CVE-2026-80795
CVE CVE-2026-80795EUVD EUVD-2026-71438Published 2026-09-04T15:13:08.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix out-of-bounds write in nci_target_auto_activated() nci_target_auto_activated() appends a target to the fixed-size array ndev->targets[NCI_MAX_DISCOVERED_TARGETS] and increments ndev->n_targets without first checking the array is full; unlike its sibling nci_add_new_target(), which bails out when n_targets already equals NCI_MAX_DISCOVERED_TARGETS. ndev->n_targets is only cleared by nci_clear_target_list(), so an NFCC that repeatedly re-runs discovery (RF_DISCOVER_RSP, which re-enters NCI_DISCOVERY without clearing the target list) and reports an auto-activated target (RF_INTF_ACTIVATED_NTF) drives n_targets past the limit. The append then writes a struct nfc_target past the end of the array (a slab out-of-bounds write), and nfc_targets_found() goes on to walk the array with the inflated count: BUG: KASAN: slab-out-of-bounds in nci_add_new_protocol+0x94/0x2ac [nci] Write of size 2 at addr ffff0000c7299a18 by task kworker/u8:0/12 Workqueue: nfc0_nci_rx_wq nci_rx_work [nci] Call trace: nci_add_new_protocol+0x94/0x2ac [nci] nci_ntf_packet+0xddc/0x11a0 [nci] nci_rx_work+0x15c/0x1e0 [nci] process_one_work+0x2dc/0x500 worker_thread+0x240/0x460 kthread+0x1c0/0x1d0 ret_from_fork+0x10/0x20 The buggy address belongs to the cache kmalloc-2k of size 2048 The buggy address is located 1024 bytes to the right of allocated 1560-byte region [ffff0000c7299000, ffff0000c7299618) Guard nci_target_auto_activated() with the same check used by nci_add_new_target().
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 <d7083f41c21b30582e91b2e6de4d54dce74f6f9c; patch: 6.18.47; 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 <129032c0616d83a5e3e304f6ebf88f14ba01e5f7; patch: 5.10.267; 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 <0dc59de0075f88404a0f4a2b5233104ef459fbb2; patch: 6.12.106; patch: 7.3-rc1; patch: 7.1.11; patch: 7.2.1; 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 <94530ffabfca57e9bff1d207106010014cc84032; 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 <24761d3a5f692df5f7d848caeabcb2afd10917aa; 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 <afd8605fb43becb892311102844955c3b127fc7e; 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 <ac200079db50af81e6b04d058b33ec92901d8edd; 3.4; patch: 6.1.185; patch: 0; patch: 5.15.218; 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 <50e87e1c0e18d791dcd7dccf30f9a2f3e2cf3951; 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 <2f08dbce3b37624ec6b424d759336a99586170ec; patch: 6.6.154
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.