Description
In the Linux kernel, the following vulnerability has been resolved:

nfc: llcp: avoid userspace overflow on invalid optlen

nfc_llcp_getsockopt() casts optval to (u32 __user *) for put_user(), so
the kernel always stores 4 bytes regardless of the caller-supplied
optlen. The existing min_t(u32, len, sizeof(u32)) only clamps the length
reported back to userspace; it does not constrain the store. A call with
optlen < 4 therefore writes past the user buffer, violating the
getsockopt(2) contract for all five supported optnames.

Reject any call with optlen < sizeof(u32) up front. 'len' is int, so a
plain size comparison would promote a negative optlen to size_t and slip
past the check; an explicit 'len < 0' test is added first to catch
negative values before the size compare.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Out‑of‑bounds write potentially leading to arbitrary code execution
Action: Apply Kernel Patch
AI Analysis

Impact

The vulnerability allows an attacker to cause the Linux kernel to write beyond the end of a user‑supplied buffer when calling getsockopt on an NFC LLCP socket. The kernel casts the user value to a 32‑bit pointer and always writes four bytes, regardless of the optlen supplied by the caller. If optlen is less than four, the write exceeds the user buffer, violating the getsockopt contract and creating a out‑of‑bounds write that can be abused to execute arbitrary code within the context of the kernel or overwrite critical data.

Affected Systems

All Linux kernel releases that provide a functioning NFC LLCP implementation are affected. No specific kernel version range is given in the advisory, so the issue applies to every build that includes the llcp driver before the patch referenced in the commit logs.

Risk and Exploitability

The risk is high due to the severity of the buffer overflow, but the EPSS score is reported as less than 1 percent indicating low exploitation probability at this time. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would require an attacker to invoke getsockopt on an NFC LLCP socket with an optlen smaller than four bytes, a scenario that can arise from local misuse or potentially from remote clients that can establish and interact with an NFC llcp socket. The attack vector is inferred to be local or remote with access to the llcp interface, and the presence of the exploit would allow the attacker to gain elevated privileges.

Generated by OpenCVE AI on September 19, 2026 at 15:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the patch demonstrated in the trusted commits
  • If a kernel upgrade is not possible, disable the NFC llcp driver using kernel configuration or sysctl configuration such that no llcp sockets can be created
  • Ensure that any application using NFC llcp socket interfaces checks optlen against the required minimum before performing getsockopt calls, as a defensive practice

Generated by OpenCVE AI on September 19, 2026 at 15:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-788

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: avoid userspace overflow on invalid optlen nfc_llcp_getsockopt() casts optval to (u32 __user *) for put_user(), so the kernel always stores 4 bytes regardless of the caller-supplied optlen. The existing min_t(u32, len, sizeof(u32)) only clamps the length reported back to userspace; it does not constrain the store. A call with optlen < 4 therefore writes past the user buffer, violating the getsockopt(2) contract for all five supported optnames. Reject any call with optlen < sizeof(u32) up front. 'len' is int, so a plain size comparison would promote a negative optlen to size_t and slip past the check; an explicit 'len < 0' test is added first to catch negative values before the size compare.
Title nfc: llcp: avoid userspace overflow on invalid optlen
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:35.322Z

Reserved: 2026-09-11T19:38:34.794Z

Link: CVE-2026-90226

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:18.270

Modified: 2026-09-17T17:17:18.270

Link: CVE-2026-90226

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:30:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-788

    Access of Memory Location After End of Buffer