nfc: microread: validate target discovery payload lengths

Summary

CVECVE-2026-80801
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-04 16:18:06 UTC
Updated2026-09-04 16:18:06 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: nfc: microread: validate target discovery payload lengths microread_target_discovered() parses target discovery payloads from skb->data according to the HCI gate. The fixed field offsets and UID copies were checked only against the destination nfc_target buffers, not against the actual skb length. Validate that each gate-specific payload contains the fixed fields and UID bytes before reading or copying them.

Risk And Classification

EPSS: 0.001950000 probability, percentile 0.092720000 (date 2026-09-05)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected cfad1ba87150e198be9ea32367a24e500e59de2c c6de4241f2efbbab286efbb84a9c7190298b3052 git Not specified
CNA Linux Linux affected cfad1ba87150e198be9ea32367a24e500e59de2c 92a6f0201bb68391b5eba1b3f330af007d7323b6 git Not specified
CNA Linux Linux affected cfad1ba87150e198be9ea32367a24e500e59de2c cb298672282421159e53ab311fe49d204c8a52da git Not specified
CNA Linux Linux affected cfad1ba87150e198be9ea32367a24e500e59de2c 18f02354ed229b8e4561b580812d026e7eb29c85 git Not specified
CNA Linux Linux affected cfad1ba87150e198be9ea32367a24e500e59de2c e6397fe7b8b5ef18e051f49612d40ff476c5f7d9 git Not specified
CNA Linux Linux affected cfad1ba87150e198be9ea32367a24e500e59de2c d0902a7c454326c6384c614226ab8987f3fd425d git Not specified
CNA Linux Linux affected cfad1ba87150e198be9ea32367a24e500e59de2c dabfa26a208e56f4d8dbf26fddc48f188bdb0649 git Not specified
CNA Linux Linux affected cfad1ba87150e198be9ea32367a24e500e59de2c 953963b9ac5eecbb316617d337bfaa3d731e3c5e git Not specified
CNA Linux Linux affected cfad1ba87150e198be9ea32367a24e500e59de2c 25519469972ef57c3edb1805dabd6c5612b90211 git Not specified
CNA Linux Linux affected 3.9 Not specified
CNA Linux Linux unaffected 3.9 semver Not specified
CNA Linux Linux unaffected 5.10.267 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.218 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.185 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.154 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.106 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.47 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.11 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2.1 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/d0902a7c454326c6384c614226ab8987f3fd425d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c6de4241f2efbbab286efbb84a9c7190298b3052 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/92a6f0201bb68391b5eba1b3f330af007d7323b6 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/25519469972ef57c3edb1805dabd6c5612b90211 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/953963b9ac5eecbb316617d337bfaa3d731e3c5e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e6397fe7b8b5ef18e051f49612d40ff476c5f7d9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/18f02354ed229b8e4561b580812d026e7eb29c85 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/dabfa26a208e56f4d8dbf26fddc48f188bdb0649 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/cb298672282421159e53ab311fe49d204c8a52da 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report