CVE-2026-90221

Unknown

Last modified

CVE-2026-90221 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() parse the CORE_INIT_RSP packet without validating that the skb contains enough data. A malformed response (e.g.

Description

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() parse the CORE_INIT_RSP packet without validating that the skb contains enough data. A malformed response (e.g. injected via virtual_ncidev) can declare a large num_supported_rf_interfaces while providing insufficient data, causing reads of uninitialized slab memory. This is later used in nci_init_complete_req(), triggering a KMSAN uninit-value warning. Add skb length checks before accessing packet fields: - Validate the skb has at least 1 byte for the status field. - Validate the skb can hold the fixed-size header before parsing. - In v2, bounds-check each variable-length rf_interface entry and its extension parameters within the parsing loop. - In v1, verify the skb is large enough for both the variable-length rf_interfaces array and the trailing rsp_2 structure.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= bcd684aace34fedbd473fbd9b21ed06b0c2d2212, < baed3fdf6ed2195c56f25ae18a086b938dcd3983; >= bcd684aace34fedbd473fbd9b21ed06b0c2d2212, < 2f434478771a4ebdd535033561c0590bcde39753; >= bcd684aace34fedbd473fbd9b21ed06b0c2d2212, < 5487f04c1ccbfa15aa6e531eb1ec9c9ec9c7bf31; >= bcd684aace34fedbd473fbd9b21ed06b0c2d2212, < bbe68e8249e2c76d65adfd9224fa95f1ca0fbe4e; >= bcd684aace34fedbd473fbd9b21ed06b0c2d2212, < 4f0483bbcdaccc9d4aee30df7351863334cecfa7; >= bcd684aace34fedbd473fbd9b21ed06b0c2d2212, < 7d44b897bff84edcd4814899314d661ad4956a8e; >= bcd684aace34fedbd473fbd9b21ed06b0c2d2212, < d56575a2595ee1f597f39e8a1cfb67ed3501678d
LinuxLinux5.11

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-90221?
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() parse the CORE_INIT_RSP packet without validating that the skb contains enough data. A malformed response (e.g. injected via virtual_ncidev) can declare a large num_supported_rf_interfaces while providing insufficient data, causing reads of uninitialized slab memory. This is later used in nci_init_complete_req(), triggering a KMSAN uninit-value warning. Add skb length checks before accessing packet fields: - Validate the skb has at least 1 byte for the status field. - Validate the skb can hold the fixed-size header before parsing. - In v2, bounds-check each variable-length rf_interface entry and its extension parameters within the parsing loop. - In v1, verify the skb is large enough for both the variable-length rf_interfaces array and the trailing rsp_2 structure.
How severe is CVE-2026-90221?
Severity scoring for CVE-2026-90221 is pending analysis.
How do I fix CVE-2026-90221?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-90221?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST