PT-2026-94569 · Linux · Linux Kernel

CVE-2026-90221

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the NFC NCI component where the functions nci core init rsp packet v1() and nci core init rsp packet v2() parse the CORE INIT RSP packet without verifying if the socket buffer (skb) contains sufficient data. A malformed response can specify a large num supported rf interfaces value while providing insufficient data, leading to the reading of uninitialized slab memory. This uninitialized value is subsequently used in nci init complete req(), which can trigger a KMSAN uninit-value warning. KMSAN (Kernel Memory Sanitizer) is a tool used to detect the use of uninitialized memory in the kernel.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102122
CVE-2026-90221
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel