Description
In the Linux kernel, the following vulnerability has been resolved:

nfc: llcp: bound SNL TLV parsing to the skb and add length checks

nfc_llcp_recv_snl() walked the SNL TLV list using a u16 offset/length
pair derived from skb->len, without bounding reads to the actual skb
data. Three problems followed:

- For a short frame (skb->len < LLCP_HEADER_SIZE), tlv_len underflowed.
- The per-TLV header (type, length) was read without checking that two
bytes remained.
- A declared TLV length could run past the end of the buffer, and an
SDREQ with length == 0 made "service_name_len = length - 1" underflow
(size_t), driving an out-of-bounds read in the following strncmp() /
nfc_llcp_sock_from_sn(). The SDRES case likewise read tlv[2]/tlv[3]
without a length check.

A nearby NFC device can reach this without authentication; LLCP link
activation happens automatically after NFC-DEP.

Walk the TLV list by pointer, bounded by skb_tail_pointer() over the
linear skb data, and validate each TLV declared length before use. Add
explicit length checks for SDREQ (>= 1) and SDRES (exactly 2).

Found by 0sec automated security-research tooling (https://0sec.ai).
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-Bounds Read
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from unbounded parsing of Service Name List (SNL) TLVs in the Linux kernel's NFC LLCP implementation. The code walks the TLV list using offsets derived only from the packet length, without validating that the data remains within the actual buffer. This allows crafting of TLVs that trigger length underflows, out-of-bounds reads, and potentially memory corruption. An attacker capable of sending such TLV structures can read kernel memory, potentially leading to information disclosure or, if further exploited, remote code execution. The weakness is a classic example of improper bounds checking.

Affected Systems

All Linux kernel versions that include the vulnerable NFC LLCP code but have not yet incorporated the fix are affected. The patch is applied directly in the kernel source; therefore any kernel release prior to the inclusion of the described commits remains vulnerable. Specific version numbers are not listed in the provided data.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability presents moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation as of available data, and it is not catalogued in CISA KEV. The attack vector is inferred to be an unauthenticated remote device that can communicate over NFC LLCP, as the protocol activates automatically after NFC‑DEP discovery. If exploited, the attacker could obtain kernel memory contents and potentially establish a foothold for further attacks.

Generated by OpenCVE AI on September 20, 2026 at 02:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commits which bound TLV parsing and added length checks.
  • If an immediate kernel upgrade is not possible, apply the specific patch commits (e.g., 02030f95820c and related series) that implement the bounds and length validation to the running kernel source.
  • As a temporary workaround, disable or restrict NFC LLCP services on affected systems to prevent unauthenticated devices from creating LLCP links until the kernel is patched.

Generated by OpenCVE AI on September 20, 2026 at 02:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: bound SNL TLV parsing to the skb and add length checks nfc_llcp_recv_snl() walked the SNL TLV list using a u16 offset/length pair derived from skb->len, without bounding reads to the actual skb data. Three problems followed: - For a short frame (skb->len < LLCP_HEADER_SIZE), tlv_len underflowed. - The per-TLV header (type, length) was read without checking that two bytes remained. - A declared TLV length could run past the end of the buffer, and an SDREQ with length == 0 made "service_name_len = length - 1" underflow (size_t), driving an out-of-bounds read in the following strncmp() / nfc_llcp_sock_from_sn(). The SDRES case likewise read tlv[2]/tlv[3] without a length check. A nearby NFC device can reach this without authentication; LLCP link activation happens automatically after NFC-DEP. Walk the TLV list by pointer, bounded by skb_tail_pointer() over the linear skb data, and validate each TLV declared length before use. Add explicit length checks for SDREQ (>= 1) and SDRES (exactly 2). Found by 0sec automated security-research tooling (https://0sec.ai).
Title nfc: llcp: bound SNL TLV parsing to the skb and add length checks
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:49.876Z

Reserved: 2026-09-11T19:38:34.794Z

Link: CVE-2026-90223

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:17.850

Modified: 2026-09-18T18:17:46.967

Link: CVE-2026-90223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:45:18Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')