CVE-2026-80801
Last modified
CVE-2026-80801 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: nfc: microread: validate target discovery payload lengths microread_target_discovered() parses target discovery payloads from skb->data according to the HCI gate. The fixed field offsets and UID copies were checked only against the destination nfc_target buffers, not against the actual skb length. Validate that each gate-specific payload contains the fixed fields and UID bytes before reading or copying them..
Description
In the Linux kernel, the following vulnerability has been resolved: nfc: microread: validate target discovery payload lengths microread_target_discovered() parses target discovery payloads from skb->data according to the HCI gate. The fixed field offsets and UID copies were checked only against the destination nfc_target buffers, not against the actual skb length. Validate that each gate-specific payload contains the fixed fields and UID bytes before reading or copying them.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= cfad1ba87150e198be9ea32367a24e500e59de2c, < c6de4241f2efbbab286efbb84a9c7190298b3052; >= cfad1ba87150e198be9ea32367a24e500e59de2c, < 92a6f0201bb68391b5eba1b3f330af007d7323b6; >= cfad1ba87150e198be9ea32367a24e500e59de2c, < cb298672282421159e53ab311fe49d204c8a52da; >= cfad1ba87150e198be9ea32367a24e500e59de2c, < 18f02354ed229b8e4561b580812d026e7eb29c85; >= cfad1ba87150e198be9ea32367a24e500e59de2c, < e6397fe7b8b5ef18e051f49612d40ff476c5f7d9; >= cfad1ba87150e198be9ea32367a24e500e59de2c, < d0902a7c454326c6384c614226ab8987f3fd425d; >= cfad1ba87150e198be9ea32367a24e500e59de2c, < dabfa26a208e56f4d8dbf26fddc48f188bdb0649; >= cfad1ba87150e198be9ea32367a24e500e59de2c, < 953963b9ac5eecbb316617d337bfaa3d731e3c5e; >= cfad1ba87150e198be9ea32367a24e500e59de2c, < 25519469972ef57c3edb1805dabd6c5612b90211 |
| Linux | Linux | 3.9 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-80801?
How severe is CVE-2026-80801?
How do I fix CVE-2026-80801?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80796In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80797In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80798In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80799In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8080Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2026-80800In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80802In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80803In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80804In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80805In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80806In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80807In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-80801?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
