CVE-2022-50656
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/12/2025
Last modified:
09/12/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
nfc: pn533: Clear nfc_target before being used<br />
<br />
Fix a slab-out-of-bounds read that occurs in nla_put() called from<br />
nfc_genl_send_target() when target->sensb_res_len, which is duplicated<br />
from an nfc_target in pn533, is too large as the nfc_target is not<br />
properly initialized and retains garbage values. Clear nfc_targets with<br />
memset() before they are used.<br />
<br />
Found by a modified version of syzkaller.<br />
<br />
BUG: KASAN: slab-out-of-bounds in nla_put<br />
Call Trace:<br />
memcpy<br />
nla_put<br />
nfc_genl_dump_targets<br />
genl_lock_dumpit<br />
netlink_dump<br />
__netlink_dump_start<br />
genl_family_rcv_msg_dumpit<br />
genl_rcv_msg<br />
netlink_rcv_skb<br />
genl_rcv<br />
netlink_unicast<br />
netlink_sendmsg<br />
sock_sendmsg<br />
____sys_sendmsg<br />
___sys_sendmsg<br />
__sys_sendmsg<br />
do_syscall_64
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/61a7e15d55fae329a245535c3bac494e401005b8
- https://git.kernel.org/stable/c/755019e37815a66bb0a23893debbd3dd640ccbd3
- https://git.kernel.org/stable/c/8bddef54cbe9ede5ac7478f1e1e968fcfe7e6f03
- https://git.kernel.org/stable/c/9da4a0411f3455e3885831d0758bee3e3d565bbc
- https://git.kernel.org/stable/c/9f28157778ede0d4f183f7ab3b46995bb400abbe
- https://git.kernel.org/stable/c/aae9c24ebd901f482e6c88b6f9e0c80dc5b536d6
- https://git.kernel.org/stable/c/aea9e64dec2cc6cd742e07ecd4e6236fc76b389b
- https://git.kernel.org/stable/c/bef2f478513e7367ef3b05441f6afca981de29be
- https://git.kernel.org/stable/c/e491285b4d08884b622638be8e4961eb43b0af64



