{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90223","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.794Z","datePublished":"2026-09-17T16:07:33.355Z","dateUpdated":"2026-09-18T17:53:49.876Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:53:49.876Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: bound SNL TLV parsing to the skb and add length checks\n\nnfc_llcp_recv_snl() walked the SNL TLV list using a u16 offset/length\npair derived from skb->len, without bounding reads to the actual skb\ndata. Three problems followed:\n\n  - For a short frame (skb->len < LLCP_HEADER_SIZE), tlv_len underflowed.\n  - The per-TLV header (type, length) was read without checking that two\n    bytes remained.\n  - A declared TLV length could run past the end of the buffer, and an\n    SDREQ with length == 0 made \"service_name_len = length - 1\" underflow\n    (size_t), driving an out-of-bounds read in the following strncmp() /\n    nfc_llcp_sock_from_sn(). The SDRES case likewise read tlv[2]/tlv[3]\n    without a length check.\n\nA nearby NFC device can reach this without authentication; LLCP link\nactivation happens automatically after NFC-DEP.\n\nWalk the TLV list by pointer, bounded by skb_tail_pointer() over the\nlinear skb data, and validate each TLV declared length before use. Add\nexplicit length checks for SDREQ (>= 1) and SDRES (exactly 2).\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - A nearby NFC-DEP peer supplies the malformed bytes in an LLCP SNL PDU (ptype LLCP_PDU_SNL, DSAP/SSAP LLCP_SAP_SDP). nfc_tm_data_received() or the initiator nfc_llcp_recv() callback delivers that skb through __nfc_llcp_recv() and nfc_llcp_rx_skb() into nfc_llcp_recv_snl(), which walks attacker-controlled SDREQ/SDRES TLVs. NFC is radio-range, so Adjacent.\nAC:L - The attacker fully controls the SNL payload, including each TLV type and u8 length. An SDREQ with length 0 or 15, or a declared length past the remaining skb, hits the missing header/value checks in nfc_llcp_recv_snl() deterministically, with no race or heap layout the attacker cannot set.\nPR:N - nfc_llcp_recv_snl() only rejects PDUs whose DSAP/SSAP are not LLCP_SAP_SDP; it does not require LLCP CONNECT, SDP credentials, or any host account. After nfc_dep_link_is_up(), an unauthenticated NFC-DEP peer can send SNL immediately.\nUI:N - nfc_tm_activated() calls nfc_dep_link_is_up() automatically when protocol is NFC_PROTO_NFC_DEP_MASK, after which nfc_tm_data_received() hands DEP payloads to LLCP. The attacker triggers the SNL parse with their own frames; no extra victim click, mount, or dialog is required.\nS:U - nfc_llcp_recv_snl() over-reads kernel memory adjacent to the received skb in the LLCP receive path. That stays inside the host kernel's security authority; there is no VM, IOMMU, or sandbox boundary crossed.\nC:L - A short SDREQ with length==15 makes strncmp(service_name, \"urn:nfc:sn:sdp\", 14) read up to 14 bytes past the skb, and length==0 uses out-of-bounds tlv[2] as the tid echoed by nfc_llcp_build_sdres_tlv(). nfc_llcp_sock_from_sn() memcmp is gated on matching socket name length, so this is a small bounded leak, not an arbitrary read.\nI:N - The SNL walker only reads past the skb; it does not write past it. The SDRES path assigns tlv[3] into an existing pending nfc_llcp_sdp_tlv->sap on a tid match, which is an in-object protocol field a well-formed SDRES can already set, not a kernel write primitive.\nA:H - nfc_llcp_recv_snl() can read tlv[0]/tlv[1] when fewer than two bytes remain, and strncmp()/tlv[2] past the skb tail. Those over-reads can fault on an unmapped page or KFENCE guard and oops the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/nfc/llcp_core.c"],"versions":[{"version":"19cfe5843e86cc95542d9d875c9386e197956d75","lessThan":"88b36d36e12c9ba76decdb580d9c1907c084e587","status":"affected","versionType":"git"},{"version":"19cfe5843e86cc95542d9d875c9386e197956d75","lessThan":"587fc2a5a35b41883b22b8f808fe5d345208914b","status":"affected","versionType":"git"},{"version":"19cfe5843e86cc95542d9d875c9386e197956d75","lessThan":"f04ac9bf2379f3e2470c400c235eb12f74891bef","status":"affected","versionType":"git"},{"version":"19cfe5843e86cc95542d9d875c9386e197956d75","lessThan":"02030f95820c42431280f4f945ff34247fb840ff","status":"affected","versionType":"git"},{"version":"19cfe5843e86cc95542d9d875c9386e197956d75","lessThan":"99fdb5c2522f365efa199d0117b641e35097041e","status":"affected","versionType":"git"},{"version":"19cfe5843e86cc95542d9d875c9386e197956d75","lessThan":"749a9048bf51a668ec3ab6c0392ba32325607281","status":"affected","versionType":"git"},{"version":"19cfe5843e86cc95542d9d875c9386e197956d75","lessThan":"eeb16fb24cfe67947b832fd9ada5f488afc72579","status":"affected","versionType":"git"},{"version":"19cfe5843e86cc95542d9d875c9386e197956d75","lessThan":"f4c7f37f0ab990952539dc68d931d65c3657600a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/nfc/llcp_core.c"],"versions":[{"version":"3.8","status":"affected"},{"version":"0","lessThan":"3.8","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/88b36d36e12c9ba76decdb580d9c1907c084e587"},{"url":"https://git.kernel.org/stable/c/587fc2a5a35b41883b22b8f808fe5d345208914b"},{"url":"https://git.kernel.org/stable/c/f04ac9bf2379f3e2470c400c235eb12f74891bef"},{"url":"https://git.kernel.org/stable/c/02030f95820c42431280f4f945ff34247fb840ff"},{"url":"https://git.kernel.org/stable/c/99fdb5c2522f365efa199d0117b641e35097041e"},{"url":"https://git.kernel.org/stable/c/749a9048bf51a668ec3ab6c0392ba32325607281"},{"url":"https://git.kernel.org/stable/c/eeb16fb24cfe67947b832fd9ada5f488afc72579"},{"url":"https://git.kernel.org/stable/c/f4c7f37f0ab990952539dc68d931d65c3657600a"}],"title":"nfc: llcp: bound SNL TLV parsing to the skb and add length checks","x_generator":{"engine":"bippy-1.2.0"}}}}