« Volver al listado

CVE-2026-80795

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

nfc: nci: fix out-of-bounds write in nci_target_auto_activated()

nci_target_auto_activated() appends a target to the fixed-size array ndev->targets[NCI_MAX_DISCOVERED_TARGETS] and increments ndev->n_targets without first checking the array is full; unlike its sibling nci_add_new_target(), which bails out when n_targets already equals NCI_MAX_DISCOVERED_TARGETS.

ndev->n_targets is only cleared by nci_clear_target_list(), so an NFCC that repeatedly re-runs discovery (RF_DISCOVER_RSP, which re-enters NCI_DISCOVERY without clearing the target list) and reports an auto-activated target (RF_INTF_ACTIVATED_NTF) drives n_targets past the limit.

Leer descripción completaMostrar menos

The append then writes a struct nfc_target past the end of the array (a slab out-of-bounds write), and nfc_targets_found() goes on to walk the array with the inflated count:

Guard nci_target_auto_activated() with the same check used by nci_add_new_target().

Detalles técnicos trazas, registros y código del informe original
  BUG: KASAN: slab-out-of-bounds in nci_add_new_protocol+0x94/0x2ac [nci]
  Write of size 2 at addr ffff0000c7299a18 by task kworker/u8:0/12
  Workqueue: nfc0_nci_rx_wq nci_rx_work [nci]
  Call trace:
   nci_add_new_protocol+0x94/0x2ac [nci]
   nci_ntf_packet+0xddc/0x11a0 [nci]
   nci_rx_work+0x15c/0x1e0 [nci]
   process_one_work+0x2dc/0x500
   worker_thread+0x240/0x460
   kthread+0x1c0/0x1d0
   ret_from_fork+0x10/0x20

  The buggy address belongs to the cache kmalloc-2k of size 2048
  The buggy address is located 1024 bytes to the right of
  allocated 1560-byte region [ffff0000c7299000, ffff0000c7299618)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80795",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
              "lessThan": "0dc59de0075f88404a0f4a2b5233104ef459fbb2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
              "lessThan": "94530ffabfca57e9bff1d207106010014cc84032",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
              "lessThan": "afd8605fb43becb892311102844955c3b127fc7e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
              "lessThan": "24761d3a5f692df5f7d848caeabcb2afd10917aa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
              "lessThan": "50e87e1c0e18d791dcd7dccf30f9a2f3e2cf3951",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
              "lessThan": "2f08dbce3b37624ec6b424d759336a99586170ec",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
              "lessThan": "d7083f41c21b30582e91b2e6de4d54dce74f6f9c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
              "lessThan": "129032c0616d83a5e3e304f6ebf88f14ba01e5f7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
              "lessThan": "ac200079db50af81e6b04d058b33ec92901d8edd",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/nfc/nci/ntf.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.4"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.4",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.267",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.218",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.185",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.154",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.106",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.47",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/nfc/nci/ntf.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:06.020",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0dc59de0075f88404a0f4a2b5233104ef459fbb2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/129032c0616d83a5e3e304f6ebf88f14ba01e5f7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/24761d3a5f692df5f7d848caeabcb2afd10917aa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2f08dbce3b37624ec6b424d759336a99586170ec",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/50e87e1c0e18d791dcd7dccf30f9a2f3e2cf3951",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/94530ffabfca57e9bff1d207106010014cc84032",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ac200079db50af81e6b04d058b33ec92901d8edd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/afd8605fb43becb892311102844955c3b127fc7e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d7083f41c21b30582e91b2e6de4d54dce74f6f9c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: fix out-of-bounds write in nci_target_auto_activated()\n\nnci_target_auto_activated() appends a target to the fixed-size array\nndev->targets[NCI_MAX_DISCOVERED_TARGETS] and increments ndev->n_targets\nwithout first checking the array is full; unlike its sibling\nnci_add_new_target(), which bails out when n_targets already equals\nNCI_MAX_DISCOVERED_TARGETS.\n\nndev->n_targets is only cleared by nci_clear_target_list(), so an NFCC\nthat repeatedly re-runs discovery (RF_DISCOVER_RSP, which re-enters\nNCI_DISCOVERY without clearing the target list) and reports an\nauto-activated target (RF_INTF_ACTIVATED_NTF) drives n_targets past the\nlimit. The append then writes a struct nfc_target past the end of the\narray (a slab out-of-bounds write), and nfc_targets_found() goes on to\nwalk the array with the inflated count:\n\n  BUG: KASAN: slab-out-of-bounds in nci_add_new_protocol+0x94/0x2ac [nci]\n  Write of size 2 at addr ffff0000c7299a18 by task kworker/u8:0/12\n  Workqueue: nfc0_nci_rx_wq nci_rx_work [nci]\n  Call trace:\n   nci_add_new_protocol+0x94/0x2ac [nci]\n   nci_ntf_packet+0xddc/0x11a0 [nci]\n   nci_rx_work+0x15c/0x1e0 [nci]\n   process_one_work+0x2dc/0x500\n   worker_thread+0x240/0x460\n   kthread+0x1c0/0x1d0\n   ret_from_fork+0x10/0x20\n\n  The buggy address belongs to the cache kmalloc-2k of size 2048\n  The buggy address is located 1024 bytes to the right of\n  allocated 1560-byte region [ffff0000c7299000, ffff0000c7299618)\n\nGuard nci_target_auto_activated() with the same check used by\nnci_add_new_target()."
    }
  ],
  "lastModified": "2026-09-04T16:18:06.020",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}