PT-2026-94571 · Linux · Linux Kernel
CVE-2026-90223
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
nfc llcp recv snl() function where the SNL TLV list is processed using an offset and length pair derived from skb->len without bounding reads to the actual socket buffer (skb) data. This leads to several problems: for short frames, the TLV length can underflow; the per-TLV header can be read without verifying that two bytes remain; and a declared TLV length can exceed the buffer boundary. Specifically, an SDREQ with a length of 0 causes a size t underflow when calculating service name len, resulting in an out-of-bounds read during strncmp() or nfc llcp sock from sn(). Similarly, the SDRES case can read data without a length check. A nearby NFC device can trigger this behavior without authentication, as LLCP link activation occurs automatically after NFC-DEP.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel