PT-2026-94571 · Linux · Linux Kernel

CVE-2026-90223

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the nfc llcp recv snl() function where the SNL TLV list is processed using an offset and length pair derived from skb->len without bounding reads to the actual socket buffer (skb) data. This leads to several problems: for short frames, the TLV length can underflow; the per-TLV header can be read without verifying that two bytes remain; and a declared TLV length can exceed the buffer boundary. Specifically, an SDREQ with a length of 0 causes a size t underflow when calculating service name len, resulting in an out-of-bounds read during strncmp() or nfc llcp sock from sn(). Similarly, the SDRES case can read data without a length check. A nearby NFC device can trigger this behavior without authentication, as LLCP link activation occurs automatically after NFC-DEP.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102746
CVE-2026-90223
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel