{"id":"AZL-99497","summary":"CVE-2026-80794 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: fix uninit-value in the RF discover/activated NTF handlers\n\nnci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each\nparse a notification into an on-stack struct (nci_rf_discover_ntf /\nnci_rf_intf_activated_ntf) that is not initialised. The RF\ntechnology-specific parameters are only extracted when\nrf_tech_specific_params_len is non-zero, so a notification that reports a\nzero length leaves the rf_tech_specific_params union uninitialised - and\nboth handlers then pass it to nci_add_new_protocol(), which reads it:\n\n - discover:  nci_add_new_target() -\u003e nci_add_new_protocol();\n - activated: nci_target_auto_activated() -\u003e nci_add_new_protocol().\n\nnci_add_new_protocol() uses nfca_poll-\u003enfcid1_len as both a branch\ncondition and a memcpy() length and copies nfcid1/sens_res/sel_res into\nndev-\u003etargets, which is later exposed to user space via NFC_CMD_GET_TARGET.\n\n  BUG: KMSAN: uninit-value in nci_add_new_protocol+0x624/0x6c0\n   nci_add_new_protocol+0x624/0x6c0\n   nci_ntf_packet+0x25b2/0x3c30\n   nci_rx_work+0x318/0x5d0\n   process_scheduled_works+0x84b/0x17a0\n   worker_thread+0xc10/0x11b0\n   kthread+0x376/0x500\n  Local variable ntf.i created at:\n   nci_ntf_packet+0xbc2/0x3c30\n\nZero-initialise both on-stack notifications so the union reads back as\nzero when no technology-specific parameters are present.","modified":"2026-09-05T14:17:03.896538559Z","published":"2026-09-04T16:18:05Z","upstream":["CVE-2026-80794"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80794"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99497.json"}}],"schema_version":"1.9.0"}