« Volver al listado

CVE-2026-80799

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers

nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain three related bugs in their TLV parsing loops:

Both functions are reachable without authentication via nfc_llcp_set_remote_gb() which feeds remote LLCP general bytes directly into nfc_llcp_parse_gb_tlv() with no additional validation.

Fix all three issues by widening offset from u8 to u16 and adding bounds checks for both the TLV header and value field before each access.

Detalles técnicos trazas, registros y código del informe original
1. 'offset' is declared u8 but tlv_array_len is u16. When TLV data
   advances offset past 255 it silently wraps to zero, causing
   infinite loops or double-processing of buffer data.

2. Before reading tlv[0] (type) and tlv[1] (length) there is no
   check that offset+2 <= tlv_array_len. A truncated TLV causes
   an OOB read of one byte past the buffer end.

3. After reading the length field, the value bytes are accessed
   without checking offset+2+length <= tlv_array_len. A crafted
   length=0xFF on a short buffer causes up to 255 bytes of OOB
   read past the buffer end.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80799",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "0be9de2ea01e8d52646e7310a7eef5459cf07ea8",
              "lessThan": "2c1456fe09ab1a5a9fe1d8339ca6d509589b56e1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
              "lessThan": "7f6f3d087c67a4346189ef2c36481455bbc59a74",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
              "lessThan": "9c47d667963542c3cf8e3007b7f10c0904d08238",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
              "lessThan": "a209334ed929941b20810c17c3a507445b0a7c85",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
              "lessThan": "382eaa770335acf4f16a5a55524500f2bb4207df",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
              "lessThan": "2d239590d1845a706304833d40dd6d4fec20ad88",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
              "lessThan": "e84cdfdc4a6c88e8b751144458f2e04e24415a28",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
              "lessThan": "875285a165fd3b402de2ab3be0deb355d6f4caf5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
              "lessThan": "78b20c8eeacd2e44a2d8a4cb5316d3c521d90911",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1deacb5e031e289ca5636f2db4fcae6612c05d34",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "66a1be74230bbe098e651766c9a0cf4038db8442",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.188",
              "lessThan": "5.10.267",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.19.291",
              "lessThan": "4.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.4.251",
              "lessThan": "5.5",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/nfc/llcp_commands.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.267",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.218",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.185",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.154",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.106",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.47",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/nfc/llcp_commands.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:06.637",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2c1456fe09ab1a5a9fe1d8339ca6d509589b56e1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2d239590d1845a706304833d40dd6d4fec20ad88",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/382eaa770335acf4f16a5a55524500f2bb4207df",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/78b20c8eeacd2e44a2d8a4cb5316d3c521d90911",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7f6f3d087c67a4346189ef2c36481455bbc59a74",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/875285a165fd3b402de2ab3be0deb355d6f4caf5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9c47d667963542c3cf8e3007b7f10c0904d08238",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a209334ed929941b20810c17c3a507445b0a7c85",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e84cdfdc4a6c88e8b751144458f2e04e24415a28",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: fix OOB read and u8 offset wrap in TLV parsers\n\nnfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain\nthree related bugs in their TLV parsing loops:\n\n1. 'offset' is declared u8 but tlv_array_len is u16. When TLV data\n   advances offset past 255 it silently wraps to zero, causing\n   infinite loops or double-processing of buffer data.\n\n2. Before reading tlv[0] (type) and tlv[1] (length) there is no\n   check that offset+2 <= tlv_array_len. A truncated TLV causes\n   an OOB read of one byte past the buffer end.\n\n3. After reading the length field, the value bytes are accessed\n   without checking offset+2+length <= tlv_array_len. A crafted\n   length=0xFF on a short buffer causes up to 255 bytes of OOB\n   read past the buffer end.\n\nBoth functions are reachable without authentication via\nnfc_llcp_set_remote_gb() which feeds remote LLCP general bytes\ndirectly into nfc_llcp_parse_gb_tlv() with no additional\nvalidation.\n\nFix all three issues by widening offset from u8 to u16 and adding\nbounds checks for both the TLV header and value field before each\naccess."
    }
  ],
  "lastModified": "2026-09-04T16:18:06.637",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}