Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80800— nfc: llcp: bound the connect_sn TLV walk to the skb

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于nfc_llcp_connect_sn()函数在解析TLV列表时未正确检查缓冲区边界,可能导致越界读取。

AI Predicted 7.5 Difficulty: Moderate EPSS 0.23% · P15

Possible ATT&CK Techniques 1 AI

T1595 · Active Scanning

Affected Version Matrix 20

VendorProduct Version RangeStatus
Linux Linux d646960f7986fefb460a2b062d5ccc8ccfeacc3a< b2ebdfe3d5b76e91f267a61cbc3f9a0e3f77071e affected
d646960f7986fefb460a2b062d5ccc8ccfeacc3a< e18d044bab6d3d0280639098c3fe6621692cbfe2 affected
d646960f7986fefb460a2b062d5ccc8ccfeacc3a< 65a0ec7783b06068dda6745dd689bf4a91ee64aa affected
d646960f7986fefb460a2b062d5ccc8ccfeacc3a< 1964addc8dd535a05d5d3b55b4d1ac19ae31aa65 affected
d646960f7986fefb460a2b062d5ccc8ccfeacc3a< 389986fd79e4d43f971a03b512645a1bb63c982f affected
d646960f7986fefb460a2b062d5ccc8ccfeacc3a< e87527b506c40db9af528714b7b1240918eb80fc affected
d646960f7986fefb460a2b062d5ccc8ccfeacc3a< 22e5177ba1196a0b272a6a46c2575eb940a939c4 affected
d646960f7986fefb460a2b062d5ccc8ccfeacc3a< 0cfbdb0e13ab5b0765d77f96af67eb879cbc9736 affected
… +12 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80800

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
nfc: llcp: bound the connect_sn TLV walk to the skb
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: bound the connect_sn TLV walk to the skb Commit 27256cdb290e ("nfc: llcp: bound SNL TLV parsing to the skb and add length checks") fixed the unbounded TLV walk in nfc_llcp_recv_snl(), and commit d8bd2dedbde5 ("nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers") subsequently bounded nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv(). One sibling parser sharing the same pattern remains unbounded: nfc_llcp_connect_sn(). nfc_llcp_connect_sn() walks a TLV list, reading a two-byte header (type, length) followed by length bytes of value, without checking that the two header bytes or the declared length stay within the buffer. It returns a pointer to a service name of up to 255 bytes that may point past the end of the skb; it is subsequently consumed by memcmp() in nfc_llcp_sock_from_sn(). In addition tlv_array_len was computed as "skb->len - LLCP_HEADER_SIZE" in size_t, so a CONNECT/CC frame shorter than the LLCP header underflows to a huge length and the walk runs far past the buffer. nfc_llcp_connect_sn() is reachable from nfc_llcp_recv_connect() and nfc_llcp_recv_cc(), i.e. from received CONNECT and CC PDUs. A nearby NFC device can reach this without authentication; LLCP link activation happens automatically after NFC-DEP, and the nfc_llcp_rx_skb() dispatcher applies no minimum-length guard. Walk the TLV list by pointer, bounded by skb_tail_pointer(skb), and validate each declared length before use, matching the approach already used for nfc_llcp_recv_snl(). Starting the walk at &skb->data[LLCP_HEADER_SIZE] against the tail pointer also removes the size_t underflow for short frames. Found by 0sec automated security-research tooling (https://0sec.ai).
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于nfc_llcp_connect_sn()函数在解析TLV列表时未正确检查缓冲区边界,可能导致越界读取。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux d646960f7986fefb460a2b062d5ccc8ccfeacc3a ~ b2ebdfe3d5b76e91f267a61cbc3f9a0e3f77071e -
Linux Linux 3.3 -

II. Public POCs for CVE-2026-80800

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80800

登录查看更多情报信息。

Patches & Fixes for CVE-2026-80800 (8)

Mailing List Discussions for CVE-2026-80800 (1)

Same Patch Batch · Linux · 2026-09-04 · 156 CVEs total

CVE-2026-80865 bpf: Add missing access_ok call to copy_user_syms
CVE-2026-80856 fuse: fix invalidate lock leak on setattr writeback failure
CVE-2026-80857 fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free
CVE-2026-80858 fuse: publish io-uring queues with release semantics
CVE-2026-80859 fuse: fix missing barrier when checking io-uring readiness
CVE-2026-80860 fuse: fix race between interrupt and resend
CVE-2026-80861 usb: xhci: bail out of setup if the controller is inaccessible
CVE-2026-80862 nvme-tcp: fix usage of page_frag_cache
CVE-2026-80863 RDMA/rxe: Fix OOB in free_rd_atomic_resources()
CVE-2026-80864 RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
CVE-2026-80870 drm/amdkfd: Validate CRIU-restored IDs before idr_alloc
CVE-2026-80874 arm64: dts: renesas: ironhide: Describe inline ECC carveouts
CVE-2026-80873 KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions
CVE-2026-80872 ALSA: hda/tas2781: Cancel async firmware request at unbind
CVE-2026-80871 crypto: xilinx-trng - Remove crypto_rng interface
CVE-2026-80868 ntfs3: Allocate iomap inline_data using alloc_page
CVE-2026-80866 tipc: avoid busy looping in tipc_exit_net()
CVE-2026-80867 alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
CVE-2026-80855 fuse: fix invalidate lock leak on open O_TRUNC DAX failure
CVE-2026-80869 ntfs: bound the attribute-list entry in ntfs_read_inode_mount()

Showing top 20 of 156 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-80800

No comments yet


Leave a comment