From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B562340B104 for ; Fri, 4 Sep 2026 15:20:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535208; cv=none; b=fL4Nawzw/1m3+6kdXaCYEGnLwd2tdbFWytG/sZ4/Rloub3wZ+oRx9GNA3KZxfdfvAiz+udZ8dNTsZgWJNj5ebqrY6d+EobPq3bJ/Sj0l+mwLxn/JZaAOINzNtrQfYzyR7io1RNOW5NZaMFE5uyzXPQddj2ROaiL3/JGCniRbJvw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535208; c=relaxed/simple; bh=hi8oZlALeBUgxqF5ggtXPnhlP4dnucc8CnDw7mHC9Eg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=ZfWMHztZu6qr/HUIuFvCdss9r2hsIe9tBh0ai8sms7uCAuWZHND1Pw5mm78jKyjHmccdwXCKhuTeydV4KV3waTHGl2S8k/QrcvhqCq8Mdhe9vjaQqPRLv139PZ/+NHXX93d4vHMHXEo8EByU+TDjprFs86D16MTh0Hze65afgIc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=z1p4t2Sq; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="z1p4t2Sq" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 961CA1F00A3D; Fri, 4 Sep 2026 15:20:05 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788535206; bh=h6klsrmxDpM03YCp1FmicXYncOmNm48M5gLkBaBM7D8=; h=From:To:Cc:Subject:Date:Reply-To; b=z1p4t2SqWHTkhq45p24hRyK26WrFK94ggx8L7yDg7yo7K5EO7NqQhrIb0AssuwujU piE+6lQX5lGNDcIMdHlLvyeEAtAYGEsSeXpswsf3Iyz7qtGplxPPBUpn7hsXzhUb/c duNG1O10VnmMYXBujCd1MkmepJtltrF6Sp0aQFOY= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80794: nfc: nci: fix uninit-value in the RF discover/activated NTF handlers Date: Fri, 4 Sep 2026 17:11:33 +0200 Message-ID: <2026090407-CVE-2026-80794-2213@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4659; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=moGXVQmG+ZEMRoYf9v9OH+wY8frMBhrc4Xalf7c7ORI=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmz7nebKXmmrSpe9/fAr6YglTDWUJN7a7m/5Rddf/ZzT 5OywqovHbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjARSx6G+WmMn+828+sLbHl7 Spdr0lzDpP2+AgwLtketWsEX/VTXuGp7tFpQ09K1nQb8AA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix uninit-value in the RF discover/activated NTF handlers nci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each parse a notification into an on-stack struct (nci_rf_discover_ntf / nci_rf_intf_activated_ntf) that is not initialised. The RF technology-specific parameters are only extracted when rf_tech_specific_params_len is non-zero, so a notification that reports a zero length leaves the rf_tech_specific_params union uninitialised - and both handlers then pass it to nci_add_new_protocol(), which reads it: - discover: nci_add_new_target() -> nci_add_new_protocol(); - activated: nci_target_auto_activated() -> nci_add_new_protocol(). nci_add_new_protocol() uses nfca_poll->nfcid1_len as both a branch condition and a memcpy() length and copies nfcid1/sens_res/sel_res into ndev->targets, which is later exposed to user space via NFC_CMD_GET_TARGET. BUG: KMSAN: uninit-value in nci_add_new_protocol+0x624/0x6c0 nci_add_new_protocol+0x624/0x6c0 nci_ntf_packet+0x25b2/0x3c30 nci_rx_work+0x318/0x5d0 process_scheduled_works+0x84b/0x17a0 worker_thread+0xc10/0x11b0 kthread+0x376/0x500 Local variable ntf.i created at: nci_ntf_packet+0xbc2/0x3c30 Zero-initialise both on-stack notifications so the union reads back as zero when no technology-specific parameters are present. The Linux kernel CVE team has assigned CVE-2026-80794 to this issue. Affected and fixed versions =========================== Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 5.10.269 with commit 1007a6b429d756513abd25bd00290908f2e89a4a Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 5.15.218 with commit 4bda9ef8392710f21e99027467f3f4afdfb5c99a Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 6.1.185 with commit fe69fed3495f676578d49414a069ad7d8468e2ce Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 6.6.154 with commit 7489f59d1ea2d3298aa41de7baf193e5e6e132f6 Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 6.12.106 with commit 7086dab72b3ed95df96842801e10e935cfeb27a3 Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 6.18.47 with commit 0d4b5cfab6891a5ca0f6aef209beebba4bd7c095 Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 7.1.11 with commit 5bd00c0e1470d90d77a7c60242854257ddf14e00 Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 7.2.1 with commit d6f743d3d388913135681cde051c08823730194f Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 7.3-rc1 with commit 8cbe06c1e699c0a165dae5093a2550e65f914818 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80794 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/nfc/nci/ntf.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/1007a6b429d756513abd25bd00290908f2e89a4a https://git.kernel.org/stable/c/4bda9ef8392710f21e99027467f3f4afdfb5c99a https://git.kernel.org/stable/c/fe69fed3495f676578d49414a069ad7d8468e2ce https://git.kernel.org/stable/c/7489f59d1ea2d3298aa41de7baf193e5e6e132f6 https://git.kernel.org/stable/c/7086dab72b3ed95df96842801e10e935cfeb27a3 https://git.kernel.org/stable/c/0d4b5cfab6891a5ca0f6aef209beebba4bd7c095 https://git.kernel.org/stable/c/5bd00c0e1470d90d77a7c60242854257ddf14e00 https://git.kernel.org/stable/c/d6f743d3d388913135681cde051c08823730194f https://git.kernel.org/stable/c/8cbe06c1e699c0a165dae5093a2550e65f914818