CVE-2026-80823
CVE CVE-2026-80823EUVD EUVD-2026-71265Published 2026-09-04T15:27:46.000ZLast changed 2026-09-04T15:29:25.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: nfc: st21nfca: validate ATR_REQ length against the received frame st21nfca_tm_recv_atr_req() checks that the received ATR_REQ frame is at least ST21NFCA_ATR_REQ_MIN_SIZE and that the self-declared atr_req->length is at least sizeof(struct st21nfca_atr_req), but never checks that atr_req->length does not exceed the actual received length (skb->len). st21nfca_tm_send_atr_res() then trusts the declared length: gb_len = atr_req->length - sizeof(struct st21nfca_atr_req); ... memcpy(atr_res->gbi, atr_req->gbi, gb_len); so an RF peer that sends a short frame but sets atr_req->length larger than the frame makes gb_len exceed the general bytes actually present, and the memcpy reads out of bounds past the received skb. Those bytes are placed in the ATR_RES and sent back to the peer (kernel-memory disclosure to a proximity attacker); a larger declared length is an out-of-bounds read (DoS). Reject frames whose declared length exceeds the received length. The adjacent nfc_tm_activated() path in the same function already derives its general-bytes length from skb->len rather than the declared field. Found by 0sec (https://0sec.ai) using automated source analysis; the missing bound is evident from source. Compile-tested.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 1892bf844ea0261736bd5e75546fc996e9daeedf <785df00bb3ae3206674a43284eb06dac575b5c64; 1892bf844ea0261736bd5e75546fc996e9daeedf <bfcca5f42c9aa4eadef1e5fe7bb23783d7fcc96d; patch: 6.12.106; patch: 6.18.47; patch: 5.10.267; 1892bf844ea0261736bd5e75546fc996e9daeedf <9635507fe82949e429b3cd938876a9917125b151; 1892bf844ea0261736bd5e75546fc996e9daeedf <f33cecf69095c43be88567fef92b180b858f7369; patch: 7.2.1; 1892bf844ea0261736bd5e75546fc996e9daeedf <2c1ad291f4cdc357f9527b688c6fda9c6ffa7890; patch: 6.6.154; patch: 7.1.11; patch: 0; 1892bf844ea0261736bd5e75546fc996e9daeedf <304f5b414f4051d324b8c4a3ab0e79f7dc7e150e; 1892bf844ea0261736bd5e75546fc996e9daeedf <dd26d30f40c43ad9cfe2f25c6ea0ead1dd51d5aa; patch: 5.15.218; patch: 7.3-rc1; patch: 6.1.185; 3.17; 1892bf844ea0261736bd5e75546fc996e9daeedf <5cdcca5d62a66eda6b774110a44cba67bc1a8d1d; 1892bf844ea0261736bd5e75546fc996e9daeedf <0f344944c506b4f02d2b098489f7268b438c369e
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.