Description
In the Linux kernel, the following vulnerability has been resolved:

nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing

nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() parse
the CORE_INIT_RSP packet without validating that the skb contains
enough data. A malformed response (e.g. injected via virtual_ncidev)
can declare a large num_supported_rf_interfaces while providing
insufficient data, causing reads of uninitialized slab memory. This
is later used in nci_init_complete_req(), triggering a KMSAN
uninit-value warning.

Add skb length checks before accessing packet fields:
- Validate the skb has at least 1 byte for the status field.
- Validate the skb can hold the fixed-size header before parsing.
- In v2, bounds-check each variable-length rf_interface entry and its
extension parameters within the parsing loop.
- In v1, verify the skb is large enough for both the variable-length
rf_interfaces array and the trailing rsp_2 structure.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service / Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The bug lies in the parsing of the CORE_INIT_RSP packet in the NCI NFC driver where the packet length is not validated before accessing packet fields. A malformed response can cause the kernel to read from uninitialized slab memory, leading to KMSAN uninitialized value warnings and potentially a kernel crash. Because the memory read occurs in the kernel, it can expose kernel data and disrupt system operation, but the description does not indicate privilege escalation. The primary impact is thus a kernel crash and possible kernel data leakage.

Affected Systems

All Linux kernel builds that include the NFC NCI driver are affected. Since no specific kernel version range is provided, the vulnerability applies to every kernel that compiles this driver until the security fix is applied.

Risk and Exploitability

The EPSS score is below 1 % and the issue is not listed in the CISA KEV catalog, indicating a very low public exploitation probability at present. The attack vector appears local or limited to an attacker who can inject malformed NFC responses via the virtual_nci_dev interface; there is no evidence that this can be leveraged for arbitrary code execution or privilege escalation.

Generated by OpenCVE AI on September 20, 2026 at 01:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix for the CORE_INIT_RSP parsing error.
  • If an immediate update is not possible, disable the NFC NCI driver (e.g., by unloading the module or adding it to a blacklist) until the patch is applied.
  • Monitor kernel logs for KMSAN uninitialized value warnings and verify that NFC firmware responses are well‑formed; consider enabling firmware validation if supported.

Generated by OpenCVE AI on September 20, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-457

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() parse the CORE_INIT_RSP packet without validating that the skb contains enough data. A malformed response (e.g. injected via virtual_ncidev) can declare a large num_supported_rf_interfaces while providing insufficient data, causing reads of uninitialized slab memory. This is later used in nci_init_complete_req(), triggering a KMSAN uninit-value warning. Add skb length checks before accessing packet fields: - Validate the skb has at least 1 byte for the status field. - Validate the skb can hold the fixed-size header before parsing. - In v2, bounds-check each variable-length rf_interface entry and its extension parameters within the parsing loop. - In v1, verify the skb is large enough for both the variable-length rf_interfaces array and the trailing rsp_2 structure.
Title nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:32.070Z

Reserved: 2026-09-11T19:38:34.793Z

Link: CVE-2026-90221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:17.550

Modified: 2026-09-17T17:17:17.550

Link: CVE-2026-90221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:30:16Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable