Impact
The vulnerability allows an attacker to cause the Linux kernel to write beyond the end of a user‑supplied buffer when calling getsockopt on an NFC LLCP socket. The kernel casts the user value to a 32‑bit pointer and always writes four bytes, regardless of the optlen supplied by the caller. If optlen is less than four, the write exceeds the user buffer, violating the getsockopt contract and creating a out‑of‑bounds write that can be abused to execute arbitrary code within the context of the kernel or overwrite critical data.
Affected Systems
All Linux kernel releases that provide a functioning NFC LLCP implementation are affected. No specific kernel version range is given in the advisory, so the issue applies to every build that includes the llcp driver before the patch referenced in the commit logs.
Risk and Exploitability
The risk is high due to the severity of the buffer overflow, but the EPSS score is reported as less than 1 percent indicating low exploitation probability at this time. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would require an attacker to invoke getsockopt on an NFC LLCP socket with an optlen smaller than four bytes, a scenario that can arise from local misuse or potentially from remote clients that can establish and interact with an NFC llcp socket. The attack vector is inferred to be local or remote with access to the llcp interface, and the presence of the exploit would allow the attacker to gain elevated privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA