Impact
nci_target_auto_activated() appends a target to a fixed buffer without verifying that the array has space left, resulting in a slab out-of-bounds write. The vulnerability can corrupt kernel memory and may lead to privilege escalation or denial of service on systems using the NFC NCI driver.
Affected Systems
The flaw exists in the Linux kernel’s NFC NCI subsystem. Systems running kernel versions that have not yet incorporated the patch are affected; the advisory does not enumerate exact kernel releases.
Risk and Exploitability
No CVSS score is listed and the EPSS metric is unavailable. The vulnerability is not present in CISA KEV, indicating no publicly known active exploits. An attacker would need the ability to send crafted NFC frames or repeatedly trigger discovery on a local NFC device, so the risk is moderate but potentially high in environments with exposed NFC hardware.
OpenCVE Enrichment