CVE-2026-80797: nfc: pn533: purge fragmented skbs during cleanup
In the Linux kernel, the following vulnerability has been resolved:
nfc: pn533: purge fragmented skbs during cleanup
pn53xcommonclean() purges respq before freeing the common PN533 state, but it leaves fragmentskb untouched. The fragmentation helpers queue transmit fragments there while sending large initiator or target-mode frames, and those skbs remain owned by the driver until they are sent or discarded.
If the device is removed while fragments are still queued, the common cleanup path frees the PN533 state without releasing the queued fragment skbs, leaking them.
Purge fragmentskb during cleanup alongside respq.
Affected Software
Event History
Frequently Asked Questions
When can this memory leak occur?
It can occur when a PN533 device is removed while transmit fragments for a large initiator-mode or target-mode frame are still queued in fragment_skb.
What is the impact of the issue?
Queued fragment socket buffers remain unreleased after the PN533 common state is freed, causing a memory leak.
What should teams do if they cannot immediately apply the fix?
Avoid removing PN533 devices while large initiator-mode or target-mode transmissions may still have queued fragments, where operationally possible.