Kestrel
대시보드로 돌아가기
CVE-2026-80799UNKNOWNMITRENVD대응게시일: 2026. 09. 04.수정일: 2026. 09. 04.CNA: 416baaa9-dc9f-4396-8d5f-8c081fb06d67Received

In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers nfc_llcp_par

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
unknown

이론적 심각도 점수

EPSS
0.2%상위 85.7%

30일 내 악용 확률 예측

KEV
미등재

실측 악용 기록 없음

권장 대응 기한60일 이내CISA SSVC 기준

계획된 패치 주기 내 조치(60일 이내)

외부 노출· KEV 미등재 · 자동화 어려움 · 부분 영향 · 외부 노출

CVSS 벡터 · 메트릭

CVSS 벡터 정보 없음

상세 설명

In the Linux kernel, the following vulnerability has been resolved:

nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers

nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain
three related bugs in their TLV parsing loops:

  1. 'offset' is declared u8 but tlv_array_len is u16. When TLV data
    advances offset past 255 it silently wraps to zero, causing
    infinite loops or double-processing of buffer data.

  2. Before reading tlv[0] (type) and tlv[1] (length) there is no
    check that offset+2 <= tlv_array_len. A truncated TLV causes
    an OOB read of one byte past the buffer end.

  3. After reading the length field, the value bytes are accessed
    without checking offset+2+length <= tlv_array_len. A crafted
    length=0xFF on a short buffer causes up to 255 bytes of OOB
    read past the buffer end.

Both functions are reachable without authentication via
nfc_llcp_set_remote_gb() which feeds remote LLCP general bytes
directly into nfc_llcp_parse_gb_tlv() with no additional
validation.

Fix all three issues by widening offset from u8 to u16 and adding
bounds checks for both the TLV header and value field before each
access.

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.