CVE-2026-31660

EUVD-2026-25553
In the Linux kernel, the following vulnerability has been resolved:

nfc: pn533: allocate rx skb before consuming bytes

pn532_receive_buf() reports the number of accepted bytes to the serdev
core. The current code consumes bytes into recv_skb and may already hand
a complete frame to pn533_recv_frame() before allocating a fresh receive
buffer.

If that alloc_skb() fails, the callback returns 0 even though it has
already consumed bytes, and it leaves recv_skb as NULL for the next
receive callback. That breaks the receive_buf() accounting contract and
can also lead to a NULL dereference on the next skb_put_u8().

Allocate the receive skb lazily before consuming the next byte instead.
If allocation fails, return the number of bytes already accepted.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
5.5.1 ≤
𝑥
< 5.10.253
linuxlinux_kernel
5.11 ≤
𝑥
< 5.15.203
linuxlinux_kernel
5.16 ≤
𝑥
< 6.1.169
linuxlinux_kernel
6.2 ≤
𝑥
< 6.6.135
linuxlinux_kernel
6.7 ≤
𝑥
< 6.12.82
linuxlinux_kernel
6.13 ≤
𝑥
< 6.18.23
linuxlinux_kernel
6.19 ≤
𝑥
< 6.19.13
linuxlinux_kernel
5.5
linuxlinux_kernel
7.0:rc1
linuxlinux_kernel
7.0:rc2
linuxlinux_kernel
7.0:rc3
linuxlinux_kernel
7.0:rc4
linuxlinux_kernel
7.0:rc5
linuxlinux_kernel
7.0:rc6
linuxlinux_kernel
7.0:rc7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.176-1
fixed
bookworm (security)
6.1.177-1
fixed
bullseye
vulnerable
bullseye (security)
5.10.259-1
fixed
forky
7.1.3-1
fixed
sid
7.1.4-1
fixed
trixie
6.12.94-1
fixed
trixie (security)
6.12.96-1
fixed
linux-6.1
bullseye (security)
6.1.176-1~deb11u1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
kernel-64kb
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
kernel-default
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
kernel-default-base
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2.150700.17.41.4
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2.150700.17.41.4
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2.150700.17.41.4
fixed
kernel-obs-build
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
kernel-source
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.1
fixed
kernel-zfcpdump
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
kernel
Azure Linux 3.0
0:6.6.137.1-1.azl3
fixed