๐Ÿ” CVE Alert

CVE-2026-80798

UNKNOWN 0.0

nfc: llcp: reject PDUs shorter than the LLCP header

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: reject PDUs shorter than the LLCP header Every LLCP PDU begins with a two-byte header (DSAP/SSAP + PTYPE), but the receive path never checked that a frame is at least LLCP_HEADER_SIZE bytes before parsing it. nfc_llcp_rx_skb() reads the header via nfc_llcp_ptype()/nfc_llcp_dsap()/ nfc_llcp_ssap(), which dereference pdu->data[0] and pdu->data[1], and a CONNECT or CC PDU then computes tlv_array_len = skb->len - LLCP_HEADER_SIZE; as a size_t and hands it to the TLV walk. When the frame is shorter than the header the subtraction wraps to a huge value and the walk runs far past the buffer, an out-of-bounds read. A nearby NFC device can reach this without authentication; LLCP link activation happens automatically after NFC-DEP. Guard the common receive choke point __nfc_llcp_recv(), shared by both the target (nfc_llcp_data_received()) and initiator (nfc_llcp_recv()) paths, so a short skb is dropped before the rx_work worker parses it. Use pskb_may_pull() rather than a skb->len test so the two header bytes are guaranteed to sit in the skb linear area even for a non-linear skb, matching how the sibling NCI and HCI receive paths validate their headers. Reproduced with a KFENCE out-of-bounds read via /dev/virtual_nci on linux-next. Found by 0sec automated security-research tooling (https://0sec.ai).

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
d646960f7986fefb460a2b062d5ccc8ccfeacc3a < e6ec76a68dce04884dfeccfe5a5f0e9f67c0ec82 d646960f7986fefb460a2b062d5ccc8ccfeacc3a < f36cffea24bf3e2cc29a00d4b51dbcadc087d810 d646960f7986fefb460a2b062d5ccc8ccfeacc3a < a7b9b449f5a5132221fff6adc11a9431ab8cd914 d646960f7986fefb460a2b062d5ccc8ccfeacc3a < 3793d768b40f38bb97265dd5b9a8b8655c4e1b1d d646960f7986fefb460a2b062d5ccc8ccfeacc3a < eab47618e282602197db287ecbd1b09d356a2515 d646960f7986fefb460a2b062d5ccc8ccfeacc3a < e969e98410051b1ef8cc318bfe0c7e3f24ec766d d646960f7986fefb460a2b062d5ccc8ccfeacc3a < ae5f20f5842f440b72d030e3a34fe182dd8eae42 d646960f7986fefb460a2b062d5ccc8ccfeacc3a < d3d90243393c48146911c67fd3792b549d21d9e6 d646960f7986fefb460a2b062d5ccc8ccfeacc3a < 95674f506c6376d6722a23144c9acd26609771ed
Linux / Linux
3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/e6ec76a68dce04884dfeccfe5a5f0e9f67c0ec82 git.kernel.org: https://git.kernel.org/stable/c/f36cffea24bf3e2cc29a00d4b51dbcadc087d810 git.kernel.org: https://git.kernel.org/stable/c/a7b9b449f5a5132221fff6adc11a9431ab8cd914 git.kernel.org: https://git.kernel.org/stable/c/3793d768b40f38bb97265dd5b9a8b8655c4e1b1d git.kernel.org: https://git.kernel.org/stable/c/eab47618e282602197db287ecbd1b09d356a2515 git.kernel.org: https://git.kernel.org/stable/c/e969e98410051b1ef8cc318bfe0c7e3f24ec766d git.kernel.org: https://git.kernel.org/stable/c/ae5f20f5842f440b72d030e3a34fe182dd8eae42 git.kernel.org: https://git.kernel.org/stable/c/d3d90243393c48146911c67fd3792b549d21d9e6 git.kernel.org: https://git.kernel.org/stable/c/95674f506c6376d6722a23144c9acd26609771ed