CVE-2026-80799
CVE CVE-2026-80799EUVD EUVD-2026-71234Published 2026-09-04T15:13:13.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain three related bugs in their TLV parsing loops: 1. 'offset' is declared u8 but tlv_array_len is u16. When TLV data advances offset past 255 it silently wraps to zero, causing infinite loops or double-processing of buffer data. 2. Before reading tlv[0] (type) and tlv[1] (length) there is no check that offset+2 <= tlv_array_len. A truncated TLV causes an OOB read of one byte past the buffer end. 3. After reading the length field, the value bytes are accessed without checking offset+2+length <= tlv_array_len. A crafted length=0xFF on a short buffer causes up to 255 bytes of OOB read past the buffer end. Both functions are reachable without authentication via nfc_llcp_set_remote_gb() which feeds remote LLCP general bytes directly into nfc_llcp_parse_gb_tlv() with no additional validation. Fix all three issues by widening offset from u8 to u16 and adding bounds checks for both the TLV header and value field before each access.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.18.47; 1deacb5e031e289ca5636f2db4fcae6612c05d34; patch: 7.1.11; patch: 7.3-rc1; 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 <e84cdfdc4a6c88e8b751144458f2e04e24415a28; 66a1be74230bbe098e651766c9a0cf4038db8442; 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 <382eaa770335acf4f16a5a55524500f2bb4207df; 5.15; patch: 6.1.185; 5.10.188 <5.10.267; 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 <9c47d667963542c3cf8e3007b7f10c0904d08238; 4.19.291 <4.20; patch: 7.2.1; 5.4.251 <5.5; patch: 5.15.218; 0be9de2ea01e8d52646e7310a7eef5459cf07ea8 <2c1456fe09ab1a5a9fe1d8339ca6d509589b56e1; patch: 5.10.267; patch: 0; patch: 6.6.154; 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 <875285a165fd3b402de2ab3be0deb355d6f4caf5; 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 <a209334ed929941b20810c17c3a507445b0a7c85; patch: 6.12.106; 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 <2d239590d1845a706304833d40dd6d4fec20ad88; 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 <78b20c8eeacd2e44a2d8a4cb5316d3c521d90911; 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 <7f6f3d087c67a4346189ef2c36481455bbc59a74
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.