PT-2026-85643 · Linux · Linux

CVE-2026-80802

·

Published

2026-09-04

·

Updated

2026-09-04

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
nfc: fdp: bound the device-reported read length and fix an skb leak
fdp nci i2c read() takes the next packet length from two device-supplied bytes and never validates it. The value is a u16 used as the i2c master recv() count into a 261-byte on-stack buffer: a malicious, counterfeit or malfunctioning controller (or an i2c bus interposer) can drive it far past the buffer for a stack out-of-bounds write that clobbers the canary and return address, or below the minimum frame size (directly, or by truncating the computed sum) so the header/LRC strip and the next length read run past a short receive. Reject a length outside [FDP NCI I2C MIN PAYLOAD, FDP NCI I2C MAX PAYLOAD], as a corrupted packet already is, and force resynchronization.
The same loop allocates one data skb per iteration and assumes a length packet followed by a data packet; a device that sends two data packets in one call leaks the first skb when the second allocation overwrites it. Free a previously allocated skb before allocating the next.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-80802

Affected Products

Linux