CVE-2026-80803

Source
https://cve.org/CVERecord?id=CVE-2026-80803
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80803.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-80803
Downstream
Related
Published
2026-09-04T15:13:17Z
Modified
2026-09-15T18:26:51Z
Summary
nfc: digital: clamp SENSF_RES length to the destination buffer
Details

In the Linux kernel, the following vulnerability has been resolved:

nfc: digital: clamp SENSF_RES length to the destination buffer

digital_in_recv_sensf_res() memcpy()s resp->len bytes from a remote NFC-F device response into the NFC_SENSF_RES_MAXSIZE-byte target.sensf_res field without an upper-bound check. A nearby malicious NFC-F device can send an oversized SENSF_RES response to overflow the stack-local struct nfc_target.

Clamp resp->len to NFC_SENSF_RES_MAXSIZE before the copy.

Found by 0sec automated security-research tooling (https://0sec.ai).

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80803.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8c0695e4998dd268ff2a05951961247b7e015651
Fixed
6afb29751ee731e7f7a96feb8a15f91441e552ba
Fixed
e886c63d2ca7108826076989103a1ffa8a0bb8f4
Fixed
4e942da2869bcd646353eef706b7dd82efeb9db5
Fixed
d0756a98277e383c26fead988a96c91f0781cd7f
Fixed
af4c0606f743e009254a8d252096855335ade85d
Fixed
a56773e649ea99b344d6bbaf90f34c8e3fadef5d
Fixed
a1ef9bddfbb3ae42b036c5aa16cf386d78db70b6
Fixed
31aa28ed732f66ab83c40ef53d99791be69b85c4
Fixed
344a56d7c8e0f3cbaff0bcb1bcd95a1a1db24b16

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80803.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.13.0
Fixed
5.10.267
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.218
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.185
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.154
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.106
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.47
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.11
Type
ECOSYSTEM
Events
Introduced
7.2.0
Fixed
7.2.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80803.json"