From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 650B84EA393 for ; Fri, 4 Sep 2026 15:20:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535245; cv=none; b=hiRx1TSmsR3ypk95mppLjL1d8NOnFy0ilXcQe0VDrvLrvtnQ9/19rGre2REn9RYvBk9UqLIDIJEoHniIkKlXbvsydykD82elUH16uRvFRIrqpeMdMQyOqv9sEJkc+HYMfH8/VT4EqWR6OATTL0j6TZfU181+DBNYoToaxVTZOHE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535245; c=relaxed/simple; bh=ccwa7WQLs8iUXOq6Htj3dgdwwmwGgSrMwZBceTBrE1w=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=nCE255tQxueZbJhs7ym6V/tq1+U0HkxWzFMc94bj2UxEWxCKf0VJ7/dCNoeQIatSc9p7S5c+dP09qv5SaBRJCoDBEB+ECwdNy1jS06+EjOjs8U62Ce2a6sQQouSOxwuNJUiEuIsB00DYUYnDFU+BnLF5x8yfWXFBkUP766yV2Hw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=vByhvUUM; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="vByhvUUM" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 68A5B1F00A3D; Fri, 4 Sep 2026 15:20:43 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788535244; bh=cLZruef6rl+gD0DplpIV7+rMl8ochEjlFAxiXa8tz8g=; h=From:To:Cc:Subject:Date:Reply-To; b=vByhvUUMe9xFSOltZh3kUdLtwHLOKGFdurovoFgxNR2TjaFV41FILYc8KiLvqLGjS VShAkfxlVrKtCJcdYN7m1BgdcQ7NLiEfyctqIumlcCgY8Na3zKh2fcM1ZU/zmOvhxA gUMz2Hu+ekpsoVerAQgea0tISrIRveSYEZRZHI9Q= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80798: nfc: llcp: reject PDUs shorter than the LLCP header Date: Fri, 4 Sep 2026 17:11:37 +0200 Message-ID: <2026090408-CVE-2026-80798-9936@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4656; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=6iBi4DtqHtMnGlcx1xXkiymDrGv4Lh40PBU16V2m4bQ=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmz7vfs3B151X8qY8GF3WfO7FWJOyXzWiDqhUXLHu/tS wNTliw/2hHLwiDIxCArpsjyZRvP0f0VhxS9DG1Pw8xhZQIZwsDFKQAT0dnNsGD7xuXt2hlsG44b THB72TL7jm442y+GeTaO9XNSlMOyZjAKKX6taGF71yrjBAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: reject PDUs shorter than the LLCP header Every LLCP PDU begins with a two-byte header (DSAP/SSAP + PTYPE), but the receive path never checked that a frame is at least LLCP_HEADER_SIZE bytes before parsing it. nfc_llcp_rx_skb() reads the header via nfc_llcp_ptype()/nfc_llcp_dsap()/ nfc_llcp_ssap(), which dereference pdu->data[0] and pdu->data[1], and a CONNECT or CC PDU then computes tlv_array_len = skb->len - LLCP_HEADER_SIZE; as a size_t and hands it to the TLV walk. When the frame is shorter than the header the subtraction wraps to a huge value and the walk runs far past the buffer, an out-of-bounds read. A nearby NFC device can reach this without authentication; LLCP link activation happens automatically after NFC-DEP. Guard the common receive choke point __nfc_llcp_recv(), shared by both the target (nfc_llcp_data_received()) and initiator (nfc_llcp_recv()) paths, so a short skb is dropped before the rx_work worker parses it. Use pskb_may_pull() rather than a skb->len test so the two header bytes are guaranteed to sit in the skb linear area even for a non-linear skb, matching how the sibling NCI and HCI receive paths validate their headers. Reproduced with a KFENCE out-of-bounds read via /dev/virtual_nci on linux-next. Found by 0sec automated security-research tooling (https://0sec.ai). The Linux kernel CVE team has assigned CVE-2026-80798 to this issue. Affected and fixed versions =========================== Issue introduced in 3.3 with commit d646960f7986fefb460a2b062d5ccc8ccfeacc3a and fixed in 5.10.267 with commit e6ec76a68dce04884dfeccfe5a5f0e9f67c0ec82 Issue introduced in 3.3 with commit d646960f7986fefb460a2b062d5ccc8ccfeacc3a and fixed in 5.15.218 with commit f36cffea24bf3e2cc29a00d4b51dbcadc087d810 Issue introduced in 3.3 with commit d646960f7986fefb460a2b062d5ccc8ccfeacc3a and fixed in 6.1.185 with commit a7b9b449f5a5132221fff6adc11a9431ab8cd914 Issue introduced in 3.3 with commit d646960f7986fefb460a2b062d5ccc8ccfeacc3a and fixed in 6.6.154 with commit 3793d768b40f38bb97265dd5b9a8b8655c4e1b1d Issue introduced in 3.3 with commit d646960f7986fefb460a2b062d5ccc8ccfeacc3a and fixed in 6.12.106 with commit eab47618e282602197db287ecbd1b09d356a2515 Issue introduced in 3.3 with commit d646960f7986fefb460a2b062d5ccc8ccfeacc3a and fixed in 6.18.47 with commit e969e98410051b1ef8cc318bfe0c7e3f24ec766d Issue introduced in 3.3 with commit d646960f7986fefb460a2b062d5ccc8ccfeacc3a and fixed in 7.1.11 with commit ae5f20f5842f440b72d030e3a34fe182dd8eae42 Issue introduced in 3.3 with commit d646960f7986fefb460a2b062d5ccc8ccfeacc3a and fixed in 7.2.1 with commit d3d90243393c48146911c67fd3792b549d21d9e6 Issue introduced in 3.3 with commit d646960f7986fefb460a2b062d5ccc8ccfeacc3a and fixed in 7.3-rc1 with commit 95674f506c6376d6722a23144c9acd26609771ed Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80798 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/nfc/llcp_core.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/e6ec76a68dce04884dfeccfe5a5f0e9f67c0ec82 https://git.kernel.org/stable/c/f36cffea24bf3e2cc29a00d4b51dbcadc087d810 https://git.kernel.org/stable/c/a7b9b449f5a5132221fff6adc11a9431ab8cd914 https://git.kernel.org/stable/c/3793d768b40f38bb97265dd5b9a8b8655c4e1b1d https://git.kernel.org/stable/c/eab47618e282602197db287ecbd1b09d356a2515 https://git.kernel.org/stable/c/e969e98410051b1ef8cc318bfe0c7e3f24ec766d https://git.kernel.org/stable/c/ae5f20f5842f440b72d030e3a34fe182dd8eae42 https://git.kernel.org/stable/c/d3d90243393c48146911c67fd3792b549d21d9e6 https://git.kernel.org/stable/c/95674f506c6376d6722a23144c9acd26609771ed