{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "cfad1ba87150e198be9ea32367a24e500e59de2c"
            },
            {
              "fixed": "c6de4241f2efbbab286efbb84a9c7190298b3052"
            },
            {
              "fixed": "92a6f0201bb68391b5eba1b3f330af007d7323b6"
            },
            {
              "fixed": "cb298672282421159e53ab311fe49d204c8a52da"
            },
            {
              "fixed": "18f02354ed229b8e4561b580812d026e7eb29c85"
            },
            {
              "fixed": "e6397fe7b8b5ef18e051f49612d40ff476c5f7d9"
            },
            {
              "fixed": "d0902a7c454326c6384c614226ab8987f3fd425d"
            },
            {
              "fixed": "dabfa26a208e56f4d8dbf26fddc48f188bdb0649"
            },
            {
              "fixed": "953963b9ac5eecbb316617d337bfaa3d731e3c5e"
            },
            {
              "fixed": "25519469972ef57c3edb1805dabd6c5612b90211"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.9.0"
            },
            {
              "fixed": "5.10.267"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.11.0"
            },
            {
              "fixed": "5.15.218"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.16.0"
            },
            {
              "fixed": "6.1.185"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.154"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.106"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.47"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.1.11"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "7.2.0"
            },
            {
              "fixed": "7.2.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80801.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: microread: validate target discovery payload lengths\n\nmicroread_target_discovered() parses target discovery payloads from\nskb-\u003edata according to the HCI gate. The fixed field offsets and UID\ncopies were checked only against the destination nfc_target buffers, not\nagainst the actual skb length.\n\nValidate that each gate-specific payload contains the fixed fields and\nUID bytes before reading or copying them.",
  "id": "CVE-2026-80801",
  "modified": "2026-09-06T03:30:31.817049592Z",
  "published": "2026-09-04T15:13:15.263Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/18f02354ed229b8e4561b580812d026e7eb29c85"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/25519469972ef57c3edb1805dabd6c5612b90211"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/92a6f0201bb68391b5eba1b3f330af007d7323b6"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/953963b9ac5eecbb316617d337bfaa3d731e3c5e"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/c6de4241f2efbbab286efbb84a9c7190298b3052"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/cb298672282421159e53ab311fe49d204c8a52da"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d0902a7c454326c6384c614226ab8987f3fd425d"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/dabfa26a208e56f4d8dbf26fddc48f188bdb0649"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/e6397fe7b8b5ef18e051f49612d40ff476c5f7d9"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80801.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80801"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "nfc: microread: validate target discovery payload lengths"
}