๐Ÿ” CVE Alert

CVE-2026-80802

UNKNOWN 0.0

nfc: fdp: bound the device-reported read length and fix an skb leak

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nfc: fdp: bound the device-reported read length and fix an skb leak fdp_nci_i2c_read() takes the next packet length from two device-supplied bytes and never validates it. The value is a u16 used as the i2c_master_recv() count into a 261-byte on-stack buffer: a malicious, counterfeit or malfunctioning controller (or an i2c bus interposer) can drive it far past the buffer for a stack out-of-bounds write that clobbers the canary and return address, or below the minimum frame size (directly, or by truncating the computed sum) so the header/LRC strip and the next length read run past a short receive. Reject a length outside [FDP_NCI_I2C_MIN_PAYLOAD, FDP_NCI_I2C_MAX_PAYLOAD], as a corrupted packet already is, and force resynchronization. The same loop allocates one data skb per iteration and assumes a length packet followed by a data packet; a device that sends two data packets in one call leaks the first skb when the second allocation overwrites it. Free a previously allocated skb before allocating the next.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
a06347c04c13e380afce0c9816df51f00b83faf1 < d9498ab9a78cb63d78dbe4f221d8cc6c91f285ee a06347c04c13e380afce0c9816df51f00b83faf1 < 1fc32327b927a6e2cde086f82575c29880844228 a06347c04c13e380afce0c9816df51f00b83faf1 < 8d2c243b79854628ff076c38748c020042f02f57 a06347c04c13e380afce0c9816df51f00b83faf1 < fc3c2bd5b1ec6c7cbc8a50e32d9bcec114f25463 a06347c04c13e380afce0c9816df51f00b83faf1 < 0d723090645b82c1cb27cfd7ebf81f0e7c96bcae a06347c04c13e380afce0c9816df51f00b83faf1 < db7e464b350969c6ea8340de00d9796e5fd5123b a06347c04c13e380afce0c9816df51f00b83faf1 < e5eec121f2c3bc4c7022613bedd9121a8aa4c949 a06347c04c13e380afce0c9816df51f00b83faf1 < 1aa3fc769b0c45bd19f8dab1697084c2b3f6d706 a06347c04c13e380afce0c9816df51f00b83faf1 < 7ad21dcfeb5181af0c3ee2608808c0c0a5283aa1
Linux / Linux
4.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d9498ab9a78cb63d78dbe4f221d8cc6c91f285ee git.kernel.org: https://git.kernel.org/stable/c/1fc32327b927a6e2cde086f82575c29880844228 git.kernel.org: https://git.kernel.org/stable/c/8d2c243b79854628ff076c38748c020042f02f57 git.kernel.org: https://git.kernel.org/stable/c/fc3c2bd5b1ec6c7cbc8a50e32d9bcec114f25463 git.kernel.org: https://git.kernel.org/stable/c/0d723090645b82c1cb27cfd7ebf81f0e7c96bcae git.kernel.org: https://git.kernel.org/stable/c/db7e464b350969c6ea8340de00d9796e5fd5123b git.kernel.org: https://git.kernel.org/stable/c/e5eec121f2c3bc4c7022613bedd9121a8aa4c949 git.kernel.org: https://git.kernel.org/stable/c/1aa3fc769b0c45bd19f8dab1697084c2b3f6d706 git.kernel.org: https://git.kernel.org/stable/c/7ad21dcfeb5181af0c3ee2608808c0c0a5283aa1