UBUNTU-CVE-2026-80801
Dashboard / Vulnerabilities / UBUNTU-CVE-2026-80801
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: nfc: microread: validate target discovery payload lengths microread_target_discovered() parses target discovery payloads from skb->data according to the HCI gate. The fixed field offsets and UID copies were checked only against the destination nfc_target buffers, not against the actual skb length. Validate that each gate-specific payload contains the fixed fields and UID bytes before reading or copying them.
References: https://ubuntu.com/security/CVE-2026-80801, https://www.cve.org/CVERecord?id=CVE-2026-80801, https://git.kernel.org/linus/25519469972ef57c3edb1805dabd6c5612b90211
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
