Back

HIGH

nfc: pn533: Clear nfc_target before being used

Published Dec 9, 2025

Description

Fix a slab-out-of-bounds read that occurs in nla_put() called from nfc_genl_send_target() when target->sensb_res_len, which is duplicated from an nfc_target in pn533, is too large as the nfc_target is not properly initialized and retains garbage values. Clear nfc_targets with memset() before they are used.

Found by a modified version of syzkaller.

BUG: KASAN: slab-out-of-bounds in nla_put Call Trace: memcpy nla_put nfc_genl_dump_targets genl_lock_dumpit netlink_dump __netlink_dump_start genl_family_rcv_msg_dumpit genl_rcv_msg netlink_rcv_skb genl_rcv netlink_unicast netlink_sendmsg sock_sendmsg ____sys_sendmsg ___sys_sendmsg __sys_sendmsg do_syscall_64

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Dec 9, 2025
Updated Aug 5, 2026
Reserved Dec 8, 2025
NVD
Status Deferred
Modified Aug 4, 2026
Red Hat
Severity n/a
Public date Dec 9, 2025
ENISA EUVD
Assigner Linux
Published Dec 9, 2025
Updated Aug 5, 2026
Exploited since n/a
EUVD-2022-55700