PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-80795 Linux CVE debrief

A vulnerability in the Linux kernel's NFC (Near Field Communication) subsystem can lead to an out-of-bounds write when handling auto-activated targets. This issue arises from the lack of bounds checking in the `nci_target_auto_activated()` function, which can cause a slab out-of-bounds write when appending a target to the `ndev->targets` array. The vulnerability can be triggered by an NFCC (NFC Controller) that repeatedly re-runs discovery and reports an auto-activated target.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-04
Original CVE updated
2026-09-04
Advisory published
2026-09-04
Advisory updated
2026-09-04

Who should care

Linux kernel developers and maintainers, as well as users of Linux-based systems that use the NFC subsystem, should assess their exposure to this vulnerability and apply the provided patches to fix the issue.

Why it matters

The CVE-2026-80795 vulnerability in the Linux kernel's NFC subsystem can lead to an out-of-bounds write, potentially causing denial of service or elevation of privileges. Linux kernel developers and maintainers should assess their exposure and apply patches to fix the issue.

  • Potential for denial of service (DoS) due to out-of-bounds write
  • Possible elevation of privileges for attackers
  • Need for verification of affected Linux kernel versions
  • Remediation priority for Linux kernel developers and maintainers

Technical summary

The `nci_target_auto_activated()` function in the Linux kernel's NFC subsystem does not check if the `ndev->targets` array is full before appending a new target. This can lead to an out-of-bounds write when the array is full, causing a slab out-of-bounds write vulnerability. The vulnerability can be triggered by an NFCC (NFC Controller) that repeatedly re-runs discovery and reports an auto-activated target. Linux kernel developers and maintainers should assess their exposure and apply patches to fix the issue. The fix involves adding a bounds check to prevent the out-of-bounds write. Affected product deployments should be reviewed and updated to prevent exploitation.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the provided kernel patches to fix the vulnerability
  • Ensure that the Linux kernel is updated to a version that includes the fix
  • Monitor NFC-related logs for potential exploitation attempts
  • Verify the NFC subsystem configuration to prevent exploitation
  • Conduct a thorough review of the system's exposure to this vulnerability
  • Implement compensating controls to mitigate potential impacts
  • Track changes to the Linux kernel and NFC subsystem for future updates

Evidence notes

The vulnerability is caused by a missing bounds check in the `nci_target_auto_activated()` function, which allows an attacker to write past the end of the `ndev->targets` array. The issue can be triggered by an NFCC that repeatedly re-runs discovery and reports an auto-activated target.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-80795 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-80795

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-80795 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80795

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0dc59de0075f88404a0f4a2b5233104ef459fbb2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/129032c0616d83a5e3e304f6ebf88f14ba01e5f7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/24761d3a5f692df5f7d848caeabcb2afd10917aa

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2f08dbce3b37624ec6b424d759336a99586170ec

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/50e87e1c0e18d791dcd7dccf30f9a2f3e2cf3951

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/94530ffabfca57e9bff1d207106010014cc84032

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ac200079db50af81e6b04d058b33ec92901d8edd

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/afd8605fb43becb892311102844955c3b127fc7e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.