Executive brief
The pn533 NFC device driver in the Linux kernel fails to initialize data structures before use, allowing uninitialized memory containing garbage values to be read and transmitted over netlink sockets. An attacker with local access can trigger this bug to leak kernel memory, potentially exposing sensitive information or enabling further exploitation.
Technical details
The vulnerability is a slab-out-of-bounds read in the pn533 NFC device driver (drivers/nfc/pn533/pn533.c). The root cause is that nfc_target structures are not properly initialized before use in the pn533_poll_dep_complete() and pn533_in_dep_link_up_complete() functions. When these uninitialized structures containing garbage values are passed to nfc_genl_dump_targets() and subsequently to nla_put(), the function attempts to copy data using the garbage sensb_res_len field as a size parameter, causing an out-of-bounds heap read. The attack vector is local and requires triggering NFC device enumeration via netlink. The fix adds memset() calls to clear the nfc_target structures before use. This vulnerability was discovered via a modified syzkaller fuzzer.
Affected products
- Linux Linux Kernel Linux kernel versions prior to the patch (affects pn533 NFC driver)
Timeline
- 2025-12-09: disclosed
- 2022-12-14: patched: Patch commit 9f28157778ede0d4f183f7ab3b46995bb400abbe
- 2023-01-18: other: Patch merged to stable Linux kernel