NFC LLCP TLV parsers: missing bounds checks and offset wrap
Fixed in: Linux 7.3-rc1; stable fixes include 7.2.1, 7.1.11, 6.18.47, 6.12.106, 6.6.154, 6.1.185, 5.15.218 and 5.10.267; consult the Linux CNA record for affected ranges and other branches.
details
- Finding IDs
- F-TORVALDS-LINUX-NFC-001
- CVE
- CVE-2026-80799
- Status
- patched
- Fixed in
- Linux 7.3-rc1; stable fixes include 7.2.1, 7.1.11, 6.18.47, 6.12.106, 6.6.154, 6.1.185, 5.15.218 and 5.10.267; consult the Linux CNA record for affected ranges and other branches.
- Recorded credit
- Earlier public report and proposed patch: Oleh Konko / 1seal. Merged patch author: Muhammad Bilal. No reporter credit in the Linux CNA record.
- Disclosure date
- Note
- Published CVE-2026-80799 matches the LLCP parser checks in the earlier public patch quoted at https://lists.openwall.net/netdev/2026/03/26/440. Final merged fix: https://kernel.googlesource.com/pub/scm/linux/kernel/git/netdev/net/+/78b20c8eeacd2e44a2d8a4cb5316d3c521d90911. This records the earlier contribution separately from the final patch; sole discovery, final patch authorship and causation by our report are not claimed. CNA publication: 2026-09-04. No CNA CVSS assessment is recorded.
- CVE registry state
- PUBLISHED
- CVE state checked
F-TORVALDS-LINUX-NFC-001: Memory safety. The LLCP TLV parsers read headers and payloads without required buffer bounds checks. Reviewed 7 Oct 2026. Mechanism assessed by 1seal.
Mechanism source for F-TORVALDS-LINUX-NFC-001
Security area (1seal assessment): Memory safety. The LLCP TLV parsers read headers and payloads without required buffer bounds checks. Reviewed 7 Oct 2026.