Impact
The vulnerability arises from unbounded parsing of Service Name List (SNL) TLVs in the Linux kernel's NFC LLCP implementation. The code walks the TLV list using offsets derived only from the packet length, without validating that the data remains within the actual buffer. This allows crafting of TLVs that trigger length underflows, out-of-bounds reads, and potentially memory corruption. An attacker capable of sending such TLV structures can read kernel memory, potentially leading to information disclosure or, if further exploited, remote code execution. The weakness is a classic example of improper bounds checking.
Affected Systems
All Linux kernel versions that include the vulnerable NFC LLCP code but have not yet incorporated the fix are affected. The patch is applied directly in the kernel source; therefore any kernel release prior to the inclusion of the described commits remains vulnerable. Specific version numbers are not listed in the provided data.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability presents moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation as of available data, and it is not catalogued in CISA KEV. The attack vector is inferred to be an unauthenticated remote device that can communicate over NFC LLCP, as the protocol activates automatically after NFC‑DEP discovery. If exploited, the attacker could obtain kernel memory contents and potentially establish a foothold for further attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA