Related Vulnerabilities: CVE-2022-26490  

st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.

Description

The MITRE CVE dictionary describes this issue as:

st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.

Additional Information

  • Bugzilla 2064232: CVE-2022-26490 kernel: potential buffer overflows in EVT_TRANSACTION in st21nfca
  • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
  • FAQ: Frequently asked questions about CVE-2022-26490