CVE-2026-90221 PUBLISHED

nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing

nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() parse the CORE_INIT_RSP packet without validating that the skb contains enough data. A malformed response (e.g. injected via virtual_ncidev) can declare a large num_supported_rf_interfaces while providing insufficient data, causing reads of uninitialized slab memory. This is later used in nci_init_complete_req(), triggering a KMSAN uninit-value warning.

Add skb length checks before accessing packet fields: - Validate the skb has at least 1 byte for the status field. - Validate the skb can hold the fixed-size header before parsing. - In v2, bounds-check each variable-length rf_interface entry and its extension parameters within the parsing loop. - In v1, verify the skb is large enough for both the variable-length rf_interfaces array and the trailing rsp_2 structure.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from bcd684aace34fedbd473fbd9b21ed06b0c2d2212 to baed3fdf6ed2195c56f25ae18a086b938dcd3983 (excl.)
  • affected from bcd684aace34fedbd473fbd9b21ed06b0c2d2212 to 2f434478771a4ebdd535033561c0590bcde39753 (excl.)
  • affected from bcd684aace34fedbd473fbd9b21ed06b0c2d2212 to 5487f04c1ccbfa15aa6e531eb1ec9c9ec9c7bf31 (excl.)
  • affected from bcd684aace34fedbd473fbd9b21ed06b0c2d2212 to bbe68e8249e2c76d65adfd9224fa95f1ca0fbe4e (excl.)
  • affected from bcd684aace34fedbd473fbd9b21ed06b0c2d2212 to 4f0483bbcdaccc9d4aee30df7351863334cecfa7 (excl.)
  • affected from bcd684aace34fedbd473fbd9b21ed06b0c2d2212 to 7d44b897bff84edcd4814899314d661ad4956a8e (excl.)
  • affected from bcd684aace34fedbd473fbd9b21ed06b0c2d2212 to d56575a2595ee1f597f39e8a1cfb67ed3501678d (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.11 is affected
  • unaffected from 0 to 5.11 (excl.)
  • unaffected from 5.15.221 to 5.15.* (incl.)
  • unaffected from 6.1.188 to 6.1.* (incl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References