Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80799— nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于NFC LLCP TLV解析器中偏移量声明为u8导致超过255后环绕为零,且在读取TLV头和值字段前缺少边界检查,可能导致未认证攻击者触发越界读取或无限循环。

AI Predicted 4.5 Difficulty: Moderate EPSS 0.23% · P15

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 25

VendorProduct Version RangeStatus
Linux Linux 0be9de2ea01e8d52646e7310a7eef5459cf07ea8< 2c1456fe09ab1a5a9fe1d8339ca6d509589b56e1 affected
3df40eb3a2ea58bf404a38f15a7a2768e4762cb0< 7f6f3d087c67a4346189ef2c36481455bbc59a74 affected
3df40eb3a2ea58bf404a38f15a7a2768e4762cb0< 9c47d667963542c3cf8e3007b7f10c0904d08238 affected
3df40eb3a2ea58bf404a38f15a7a2768e4762cb0< a209334ed929941b20810c17c3a507445b0a7c85 affected
3df40eb3a2ea58bf404a38f15a7a2768e4762cb0< 382eaa770335acf4f16a5a55524500f2bb4207df affected
3df40eb3a2ea58bf404a38f15a7a2768e4762cb0< 2d239590d1845a706304833d40dd6d4fec20ad88 affected
3df40eb3a2ea58bf404a38f15a7a2768e4762cb0< e84cdfdc4a6c88e8b751144458f2e04e24415a28 affected
3df40eb3a2ea58bf404a38f15a7a2768e4762cb0< 875285a165fd3b402de2ab3be0deb355d6f4caf5 affected
… +17 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80799

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain three related bugs in their TLV parsing loops: 1. 'offset' is declared u8 but tlv_array_len is u16. When TLV data advances offset past 255 it silently wraps to zero, causing infinite loops or double-processing of buffer data. 2. Before reading tlv[0] (type) and tlv[1] (length) there is no check that offset+2 <= tlv_array_len. A truncated TLV causes an OOB read of one byte past the buffer end. 3. After reading the length field, the value bytes are accessed without checking offset+2+length <= tlv_array_len. A crafted length=0xFF on a short buffer causes up to 255 bytes of OOB read past the buffer end. Both functions are reachable without authentication via nfc_llcp_set_remote_gb() which feeds remote LLCP general bytes directly into nfc_llcp_parse_gb_tlv() with no additional validation. Fix all three issues by widening offset from u8 to u16 and adding bounds checks for both the TLV header and value field before each access.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于NFC LLCP TLV解析器中偏移量声明为u8导致超过255后环绕为零,且在读取TLV头和值字段前缺少边界检查,可能导致未认证攻击者触发越界读取或无限循环。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 0be9de2ea01e8d52646e7310a7eef5459cf07ea8 ~ 2c1456fe09ab1a5a9fe1d8339ca6d509589b56e1 -
Linux Linux 5.15 -

II. Public POCs for CVE-2026-80799

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80799

登录查看更多情报信息。

Patches & Fixes for CVE-2026-80799 (8)

Other References for CVE-2026-80799 (1)

Same Patch Batch · Linux · 2026-09-04 · 156 CVEs total

CVE-2026-80865 bpf: Add missing access_ok call to copy_user_syms
CVE-2026-80856 fuse: fix invalidate lock leak on setattr writeback failure
CVE-2026-80857 fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free
CVE-2026-80858 fuse: publish io-uring queues with release semantics
CVE-2026-80859 fuse: fix missing barrier when checking io-uring readiness
CVE-2026-80860 fuse: fix race between interrupt and resend
CVE-2026-80861 usb: xhci: bail out of setup if the controller is inaccessible
CVE-2026-80862 nvme-tcp: fix usage of page_frag_cache
CVE-2026-80863 RDMA/rxe: Fix OOB in free_rd_atomic_resources()
CVE-2026-80864 RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
CVE-2026-80870 drm/amdkfd: Validate CRIU-restored IDs before idr_alloc
CVE-2026-80874 arm64: dts: renesas: ironhide: Describe inline ECC carveouts
CVE-2026-80873 KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions
CVE-2026-80872 ALSA: hda/tas2781: Cancel async firmware request at unbind
CVE-2026-80871 crypto: xilinx-trng - Remove crypto_rng interface
CVE-2026-80868 ntfs3: Allocate iomap inline_data using alloc_page
CVE-2026-80866 tipc: avoid busy looping in tipc_exit_net()
CVE-2026-80867 alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
CVE-2026-80855 fuse: fix invalidate lock leak on open O_TRUNC DAX failure
CVE-2026-80869 ntfs: bound the attribute-list entry in ntfs_read_inode_mount()

Showing top 20 of 156 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-80799

No comments yet


Leave a comment