{"id":"CVE-2026-80794","summary":"nfc: nci: fix uninit-value in the RF discover/activated NTF handlers","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: fix uninit-value in the RF discover/activated NTF handlers\n\nnci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each\nparse a notification into an on-stack struct (nci_rf_discover_ntf /\nnci_rf_intf_activated_ntf) that is not initialised. The RF\ntechnology-specific parameters are only extracted when\nrf_tech_specific_params_len is non-zero, so a notification that reports a\nzero length leaves the rf_tech_specific_params union uninitialised - and\nboth handlers then pass it to nci_add_new_protocol(), which reads it:\n\n - discover:  nci_add_new_target() -\u003e nci_add_new_protocol();\n - activated: nci_target_auto_activated() -\u003e nci_add_new_protocol().\n\nnci_add_new_protocol() uses nfca_poll-\u003enfcid1_len as both a branch\ncondition and a memcpy() length and copies nfcid1/sens_res/sel_res into\nndev-\u003etargets, which is later exposed to user space via NFC_CMD_GET_TARGET.\n\n  BUG: KMSAN: uninit-value in nci_add_new_protocol+0x624/0x6c0\n   nci_add_new_protocol+0x624/0x6c0\n   nci_ntf_packet+0x25b2/0x3c30\n   nci_rx_work+0x318/0x5d0\n   process_scheduled_works+0x84b/0x17a0\n   worker_thread+0xc10/0x11b0\n   kthread+0x376/0x500\n  Local variable ntf.i created at:\n   nci_ntf_packet+0xbc2/0x3c30\n\nZero-initialise both on-stack notifications so the union reads back as\nzero when no technology-specific parameters are present.","modified":"2026-09-06T03:46:16.236427232Z","published":"2026-09-04T15:13:07.169Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80794.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0d4b5cfab6891a5ca0f6aef209beebba4bd7c095"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1007a6b429d756513abd25bd00290908f2e89a4a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4bda9ef8392710f21e99027467f3f4afdfb5c99a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5bd00c0e1470d90d77a7c60242854257ddf14e00"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7086dab72b3ed95df96842801e10e935cfeb27a3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7489f59d1ea2d3298aa41de7baf193e5e6e132f6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8cbe06c1e699c0a165dae5093a2550e65f914818"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d6f743d3d388913135681cde051c08823730194f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fe69fed3495f676578d49414a069ad7d8468e2ce"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80794.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80794"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20"},{"fixed":"1007a6b429d756513abd25bd00290908f2e89a4a"},{"fixed":"4bda9ef8392710f21e99027467f3f4afdfb5c99a"},{"fixed":"fe69fed3495f676578d49414a069ad7d8468e2ce"},{"fixed":"7489f59d1ea2d3298aa41de7baf193e5e6e132f6"},{"fixed":"7086dab72b3ed95df96842801e10e935cfeb27a3"},{"fixed":"0d4b5cfab6891a5ca0f6aef209beebba4bd7c095"},{"fixed":"5bd00c0e1470d90d77a7c60242854257ddf14e00"},{"fixed":"d6f743d3d388913135681cde051c08823730194f"},{"fixed":"8cbe06c1e699c0a165dae5093a2550e65f914818"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80794.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.3.0"},{"fixed":"5.10.269"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.218"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.185"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.154"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.106"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.47"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.11"}]},{"type":"ECOSYSTEM","events":[{"introduced":"7.2.0"},{"fixed":"7.2.1"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80794.json"}}],"schema_version":"1.9.0"}