๐Ÿ” CVE Alert

CVE-2026-80823

UNKNOWN 0.0

nfc: st21nfca: validate ATR_REQ length against the received frame

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nfc: st21nfca: validate ATR_REQ length against the received frame st21nfca_tm_recv_atr_req() checks that the received ATR_REQ frame is at least ST21NFCA_ATR_REQ_MIN_SIZE and that the self-declared atr_req->length is at least sizeof(struct st21nfca_atr_req), but never checks that atr_req->length does not exceed the actual received length (skb->len). st21nfca_tm_send_atr_res() then trusts the declared length: gb_len = atr_req->length - sizeof(struct st21nfca_atr_req); ... memcpy(atr_res->gbi, atr_req->gbi, gb_len); so an RF peer that sends a short frame but sets atr_req->length larger than the frame makes gb_len exceed the general bytes actually present, and the memcpy reads out of bounds past the received skb. Those bytes are placed in the ATR_RES and sent back to the peer (kernel-memory disclosure to a proximity attacker); a larger declared length is an out-of-bounds read (DoS). Reject frames whose declared length exceeds the received length. The adjacent nfc_tm_activated() path in the same function already derives its general-bytes length from skb->len rather than the declared field. Found by 0sec (https://0sec.ai) using automated source analysis; the missing bound is evident from source. Compile-tested.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2026
Last Updated Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1892bf844ea0261736bd5e75546fc996e9daeedf < 785df00bb3ae3206674a43284eb06dac575b5c64 1892bf844ea0261736bd5e75546fc996e9daeedf < 2c1ad291f4cdc357f9527b688c6fda9c6ffa7890 1892bf844ea0261736bd5e75546fc996e9daeedf < dd26d30f40c43ad9cfe2f25c6ea0ead1dd51d5aa 1892bf844ea0261736bd5e75546fc996e9daeedf < 9635507fe82949e429b3cd938876a9917125b151 1892bf844ea0261736bd5e75546fc996e9daeedf < 0f344944c506b4f02d2b098489f7268b438c369e 1892bf844ea0261736bd5e75546fc996e9daeedf < bfcca5f42c9aa4eadef1e5fe7bb23783d7fcc96d 1892bf844ea0261736bd5e75546fc996e9daeedf < 304f5b414f4051d324b8c4a3ab0e79f7dc7e150e 1892bf844ea0261736bd5e75546fc996e9daeedf < f33cecf69095c43be88567fef92b180b858f7369 1892bf844ea0261736bd5e75546fc996e9daeedf < 5cdcca5d62a66eda6b774110a44cba67bc1a8d1d
Linux / Linux
3.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/785df00bb3ae3206674a43284eb06dac575b5c64 git.kernel.org: https://git.kernel.org/stable/c/2c1ad291f4cdc357f9527b688c6fda9c6ffa7890 git.kernel.org: https://git.kernel.org/stable/c/dd26d30f40c43ad9cfe2f25c6ea0ead1dd51d5aa git.kernel.org: https://git.kernel.org/stable/c/9635507fe82949e429b3cd938876a9917125b151 git.kernel.org: https://git.kernel.org/stable/c/0f344944c506b4f02d2b098489f7268b438c369e git.kernel.org: https://git.kernel.org/stable/c/bfcca5f42c9aa4eadef1e5fe7bb23783d7fcc96d git.kernel.org: https://git.kernel.org/stable/c/304f5b414f4051d324b8c4a3ab0e79f7dc7e150e git.kernel.org: https://git.kernel.org/stable/c/f33cecf69095c43be88567fef92b180b858f7369 git.kernel.org: https://git.kernel.org/stable/c/5cdcca5d62a66eda6b774110a44cba67bc1a8d1d