CVE-2022-26490

Executive Summary

CVE-2022-26490 exposes a buffer overflow in the Linux kernel's NFC driver (st21nfca_connectivity_event_received) for kernel versions up to 5.16.12. Untrusted length parameters in EVT_TRANSACTION events can overflow the buffer, potentially allowing an attacker to execute arbitrary code with kernel privileges. The flaw is not yet listed in CISA KEV but poses a high‑impact kernel exploitation risk.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2022-03-06T04:15:07.100 - Last Modified: 2026-09-01T18:04:55.837

Original Description: st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.

"The best cure for the body is a quiet mind."

— Napoleon Bonaparte
Source: NVD