« Volver al listado

CVE-2026-90221

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing

nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() parse the CORE_INIT_RSP packet without validating that the skb contains enough data. A malformed response (e.g. injected via virtual_ncidev) can declare a large num_supported_rf_interfaces while providing insufficient data, causing reads of uninitialized slab memory. This is later used in nci_init_complete_req(), triggering a KMSAN uninit-value warning.

Add skb length checks before accessing packet fields: - Validate the skb has at least 1 byte for the status field. - Validate the skb can hold the fixed-size header before parsing. - In v2, bounds-check each variable-length rf_interface entry and its extension parameters within the parsing loop. - In v1, verify the skb is large enough for both the variable-length rf_interfaces array and the trailing rsp_2 structure.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90221",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "bcd684aace34fedbd473fbd9b21ed06b0c2d2212",
              "lessThan": "baed3fdf6ed2195c56f25ae18a086b938dcd3983",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bcd684aace34fedbd473fbd9b21ed06b0c2d2212",
              "lessThan": "2f434478771a4ebdd535033561c0590bcde39753",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bcd684aace34fedbd473fbd9b21ed06b0c2d2212",
              "lessThan": "5487f04c1ccbfa15aa6e531eb1ec9c9ec9c7bf31",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bcd684aace34fedbd473fbd9b21ed06b0c2d2212",
              "lessThan": "bbe68e8249e2c76d65adfd9224fa95f1ca0fbe4e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bcd684aace34fedbd473fbd9b21ed06b0c2d2212",
              "lessThan": "4f0483bbcdaccc9d4aee30df7351863334cecfa7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bcd684aace34fedbd473fbd9b21ed06b0c2d2212",
              "lessThan": "7d44b897bff84edcd4814899314d661ad4956a8e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bcd684aace34fedbd473fbd9b21ed06b0c2d2212",
              "lessThan": "d56575a2595ee1f597f39e8a1cfb67ed3501678d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/nfc/nci/rsp.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/nfc/nci/rsp.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:17.550",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2f434478771a4ebdd535033561c0590bcde39753",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4f0483bbcdaccc9d4aee30df7351863334cecfa7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5487f04c1ccbfa15aa6e531eb1ec9c9ec9c7bf31",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7d44b897bff84edcd4814899314d661ad4956a8e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/baed3fdf6ed2195c56f25ae18a086b938dcd3983",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bbe68e8249e2c76d65adfd9224fa95f1ca0fbe4e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d56575a2595ee1f597f39e8a1cfb67ed3501678d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing\n\nnci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() parse\nthe CORE_INIT_RSP packet without validating that the skb contains\nenough data. A malformed response (e.g. injected via virtual_ncidev)\ncan declare a large num_supported_rf_interfaces while providing\ninsufficient data, causing reads of uninitialized slab memory. This\nis later used in nci_init_complete_req(), triggering a KMSAN\nuninit-value warning.\n\nAdd skb length checks before accessing packet fields:\n- Validate the skb has at least 1 byte for the status field.\n- Validate the skb can hold the fixed-size header before parsing.\n- In v2, bounds-check each variable-length rf_interface entry and its\n  extension parameters within the parsing loop.\n- In v1, verify the skb is large enough for both the variable-length\n  rf_interfaces array and the trailing rsp_2 structure."
    }
  ],
  "lastModified": "2026-09-17T17:17:17.550",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}