From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E46AC4E8E17 for ; Fri, 4 Sep 2026 15:20:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535232; cv=none; b=omlffYBPk+FWcUZFuMRZvCqI7y/4728yfS9l087t9ZmGkjT7nMe4E82DQCsAuCX1+G02+OB2ibdIfGMM5mPLX+drdkjrZATzwYlrOUw+22od8v+sG68yvNoBA+lfLmLfRSSWjE4M1B3GIVJYiZZjTWczPj1QSX/T7eariZJQkSg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535232; c=relaxed/simple; bh=fssZYhJ8wGn/8aK+c9QJrAS2MLVw/z2X5LkLH0C57pI=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=KaaoEi+k8WIG89Xel3i1yUPHCd+WwKLZyfY6trXyPCFbRQyIQelciJ16eV4FN+Yeqs9h5i5sk4hHp53ni+g1BV6ps6xHXvZZktHFbDUSZTNOfLFg8Q2eMWdpD9HZYCXIXTR8hci+bxV0zIedYhLZnbmSldyHaA+qelvybGqNBxY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=haSnjXTQ; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="haSnjXTQ" Received: by smtp.kernel.org (Postfix) with ESMTPSA id B1D2E1F00A3D; Fri, 4 Sep 2026 15:20:29 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788535230; bh=KgYcyJT0j1TLjLiU4ia+7XIR0pARj51xhjhKzJ7sNhk=; h=From:To:Cc:Subject:Date:Reply-To; b=haSnjXTQ2S9g/jHYtzuYToO2igTMdkZsSA9SGOg5FpkM3T4MyHOfG/TtXZ2tqZ1T+ kVeJ9aJ8rAqToN5W20xy4KlqKXgyWnBKCz6HHyEjcgxOGKr1+z/EEZeBNscpllwvHE hA7+JYDXNnJnbhmSZi1biWE7ydgrECufXinGJS4c= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80796: nfc: nci: add data_len bound checks to activation parameter extractors Date: Fri, 4 Sep 2026 17:11:35 +0200 Message-ID: <2026090407-CVE-2026-80796-9b66@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4522; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=kRsE1oWLT/VX4S9RdNnhSFFII9YbpptAJ7iOZd2YccM=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmz7veUJxyx8Lvh9tbC3WEzT0yZsVfMe//Jl/YJSL0pn 8wddNm3I5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACZy1JthDi9X2+XfaR/yhA7U PvQqPndwd8v7Boa5IocTk+bVp0u8mdTgrHqhqHbZ5wctAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: nfc: nci: add data_len bound checks to activation parameter extractors nci_extract_activation_params_iso_dep() and nci_extract_activation_params_nfc_dep() read an inner length byte from the NCI RF_INTF_ACTIVATED_NTF payload and use it to memcpy() into fixed kernel buffers, but neither function receives the caller-validated activation_params_len. A crafted NCI notification with activation_params_len=1 and an inner length byte of up to 20 (NFC-A) or 50 (NFC-B) causes memcpy() to read that many bytes past the one valid byte in the activation params region -- a slab out-of-bounds read of kernel memory adjacent to the NCI skb. The sibling nci_extract_rf_params_*() family was given equivalent protection by commit 571dcbeb8e63 ("net: nfc: nci: Fix parameter validation for packet data"), but the two activation parameter extractors were not updated at that time. Add a data_len parameter to both functions, guard against an empty region before consuming the inner length byte, decrement the remaining count after consuming it, and clamp the copy length to what is actually available. Update both call sites to pass ntf.activation_params_len, which is already validated against the skb at ntf.c:801. The Linux kernel CVE team has assigned CVE-2026-80796 to this issue. Affected and fixed versions =========================== Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 5.10.269 with commit 1168484fe2b3828bf24a46f3c42a8719fade679b Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 5.15.220 with commit be311c0cfeadfbe815ea22d2914a98d06e3fab0e Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 6.1.187 with commit 04e51353cb9fa321caaeeed8331d4cd041fbaca7 Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 6.6.156 with commit e25b44bd8b8cc666b49a3fe0ef547e64d5b1e300 Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 6.12.108 with commit 9b01f5af0dc59263b59391b148bc78d83c0354a9 Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 6.18.47 with commit 9620a91f8d643b680f417a435db399a04d1e06d8 Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 7.1.11 with commit cf9d44be50b9074a5abdc301b4a3ba3e283591df Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 7.2.1 with commit f5c534b53f8c424a8e7633c9b585475c4bf4ee18 Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 7.3-rc1 with commit 0428fa2c22e2ba0cff766d3b80d461e149102045 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80796 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/nfc/nci/ntf.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/1168484fe2b3828bf24a46f3c42a8719fade679b https://git.kernel.org/stable/c/be311c0cfeadfbe815ea22d2914a98d06e3fab0e https://git.kernel.org/stable/c/04e51353cb9fa321caaeeed8331d4cd041fbaca7 https://git.kernel.org/stable/c/e25b44bd8b8cc666b49a3fe0ef547e64d5b1e300 https://git.kernel.org/stable/c/9b01f5af0dc59263b59391b148bc78d83c0354a9 https://git.kernel.org/stable/c/9620a91f8d643b680f417a435db399a04d1e06d8 https://git.kernel.org/stable/c/cf9d44be50b9074a5abdc301b4a3ba3e283591df https://git.kernel.org/stable/c/f5c534b53f8c424a8e7633c9b585475c4bf4ee18 https://git.kernel.org/stable/c/0428fa2c22e2ba0cff766d3b80d461e149102045