- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:13:17
- Zuletzt bearbeitet 04.09.2026 16:18:07
In the Linux kernel, the following vulnerability has been resolved: nfc: digital: clamp SENSF_RES length to the destination buffer digital_in_recv_sensf_res() memcpy()s resp->len bytes from a remote NFC-F device response into the NFC_SENSF_RES_MAXS...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:13:16
- Zuletzt bearbeitet 04.09.2026 16:18:07
In the Linux kernel, the following vulnerability has been resolved: nfc: fdp: bound the device-reported read length and fix an skb leak fdp_nci_i2c_read() takes the next packet length from two device-supplied bytes and never validates it. The value...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:13:15
- Zuletzt bearbeitet 04.09.2026 16:18:06
In the Linux kernel, the following vulnerability has been resolved: nfc: microread: validate target discovery payload lengths microread_target_discovered() parses target discovery payloads from skb->data according to the HCI gate. The fixed field o...
- EPSS 0.23%
- Veröffentlicht 04.09.2026 15:13:14
- Zuletzt bearbeitet 04.09.2026 16:18:06
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: bound the connect_sn TLV walk to the skb Commit 27256cdb290e ("nfc: llcp: bound SNL TLV parsing to the skb and add length checks") fixed the unbounded TLV walk in nfc_ll...
- EPSS 0.23%
- Veröffentlicht 04.09.2026 15:13:13
- Zuletzt bearbeitet 04.09.2026 16:18:06
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain three related bugs in their TLV parsing loops: 1. 'of...
- EPSS 0.23%
- Veröffentlicht 04.09.2026 15:13:12
- Zuletzt bearbeitet 04.09.2026 16:18:06
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: reject PDUs shorter than the LLCP header Every LLCP PDU begins with a two-byte header (DSAP/SSAP + PTYPE), but the receive path never checked that a frame is at least LL...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:13:10
- Zuletzt bearbeitet 04.09.2026 16:18:06
In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: purge fragmented skbs during cleanup pn53x_common_clean() purges resp_q before freeing the common PN533 state, but it leaves fragment_skb untouched. The fragmentation ...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:13:09
- Zuletzt bearbeitet 04.09.2026 16:18:06
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: add data_len bound checks to activation parameter extractors nci_extract_activation_params_iso_dep() and nci_extract_activation_params_nfc_dep() read an inner length byte...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:13:08
- Zuletzt bearbeitet 04.09.2026 16:18:06
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix out-of-bounds write in nci_target_auto_activated() nci_target_auto_activated() appends a target to the fixed-size array ndev->targets[NCI_MAX_DISCOVERED_TARGETS] and ...
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:13:07
- Zuletzt bearbeitet 04.09.2026 16:18:05
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix uninit-value in the RF discover/activated NTF handlers nci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each parse a notification into an on-stack ...