๐Ÿ” CVE Alert

CVE-2026-80794

UNKNOWN 0.0

nfc: nci: fix uninit-value in the RF discover/activated NTF handlers

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix uninit-value in the RF discover/activated NTF handlers nci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each parse a notification into an on-stack struct (nci_rf_discover_ntf / nci_rf_intf_activated_ntf) that is not initialised. The RF technology-specific parameters are only extracted when rf_tech_specific_params_len is non-zero, so a notification that reports a zero length leaves the rf_tech_specific_params union uninitialised - and both handlers then pass it to nci_add_new_protocol(), which reads it: - discover: nci_add_new_target() -> nci_add_new_protocol(); - activated: nci_target_auto_activated() -> nci_add_new_protocol(). nci_add_new_protocol() uses nfca_poll->nfcid1_len as both a branch condition and a memcpy() length and copies nfcid1/sens_res/sel_res into ndev->targets, which is later exposed to user space via NFC_CMD_GET_TARGET. BUG: KMSAN: uninit-value in nci_add_new_protocol+0x624/0x6c0 nci_add_new_protocol+0x624/0x6c0 nci_ntf_packet+0x25b2/0x3c30 nci_rx_work+0x318/0x5d0 process_scheduled_works+0x84b/0x17a0 worker_thread+0xc10/0x11b0 kthread+0x376/0x500 Local variable ntf.i created at: nci_ntf_packet+0xbc2/0x3c30 Zero-initialise both on-stack notifications so the union reads back as zero when no technology-specific parameters are present.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 < 1007a6b429d756513abd25bd00290908f2e89a4a e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 < 4bda9ef8392710f21e99027467f3f4afdfb5c99a e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 < fe69fed3495f676578d49414a069ad7d8468e2ce e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 < 7489f59d1ea2d3298aa41de7baf193e5e6e132f6 e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 < 7086dab72b3ed95df96842801e10e935cfeb27a3 e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 < 0d4b5cfab6891a5ca0f6aef209beebba4bd7c095 e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 < 5bd00c0e1470d90d77a7c60242854257ddf14e00 e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 < d6f743d3d388913135681cde051c08823730194f e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 < 8cbe06c1e699c0a165dae5093a2550e65f914818
Linux / Linux
3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/1007a6b429d756513abd25bd00290908f2e89a4a git.kernel.org: https://git.kernel.org/stable/c/4bda9ef8392710f21e99027467f3f4afdfb5c99a git.kernel.org: https://git.kernel.org/stable/c/fe69fed3495f676578d49414a069ad7d8468e2ce git.kernel.org: https://git.kernel.org/stable/c/7489f59d1ea2d3298aa41de7baf193e5e6e132f6 git.kernel.org: https://git.kernel.org/stable/c/7086dab72b3ed95df96842801e10e935cfeb27a3 git.kernel.org: https://git.kernel.org/stable/c/0d4b5cfab6891a5ca0f6aef209beebba4bd7c095 git.kernel.org: https://git.kernel.org/stable/c/5bd00c0e1470d90d77a7c60242854257ddf14e00 git.kernel.org: https://git.kernel.org/stable/c/d6f743d3d388913135681cde051c08823730194f git.kernel.org: https://git.kernel.org/stable/c/8cbe06c1e699c0a165dae5093a2550e65f914818