CVE-2026-80801

Source
https://cve.org/CVERecord?id=CVE-2026-80801
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80801.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80801
Downstream
Published
2026-09-04T15:13:15.263Z
Modified
2026-09-06T03:46:47.257277294Z
Summary
nfc: microread: validate target discovery payload lengths
Details

In the Linux kernel, the following vulnerability has been resolved:

nfc: microread: validate target discovery payload lengths

microreadtargetdiscovered() parses target discovery payloads from skb->data according to the HCI gate. The fixed field offsets and UID copies were checked only against the destination nfc_target buffers, not against the actual skb length.

Validate that each gate-specific payload contains the fixed fields and UID bytes before reading or copying them.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80801.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cfad1ba87150e198be9ea32367a24e500e59de2c
Fixed
c6de4241f2efbbab286efbb84a9c7190298b3052
Fixed
92a6f0201bb68391b5eba1b3f330af007d7323b6
Fixed
cb298672282421159e53ab311fe49d204c8a52da
Fixed
18f02354ed229b8e4561b580812d026e7eb29c85
Fixed
e6397fe7b8b5ef18e051f49612d40ff476c5f7d9
Fixed
d0902a7c454326c6384c614226ab8987f3fd425d
Fixed
dabfa26a208e56f4d8dbf26fddc48f188bdb0649
Fixed
953963b9ac5eecbb316617d337bfaa3d731e3c5e
Fixed
25519469972ef57c3edb1805dabd6c5612b90211

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80801.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.9.0
Fixed
5.10.267
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.218
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.185
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.154
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.106
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.47
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.11
Type
ECOSYSTEM
Events
Introduced
7.2.0
Fixed
7.2.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80801.json"