CVE-2026-90221
CVE CVE-2026-90221EUVD EUVD-2026-81814Published 2026-09-17T16:07:32.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() parse the CORE_INIT_RSP packet without validating that the skb contains enough data. A malformed response (e.g. injected via virtual_ncidev) can declare a large num_supported_rf_interfaces while providing insufficient data, causing reads of uninitialized slab memory. This is later used in nci_init_complete_req(), triggering a KMSAN uninit-value warning. Add skb length checks before accessing packet fields: - Validate the skb has at least 1 byte for the status field. - Validate the skb can hold the fixed-size header before parsing. - In v2, bounds-check each variable-length rf_interface entry and its extension parameters within the parsing loop. - In v1, verify the skb is large enough for both the variable-length rf_interfaces array and the trailing rsp_2 structure.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.18.52; bcd684aace34fedbd473fbd9b21ed06b0c2d2212 <4f0483bbcdaccc9d4aee30df7351863334cecfa7; patch: 6.6.157; patch: 0; bcd684aace34fedbd473fbd9b21ed06b0c2d2212 <2f434478771a4ebdd535033561c0590bcde39753; patch: 5.15.221; bcd684aace34fedbd473fbd9b21ed06b0c2d2212 <5487f04c1ccbfa15aa6e531eb1ec9c9ec9c7bf31; bcd684aace34fedbd473fbd9b21ed06b0c2d2212 <d56575a2595ee1f597f39e8a1cfb67ed3501678d; patch: 6.12.110; 5.11; patch: 6.1.188; bcd684aace34fedbd473fbd9b21ed06b0c2d2212 <bbe68e8249e2c76d65adfd9224fa95f1ca0fbe4e; bcd684aace34fedbd473fbd9b21ed06b0c2d2212 <7d44b897bff84edcd4814899314d661ad4956a8e; patch: 7.2.6; patch: 7.3-rc1; bcd684aace34fedbd473fbd9b21ed06b0c2d2212 <baed3fdf6ed2195c56f25ae18a086b938dcd3983
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.