1sealsemantic last-mile verification

Research / Finding

NFC LLCP TLV parsers: missing bounds checks and offset wrap

F-TORVALDS-LINUX-NFC-001

Public snapshot: 7 Oct 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

—score not recorded
CVE-2026-80799CVEtorvalds/linux

NFC LLCP TLV parsers: missing bounds checks and offset wrap

Fixed in: Linux 7.3-rc1; stable fixes include 7.2.1, 7.1.11, 6.18.47, 6.12.106, 6.6.154, 6.1.185, 5.15.218 and 5.10.267; consult the Linux CNA record for affected ranges and other branches.

patched
details
Finding IDs
F-TORVALDS-LINUX-NFC-001
CVE
CVE-2026-80799
Status
patched
Fixed in
Linux 7.3-rc1; stable fixes include 7.2.1, 7.1.11, 6.18.47, 6.12.106, 6.6.154, 6.1.185, 5.15.218 and 5.10.267; consult the Linux CNA record for affected ranges and other branches.
Recorded credit
Earlier public report and proposed patch: Oleh Konko / 1seal. Merged patch author: Muhammad Bilal. No reporter credit in the Linux CNA record.
Disclosure date
Note
Published CVE-2026-80799 matches the LLCP parser checks in the earlier public patch quoted at https://lists.openwall.net/netdev/2026/03/26/440. Final merged fix: https://kernel.googlesource.com/pub/scm/linux/kernel/git/netdev/net/+/78b20c8eeacd2e44a2d8a4cb5316d3c521d90911. This records the earlier contribution separately from the final patch; sole discovery, final patch authorship and causation by our report are not claimed. CNA publication: 2026-09-04. No CNA CVSS assessment is recorded.
CVE registry state
PUBLISHED
CVE state checked

F-TORVALDS-LINUX-NFC-001: Memory safety. The LLCP TLV parsers read headers and payloads without required buffer bounds checks. Reviewed 7 Oct 2026. Mechanism assessed by 1seal.

Mechanism source for F-TORVALDS-LINUX-NFC-001

Security area (1seal assessment): Memory safety. The LLCP TLV parsers read headers and payloads without required buffer bounds checks. Reviewed 7 Oct 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.