Answer in brief
CVE-2026-90226 records a Unknown severity vulnerability in nfc: llcp: avoid userspace overflow on invalid optlen. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <42859562b7cc4313a84a584f338118edb7087066 || >=26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <598dcd53c52f8eeb9dd5382198c03960d5d40fcd || >=26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <7e40f2f5e7bc06c3ddef781180ce4f7994176547 || >=26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <35573c6cb081af2f4a7caeea291302aca5484526 || >=26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <b4c5abaea06292e1dddb70eac1b51589b32c77a3 || >=26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <8bf228fa02b1ed8ce622fb81fa8edc42be9aeb67 || >=26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <bd6f1277b62bc1df348ca21739df2bc546fcd493 || >=26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <99985bfa8336fadcc69190ba2dcbd5386af3d661 | 42859562b7cc4313a84a584f338118edb7087066, 598dcd53c52f8eeb9dd5382198c03960d5d40fcd, 7e40f2f5e7bc06c3ddef781180ce4f7994176547, 35573c6cb081af2f4a7caeea291302aca5484526, b4c5abaea06292e1dddb70eac1b51589b32c77a3, 8bf228fa02b1ed8ce622fb81fa8edc42be9aeb67, bd6f1277b62bc1df348ca21739df2bc546fcd493, 99985bfa8336fadcc69190ba2dcbd5386af3d661 |
| Linux/Linuxgeneric | 3.10 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: avoid userspace overflow on invalid optlen nfc_llcp_getsockopt() casts optval to (u32 __user *) for put_user(), so the kernel always stores 4 bytes regardless of the caller-supplied optlen. The existing min_t(u32, len, sizeof(u32)) only clamps the length reported back to userspace; it does not constrain the store. A call with optlen < 4 therefore writes past the user buffer, violating the getsockopt(2) contract for all five supported optnames. Reject any call with optlen < sizeof(u32) up front. 'len' is int, so a plain size comparison would promote a negative optlen to size_t and slip past the check; an explicit 'len < 0' test is added first to catch negative values before the size compare.
Quoted source text, attributed separately from HOL analysis.