« Volver al listado

CVE-2026-80823

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

nfc: st21nfca: validate ATR_REQ length against the received frame

st21nfca_tm_recv_atr_req() checks that the received ATR_REQ frame is at least ST21NFCA_ATR_REQ_MIN_SIZE and that the self-declared atr_req->length is at least sizeof(struct st21nfca_atr_req), but never checks that atr_req->length does not exceed the actual received length (skb->len).

st21nfca_tm_send_atr_res() then trusts the declared length:

so an RF peer that sends a short frame but sets atr_req->length larger than the frame makes gb_len exceed the general bytes actually present, and the memcpy reads out of bounds past the received skb.

Leer descripción completaMostrar menos

Those bytes are placed in the ATR_RES and sent back to the peer (kernel-memory disclosure to a proximity attacker); a larger declared length is an out-of-bounds read (DoS).

Reject frames whose declared length exceeds the received length. The adjacent nfc_tm_activated() path in the same function already derives its general-bytes length from skb->len rather than the declared field.

Found by 0sec (https://0sec.ai) using automated source analysis; the missing bound is evident from source. Compile-tested.

Detalles técnicos trazas, registros y código del informe original
	gb_len = atr_req->length - sizeof(struct st21nfca_atr_req);
	...
	memcpy(atr_res->gbi, atr_req->gbi, gb_len);

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80823",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
              "lessThan": "785df00bb3ae3206674a43284eb06dac575b5c64",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
              "lessThan": "2c1ad291f4cdc357f9527b688c6fda9c6ffa7890",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
              "lessThan": "dd26d30f40c43ad9cfe2f25c6ea0ead1dd51d5aa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
              "lessThan": "9635507fe82949e429b3cd938876a9917125b151",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
              "lessThan": "0f344944c506b4f02d2b098489f7268b438c369e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
              "lessThan": "bfcca5f42c9aa4eadef1e5fe7bb23783d7fcc96d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
              "lessThan": "304f5b414f4051d324b8c4a3ab0e79f7dc7e150e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
              "lessThan": "f33cecf69095c43be88567fef92b180b858f7369",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
              "lessThan": "5cdcca5d62a66eda6b774110a44cba67bc1a8d1d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/nfc/st21nfca/dep.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.267",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.218",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.185",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.154",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.106",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.47",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/nfc/st21nfca/dep.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:10.080",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0f344944c506b4f02d2b098489f7268b438c369e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2c1ad291f4cdc357f9527b688c6fda9c6ffa7890",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/304f5b414f4051d324b8c4a3ab0e79f7dc7e150e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5cdcca5d62a66eda6b774110a44cba67bc1a8d1d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/785df00bb3ae3206674a43284eb06dac575b5c64",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9635507fe82949e429b3cd938876a9917125b151",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bfcca5f42c9aa4eadef1e5fe7bb23783d7fcc96d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dd26d30f40c43ad9cfe2f25c6ea0ead1dd51d5aa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f33cecf69095c43be88567fef92b180b858f7369",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: st21nfca: validate ATR_REQ length against the received frame\n\nst21nfca_tm_recv_atr_req() checks that the received ATR_REQ frame is at\nleast ST21NFCA_ATR_REQ_MIN_SIZE and that the self-declared atr_req->length\nis at least sizeof(struct st21nfca_atr_req), but never checks that\natr_req->length does not exceed the actual received length (skb->len).\n\nst21nfca_tm_send_atr_res() then trusts the declared length:\n\n\tgb_len = atr_req->length - sizeof(struct st21nfca_atr_req);\n\t...\n\tmemcpy(atr_res->gbi, atr_req->gbi, gb_len);\n\nso an RF peer that sends a short frame but sets atr_req->length larger\nthan the frame makes gb_len exceed the general bytes actually present,\nand the memcpy reads out of bounds past the received skb. Those bytes are\nplaced in the ATR_RES and sent back to the peer (kernel-memory disclosure\nto a proximity attacker); a larger declared length is an out-of-bounds\nread (DoS).\n\nReject frames whose declared length exceeds the received length. The\nadjacent nfc_tm_activated() path in the same function already derives its\ngeneral-bytes length from skb->len rather than the declared field.\n\nFound by 0sec (https://0sec.ai) using automated source analysis; the\nmissing bound is evident from source. Compile-tested."
    }
  ],
  "lastModified": "2026-09-04T16:18:10.080",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}