Linux Kernel

severity

7.1

published

The Linux kernel's NFC/NCI subsystem can expose uninitialized kernel stack memory when processing crafted RF discovery or interface-activation notifications with zero-length technology-specific parameters. The affected handlers pass uninitialized data into NFC target records that can later be returned to user space.

Both nci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() parse notifications into stack structures that were not initialized. When a notification reports no RF technology-specific parameters, the corresponding union remains uninitialized, but is still read by nci_add_new_protocol(). Values copied from that union can reach ndev->targets and be exposed through NFC_CMD_GET_TARGET; the activation handler can also expose uninitialized activation parameters through the target ATS attribute.

The fix zero-initializes both notification structures before parsing. The issue is classified as CWE-908.


References


CVSS v3.1

7.1

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CVSS v3.1

7.1

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CVSS v3.1

7.1

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

S7tPa9rQt$  lLo&o&kRi9nLg%  aAtH  yPoUu4rP  sYoPfItBwMa3rKeN  cKrUiTtGiPcQaJlElSyL.H

request briefing

request briefing

S@tGaXrNtG  l9o4oQkRi1nBgP  aDt9  y@o@uHr#  sIo3fEt1w6aQrMeC  cNr$i$tHi$cWaQlBlXy@.K

request briefing

request briefing

SItLaRr&tS  lSoIo7kLiLnIgO  aItF  y&oHu@r&  sIoGfLt&wLaTr&eB  cZrCiStViGc1a0lVlFyH.$

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026