Answer in brief
CVE-2026-90221 records a Unknown severity vulnerability in nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bcd684aace34fedbd473fbd9b21ed06b0c2d2212 <baed3fdf6ed2195c56f25ae18a086b938dcd3983 || >=bcd684aace34fedbd473fbd9b21ed06b0c2d2212 <2f434478771a4ebdd535033561c0590bcde39753 || >=bcd684aace34fedbd473fbd9b21ed06b0c2d2212 <5487f04c1ccbfa15aa6e531eb1ec9c9ec9c7bf31 || >=bcd684aace34fedbd473fbd9b21ed06b0c2d2212 <bbe68e8249e2c76d65adfd9224fa95f1ca0fbe4e || >=bcd684aace34fedbd473fbd9b21ed06b0c2d2212 <4f0483bbcdaccc9d4aee30df7351863334cecfa7 || >=bcd684aace34fedbd473fbd9b21ed06b0c2d2212 <7d44b897bff84edcd4814899314d661ad4956a8e || >=bcd684aace34fedbd473fbd9b21ed06b0c2d2212 <d56575a2595ee1f597f39e8a1cfb67ed3501678d | baed3fdf6ed2195c56f25ae18a086b938dcd3983, 2f434478771a4ebdd535033561c0590bcde39753, 5487f04c1ccbfa15aa6e531eb1ec9c9ec9c7bf31, bbe68e8249e2c76d65adfd9224fa95f1ca0fbe4e, 4f0483bbcdaccc9d4aee30df7351863334cecfa7, 7d44b897bff84edcd4814899314d661ad4956a8e, d56575a2595ee1f597f39e8a1cfb67ed3501678d |
| Linux/Linuxgeneric | 5.11 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() parse the CORE_INIT_RSP packet without validating that the skb contains enough data. A malformed response (e.g. injected via virtual_ncidev) can declare a large num_supported_rf_interfaces while providing insufficient data, causing reads of uninitialized slab memory. This is later used in nci_init_complete_req(), triggering a KMSAN uninit-value warning. Add skb length checks before accessing packet fields: - Validate the skb has at least 1 byte for the status field. - Validate the skb can hold the fixed-size header before parsing. - In v2, bounds-check each variable-length rf_interface entry and its extension parameters within the parsing loop. - In v1, verify the skb is large enough for both the variable-length rf_interfaces array and the trailing rsp_2 structure.
Quoted source text, attributed separately from HOL analysis.