๐Ÿ” CVE Alert

CVE-2026-80795

UNKNOWN 0.0

nfc: nci: fix out-of-bounds write in nci_target_auto_activated()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix out-of-bounds write in nci_target_auto_activated() nci_target_auto_activated() appends a target to the fixed-size array ndev->targets[NCI_MAX_DISCOVERED_TARGETS] and increments ndev->n_targets without first checking the array is full; unlike its sibling nci_add_new_target(), which bails out when n_targets already equals NCI_MAX_DISCOVERED_TARGETS. ndev->n_targets is only cleared by nci_clear_target_list(), so an NFCC that repeatedly re-runs discovery (RF_DISCOVER_RSP, which re-enters NCI_DISCOVERY without clearing the target list) and reports an auto-activated target (RF_INTF_ACTIVATED_NTF) drives n_targets past the limit. The append then writes a struct nfc_target past the end of the array (a slab out-of-bounds write), and nfc_targets_found() goes on to walk the array with the inflated count: BUG: KASAN: slab-out-of-bounds in nci_add_new_protocol+0x94/0x2ac [nci] Write of size 2 at addr ffff0000c7299a18 by task kworker/u8:0/12 Workqueue: nfc0_nci_rx_wq nci_rx_work [nci] Call trace: nci_add_new_protocol+0x94/0x2ac [nci] nci_ntf_packet+0xddc/0x11a0 [nci] nci_rx_work+0x15c/0x1e0 [nci] process_one_work+0x2dc/0x500 worker_thread+0x240/0x460 kthread+0x1c0/0x1d0 ret_from_fork+0x10/0x20 The buggy address belongs to the cache kmalloc-2k of size 2048 The buggy address is located 1024 bytes to the right of allocated 1560-byte region [ffff0000c7299000, ffff0000c7299618) Guard nci_target_auto_activated() with the same check used by nci_add_new_target().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < 0dc59de0075f88404a0f4a2b5233104ef459fbb2 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < 94530ffabfca57e9bff1d207106010014cc84032 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < afd8605fb43becb892311102844955c3b127fc7e 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < 24761d3a5f692df5f7d848caeabcb2afd10917aa 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < 50e87e1c0e18d791dcd7dccf30f9a2f3e2cf3951 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < 2f08dbce3b37624ec6b424d759336a99586170ec 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < d7083f41c21b30582e91b2e6de4d54dce74f6f9c 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < 129032c0616d83a5e3e304f6ebf88f14ba01e5f7 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < ac200079db50af81e6b04d058b33ec92901d8edd
Linux / Linux
3.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/0dc59de0075f88404a0f4a2b5233104ef459fbb2 git.kernel.org: https://git.kernel.org/stable/c/94530ffabfca57e9bff1d207106010014cc84032 git.kernel.org: https://git.kernel.org/stable/c/afd8605fb43becb892311102844955c3b127fc7e git.kernel.org: https://git.kernel.org/stable/c/24761d3a5f692df5f7d848caeabcb2afd10917aa git.kernel.org: https://git.kernel.org/stable/c/50e87e1c0e18d791dcd7dccf30f9a2f3e2cf3951 git.kernel.org: https://git.kernel.org/stable/c/2f08dbce3b37624ec6b424d759336a99586170ec git.kernel.org: https://git.kernel.org/stable/c/d7083f41c21b30582e91b2e6de4d54dce74f6f9c git.kernel.org: https://git.kernel.org/stable/c/129032c0616d83a5e3e304f6ebf88f14ba01e5f7 git.kernel.org: https://git.kernel.org/stable/c/ac200079db50af81e6b04d058b33ec92901d8edd