876a9917125b151
Status affected
Version 1892bf844ea0261736bd5e75546fc996e9daeedf
Version < 0f344944c506b4f02d2b098489f7268b438c369e
Status affected
Version 1892bf844ea0261736bd5e75546fc996e9daeedf
Version < bfcca5f42c9aa4eadef1e5fe7bb23783d7fcc96d
Status affected
Version 1892bf844ea0261736bd5e75546fc996e9daeedf
Version < 304f5b414f4051d324b8c4a3ab0e79f7dc7e150e
Status affected
Version 1892bf844ea0261736bd5e75546fc996e9daeedf
Version < f33cecf69095c43be88567fef92b180b858f7369
Status affected
Version 1892bf844ea0261736bd5e75546fc996e9daeedf
Version < 5cdcca5d62a66eda6b774110a44cba67bc1a8d1d
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.17
Status affected
Version 0
Version < 3.17
Status unaffected
Version <= 5.10.*
Version 5.10.267
Status unaffected
Version <= 5.15.*
Version 5.15.218
Status unaffected
Version <= 6.1.*
Version 6.1.185
Status unaffected
Version <= 6.6.*
Version 6.6.154
Status unaffected
Version <= 6.12.*
Version 6.12.106
Status unaffected
Version <= 6.18.*
Version 6.18.47
Status unaffected
Version <= 7.1.*
Version 7.1.11
Status unaffected
Version <= 7.2.*
Version 7.2.1
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.093
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/785df00bb3ae3206674a43284eb06dac575b5c64
https://git.kernel.org/stable/c/2c1ad291f4cdc357f9527b688c6fda9c6ffa7890
https://git.kernel.org/stable/c/dd26d30f40c43ad9cfe2f25c6ea0ead1dd51d5aa
https://git.kernel.org/stable/c/9635507fe82949e429b3cd938876a9917125b151
https://git.kernel.org/stable/c/0f344944c506b4f02d2b098489f7268b438c369e
https://git.kernel.org/stable/c/bfcca5f42c9aa4eadef1e5fe7bb23783d7fcc96d
https://git.kernel.org/stable/c/304f5b414f4051d324b8c4a3ab0e79f7dc7e150e
https://git.kernel.org/stable/c/f33cecf69095c43be88567fef92b180b858f7369
https://git.kernel.org/stable/c/5cdcca5d62a66eda6b774110a44cba67bc1a8d1d