From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1F831477291 for ; Fri, 4 Sep 2026 15:17:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535054; cv=none; b=W3RU0em5So6kAkPsDxViTpP6vuTQ4YrURPEE0IzpeL9kOF7uDe87wj8EV8BI0bw+HMoVeR5fCfJWG3KYYNrCSq22pSsHX0LD6y9WMjepMO3Y1RZ2U/04TsmOyvz2oBjiM9APsvM9DREeN35ePQQ6Ydyg+Z2tiBOKOqdsAcWLYYI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535054; c=relaxed/simple; bh=6F0v7NN4dA/xzMdyHZpW0jtm2Dvn3tqBt9RGah2oh1s=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=S+Z4y9xblCYqeaP1x3Qd0zAt37eU2cc3fz6DYpxlolM2E7fGA8GzQw223bgZ+Hy/uxCwzffpmAbM5eRliT4Zb3xZTRFUgiqwXoCENMMflGDORMx4Ye1P8ppJGeRP9WYEccPOKyd6pO1Xfa76RgCEgE7PHIpGAtsn3yjzvyBliUM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=ABZkeTNj; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="ABZkeTNj" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E921B1F00A3D; Fri, 4 Sep 2026 15:17:31 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788535052; bh=vEthzkGZsAWLReBXtfoP4lo9qdQIODK1gG7w1mufsNA=; h=From:To:Cc:Subject:Date:Reply-To; b=ABZkeTNjmHWEfHdPVhwDlF4y5zIxjvIrvd3CvVj7TkylXQ6TlLIU/lwvtptL5njIR paJ+N1+8xd1XBy/UooVmqbK4aHN/muj7So3hDvYPqEzCAx642DY570AeD76ZhMiey9 v3Ncc1qz9JXHPCPT9ymcd3cr2CSrl9srRS89SmXY= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80802: nfc: fdp: bound the device-reported read length and fix an skb leak Date: Fri, 4 Sep 2026 17:11:41 +0200 Message-ID: <2026090409-CVE-2026-80802-37a0@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4335; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=ZwFVBvCBPLyIHRzOr66tswIMY+YGZCrGs2P6re48QXQ=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmz7vfe/bc60I3/hswvufDGk/obHvA/qsqefu1/Z6RX+ qmQm/9+dcSyMAgyMciKKbJ82cZzdH/FIUUvQ9vTMHNYmUCGMHBxCsBE/r5mmCvy7Vi8afXCtfeP 1S07f+KTyLKAiRwM84sl7jievHDt3GxZroN/1SslVFqenQMA X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: nfc: fdp: bound the device-reported read length and fix an skb leak fdp_nci_i2c_read() takes the next packet length from two device-supplied bytes and never validates it. The value is a u16 used as the i2c_master_recv() count into a 261-byte on-stack buffer: a malicious, counterfeit or malfunctioning controller (or an i2c bus interposer) can drive it far past the buffer for a stack out-of-bounds write that clobbers the canary and return address, or below the minimum frame size (directly, or by truncating the computed sum) so the header/LRC strip and the next length read run past a short receive. Reject a length outside [FDP_NCI_I2C_MIN_PAYLOAD, FDP_NCI_I2C_MAX_PAYLOAD], as a corrupted packet already is, and force resynchronization. The same loop allocates one data skb per iteration and assumes a length packet followed by a data packet; a device that sends two data packets in one call leaks the first skb when the second allocation overwrites it. Free a previously allocated skb before allocating the next. The Linux kernel CVE team has assigned CVE-2026-80802 to this issue. Affected and fixed versions =========================== Issue introduced in 4.4 with commit a06347c04c13e380afce0c9816df51f00b83faf1 and fixed in 5.10.267 with commit d9498ab9a78cb63d78dbe4f221d8cc6c91f285ee Issue introduced in 4.4 with commit a06347c04c13e380afce0c9816df51f00b83faf1 and fixed in 5.15.218 with commit 1fc32327b927a6e2cde086f82575c29880844228 Issue introduced in 4.4 with commit a06347c04c13e380afce0c9816df51f00b83faf1 and fixed in 6.1.185 with commit 8d2c243b79854628ff076c38748c020042f02f57 Issue introduced in 4.4 with commit a06347c04c13e380afce0c9816df51f00b83faf1 and fixed in 6.6.154 with commit fc3c2bd5b1ec6c7cbc8a50e32d9bcec114f25463 Issue introduced in 4.4 with commit a06347c04c13e380afce0c9816df51f00b83faf1 and fixed in 6.12.106 with commit 0d723090645b82c1cb27cfd7ebf81f0e7c96bcae Issue introduced in 4.4 with commit a06347c04c13e380afce0c9816df51f00b83faf1 and fixed in 6.18.47 with commit db7e464b350969c6ea8340de00d9796e5fd5123b Issue introduced in 4.4 with commit a06347c04c13e380afce0c9816df51f00b83faf1 and fixed in 7.1.11 with commit e5eec121f2c3bc4c7022613bedd9121a8aa4c949 Issue introduced in 4.4 with commit a06347c04c13e380afce0c9816df51f00b83faf1 and fixed in 7.2.1 with commit 1aa3fc769b0c45bd19f8dab1697084c2b3f6d706 Issue introduced in 4.4 with commit a06347c04c13e380afce0c9816df51f00b83faf1 and fixed in 7.3-rc1 with commit 7ad21dcfeb5181af0c3ee2608808c0c0a5283aa1 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80802 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/nfc/fdp/i2c.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/d9498ab9a78cb63d78dbe4f221d8cc6c91f285ee https://git.kernel.org/stable/c/1fc32327b927a6e2cde086f82575c29880844228 https://git.kernel.org/stable/c/8d2c243b79854628ff076c38748c020042f02f57 https://git.kernel.org/stable/c/fc3c2bd5b1ec6c7cbc8a50e32d9bcec114f25463 https://git.kernel.org/stable/c/0d723090645b82c1cb27cfd7ebf81f0e7c96bcae https://git.kernel.org/stable/c/db7e464b350969c6ea8340de00d9796e5fd5123b https://git.kernel.org/stable/c/e5eec121f2c3bc4c7022613bedd9121a8aa4c949 https://git.kernel.org/stable/c/1aa3fc769b0c45bd19f8dab1697084c2b3f6d706 https://git.kernel.org/stable/c/7ad21dcfeb5181af0c3ee2608808c0c0a5283aa1