Back

MEDIUM

NFC: pn533: bound the UART receive buffer

Published May 1, 2026

Description

pn532_receive_buf() appends every incoming byte to dev->recv_skb and only resets the buffer after pn532_uart_rx_is_frame() recognizes a complete frame. A continuous stream of bytes without a valid PN532 frame header therefore keeps growing the skb until skb_put_u8() hits the tail limit.

Drop the accumulated partial frame once the fixed receive buffer is full so malformed UART traffic cannot grow the skb past PN532_UART_SKB_BUFF_LEN.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published May 1, 2026
Updated May 11, 2026
Reserved May 1, 2026

CISA Vulnrichment

No data

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

Public date May 1, 2026
Bugzilla 2464460

ENISA EUVD

Assigner Linux
Published May 1, 2026
Updated May 11, 2026

GitHub

No data