PatchSiren cyber security CVE debrief
CVE-2026-80794 Linux CVE debrief
A vulnerability in the Linux kernel's NFC (Near Field Communication) subsystem has been resolved. The issue involves uninitialized variables in the RF discover and activated NTF handlers, which could lead to exposure of sensitive information. The vulnerability is tracked as CVE-2026-80794 and was published on 2026-09-04T16:18:05.767Z. This vulnerability affects systems using NFC functionality in the Linux kernel, particularly those with unpatched versions. Defenders should assess their exposure and prioritize patching to prevent potential information exposure.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-04
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-09-04
- Advisory updated
- 2026-09-04
Who should care
Defenders responsible for Linux kernel-based systems, particularly those using NFC functionality, should assess their exposure and prioritize patching to prevent potential information exposure.
Why it matters
CVE-2026-80794 is a vulnerability in the Linux kernel's NFC subsystem that could lead to information exposure due to uninitialized variables. Defenders should prioritize patching and monitoring to prevent potential exploitation.
- Potential exposure of sensitive information
- Verification of patch application required
- Monitoring system logs for exploitation attempts necessary
Technical summary
The vulnerability is caused by uninitialized variables in the RF discover and activated NTF handlers of the Linux kernel's NFC subsystem. This could lead to exposure of sensitive information when processing certain NFC notifications. The issue arises from the use of uninitialized variables in the nci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() functions, which parse notifications into on-stack structs that are not initialized. The RF technology-specific parameters are only extracted when rf_tech_specific_params_len is non-zero, leaving the rf_tech_specific_params union uninitialized when no technology-specific parameters are present.
Defensive priority
Defenders should prioritize verifying and applying the patch to the Linux kernel's NFC subsystem to prevent potential information exposure.
Recommended defensive actions
- Verify and apply the patch to the Linux kernel's NFC subsystem
- Review and update NFC-related configurations and settings
- Monitor system logs for potential exploitation attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability was discovered in the Linux kernel's NFC subsystem, specifically in the RF discover and activated NTF handlers. The issue arises from uninitialized variables, which could lead to exposure of sensitive information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-80794 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-80794
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-80794 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80794
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0d4b5cfab6891a5ca0f6aef209beebba4bd7c095
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1007a6b429d756513abd25bd00290908f2e89a4a
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4bda9ef8392710f21e99027467f3f4afdfb5c99a
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5bd00c0e1470d90d77a7c60242854257ddf14e00
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7086dab72b3ed95df96842801e10e935cfeb27a3
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7489f59d1ea2d3298aa41de7baf193e5e6e132f6
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8cbe06c1e699c0a165dae5093a2550e65f914818
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d6f743d3d388913135681cde051c08823730194f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.