PatchSiren cyber security CVE debrief
CVE-2026-80795 Linux CVE debrief
A vulnerability in the Linux kernel's NFC (Near Field Communication) subsystem can lead to an out-of-bounds write when handling auto-activated targets. This issue arises from the lack of bounds checking in the `nci_target_auto_activated()` function, which can cause a slab out-of-bounds write when appending a target to the `ndev->targets` array. The vulnerability can be triggered by an NFCC (NFC Controller) that repeatedly re-runs discovery and reports an auto-activated target.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-04
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-09-04
- Advisory updated
- 2026-09-04
Who should care
Linux kernel developers and maintainers, as well as users of Linux-based systems that use the NFC subsystem, should assess their exposure to this vulnerability and apply the provided patches to fix the issue.
Why it matters
The CVE-2026-80795 vulnerability in the Linux kernel's NFC subsystem can lead to an out-of-bounds write, potentially causing denial of service or elevation of privileges. Linux kernel developers and maintainers should assess their exposure and apply patches to fix the issue.
- Potential for denial of service (DoS) due to out-of-bounds write
- Possible elevation of privileges for attackers
- Need for verification of affected Linux kernel versions
- Remediation priority for Linux kernel developers and maintainers
Technical summary
The `nci_target_auto_activated()` function in the Linux kernel's NFC subsystem does not check if the `ndev->targets` array is full before appending a new target. This can lead to an out-of-bounds write when the array is full, causing a slab out-of-bounds write vulnerability. The vulnerability can be triggered by an NFCC (NFC Controller) that repeatedly re-runs discovery and reports an auto-activated target. Linux kernel developers and maintainers should assess their exposure and apply patches to fix the issue. The fix involves adding a bounds check to prevent the out-of-bounds write. Affected product deployments should be reviewed and updated to prevent exploitation.
Defensive priority
Medium
Recommended defensive actions
- Review and apply the provided kernel patches to fix the vulnerability
- Ensure that the Linux kernel is updated to a version that includes the fix
- Monitor NFC-related logs for potential exploitation attempts
- Verify the NFC subsystem configuration to prevent exploitation
- Conduct a thorough review of the system's exposure to this vulnerability
- Implement compensating controls to mitigate potential impacts
- Track changes to the Linux kernel and NFC subsystem for future updates
Evidence notes
The vulnerability is caused by a missing bounds check in the `nci_target_auto_activated()` function, which allows an attacker to write past the end of the `ndev->targets` array. The issue can be triggered by an NFCC that repeatedly re-runs discovery and reports an auto-activated target.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-80795 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-80795
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-80795 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80795
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0dc59de0075f88404a0f4a2b5233104ef459fbb2
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/129032c0616d83a5e3e304f6ebf88f14ba01e5f7
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/24761d3a5f692df5f7d848caeabcb2afd10917aa
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2f08dbce3b37624ec6b424d759336a99586170ec
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/50e87e1c0e18d791dcd7dccf30f9a2f3e2cf3951
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/94530ffabfca57e9bff1d207106010014cc84032
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ac200079db50af81e6b04d058b33ec92901d8edd
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/afd8605fb43becb892311102844955c3b127fc7e
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.