Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80798— nfc: llcp: reject PDUs shorter than the LLCP header

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于NFC LLCP接收路径未检查帧长度至少为LLCP头部大小,短PDU导致减法环绕计算,造成越界读取,附近的NFC设备可无需认证触发该漏洞。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.23% · P15

Affected Version Matrix 20

VendorProduct Version RangeStatus
Linux Linux d646960f7986fefb460a2b062d5ccc8ccfeacc3a< e6ec76a68dce04884dfeccfe5a5f0e9f67c0ec82 affected
d646960f7986fefb460a2b062d5ccc8ccfeacc3a< f36cffea24bf3e2cc29a00d4b51dbcadc087d810 affected
d646960f7986fefb460a2b062d5ccc8ccfeacc3a< a7b9b449f5a5132221fff6adc11a9431ab8cd914 affected
d646960f7986fefb460a2b062d5ccc8ccfeacc3a< 3793d768b40f38bb97265dd5b9a8b8655c4e1b1d affected
d646960f7986fefb460a2b062d5ccc8ccfeacc3a< eab47618e282602197db287ecbd1b09d356a2515 affected
d646960f7986fefb460a2b062d5ccc8ccfeacc3a< e969e98410051b1ef8cc318bfe0c7e3f24ec766d affected
d646960f7986fefb460a2b062d5ccc8ccfeacc3a< ae5f20f5842f440b72d030e3a34fe182dd8eae42 affected
d646960f7986fefb460a2b062d5ccc8ccfeacc3a< d3d90243393c48146911c67fd3792b549d21d9e6 affected
… +12 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80798

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
nfc: llcp: reject PDUs shorter than the LLCP header
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: reject PDUs shorter than the LLCP header Every LLCP PDU begins with a two-byte header (DSAP/SSAP + PTYPE), but the receive path never checked that a frame is at least LLCP_HEADER_SIZE bytes before parsing it. nfc_llcp_rx_skb() reads the header via nfc_llcp_ptype()/nfc_llcp_dsap()/ nfc_llcp_ssap(), which dereference pdu->data[0] and pdu->data[1], and a CONNECT or CC PDU then computes tlv_array_len = skb->len - LLCP_HEADER_SIZE; as a size_t and hands it to the TLV walk. When the frame is shorter than the header the subtraction wraps to a huge value and the walk runs far past the buffer, an out-of-bounds read. A nearby NFC device can reach this without authentication; LLCP link activation happens automatically after NFC-DEP. Guard the common receive choke point __nfc_llcp_recv(), shared by both the target (nfc_llcp_data_received()) and initiator (nfc_llcp_recv()) paths, so a short skb is dropped before the rx_work worker parses it. Use pskb_may_pull() rather than a skb->len test so the two header bytes are guaranteed to sit in the skb linear area even for a non-linear skb, matching how the sibling NCI and HCI receive paths validate their headers. Reproduced with a KFENCE out-of-bounds read via /dev/virtual_nci on linux-next. Found by 0sec automated security-research tooling (https://0sec.ai).
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于NFC LLCP接收路径未检查帧长度至少为LLCP头部大小,短PDU导致减法环绕计算,造成越界读取,附近的NFC设备可无需认证触发该漏洞。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux d646960f7986fefb460a2b062d5ccc8ccfeacc3a ~ e6ec76a68dce04884dfeccfe5a5f0e9f67c0ec82 -
Linux Linux 3.3 -

II. Public POCs for CVE-2026-80798

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80798

登录查看更多情报信息。

Patches & Fixes for CVE-2026-80798 (9)

Same Patch Batch · Linux · 2026-09-04 · 156 CVEs total

CVE-2026-80865 bpf: Add missing access_ok call to copy_user_syms
CVE-2026-80856 fuse: fix invalidate lock leak on setattr writeback failure
CVE-2026-80857 fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free
CVE-2026-80858 fuse: publish io-uring queues with release semantics
CVE-2026-80859 fuse: fix missing barrier when checking io-uring readiness
CVE-2026-80860 fuse: fix race between interrupt and resend
CVE-2026-80861 usb: xhci: bail out of setup if the controller is inaccessible
CVE-2026-80862 nvme-tcp: fix usage of page_frag_cache
CVE-2026-80863 RDMA/rxe: Fix OOB in free_rd_atomic_resources()
CVE-2026-80864 RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
CVE-2026-80870 drm/amdkfd: Validate CRIU-restored IDs before idr_alloc
CVE-2026-80874 arm64: dts: renesas: ironhide: Describe inline ECC carveouts
CVE-2026-80873 KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions
CVE-2026-80872 ALSA: hda/tas2781: Cancel async firmware request at unbind
CVE-2026-80871 crypto: xilinx-trng - Remove crypto_rng interface
CVE-2026-80868 ntfs3: Allocate iomap inline_data using alloc_page
CVE-2026-80866 tipc: avoid busy looping in tipc_exit_net()
CVE-2026-80867 alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
CVE-2026-80855 fuse: fix invalidate lock leak on open O_TRUNC DAX failure
CVE-2026-80869 ntfs: bound the attribute-list entry in ntfs_read_inode_mount()

Showing top 20 of 156 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-80798

No comments yet


Leave a comment