PT-2026-94569 · Linux · Linux Kernel
CVE-2026-90221
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the NFC NCI component where the functions
nci core init rsp packet v1() and nci core init rsp packet v2() parse the CORE INIT RSP packet without verifying if the socket buffer (skb) contains sufficient data. A malformed response can specify a large num supported rf interfaces value while providing insufficient data, leading to the reading of uninitialized slab memory. This uninitialized value is subsequently used in nci init complete req(), which can trigger a KMSAN uninit-value warning. KMSAN (Kernel Memory Sanitizer) is a tool used to detect the use of uninitialized memory in the kernel.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel