Impact
The bug lies in the parsing of the CORE_INIT_RSP packet in the NCI NFC driver where the packet length is not validated before accessing packet fields. A malformed response can cause the kernel to read from uninitialized slab memory, leading to KMSAN uninitialized value warnings and potentially a kernel crash. Because the memory read occurs in the kernel, it can expose kernel data and disrupt system operation, but the description does not indicate privilege escalation. The primary impact is thus a kernel crash and possible kernel data leakage.
Affected Systems
All Linux kernel builds that include the NFC NCI driver are affected. Since no specific kernel version range is provided, the vulnerability applies to every kernel that compiles this driver until the security fix is applied.
Risk and Exploitability
The EPSS score is below 1 % and the issue is not listed in the CISA KEV catalog, indicating a very low public exploitation probability at present. The attack vector appears local or limited to an attacker who can inject malformed NFC responses via the virtual_nci_dev interface; there is no evidence that this can be leveraged for arbitrary code execution or privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA