CVE-2026-63915
Linux kernel NFC HCI out-of-bounds read can crash or leak memory
Is CVE-2026-63915 being exploited?
Not confirmed. CVE-2026-63915 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.35% probability of exploitation in the next 30 days.
How severe is CVE-2026-63915?
CVE-2026-63915 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-63915?
Yes. A fix has been recorded for CVE-2026-63915. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-63915 affect?
CVE-2026-63915 affects Linux kernel (nfc/hci subsystem), Devices with NFC: mobile, embedded, IoT running Linux. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-63915?
Apply kernel updates or disable NFC until patched
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Crafted 0-byte NFC HCP frames can cause heap OOB read and reassembly underflow, enabling kernel memory disclosure or crash/DoS (requires NFC proximity).
Patch when possible
- affected>= 8b8d2e08bf0d50193931afd27482a59376b66b2b and < ed6d5d97dad0334a7f43d218753429cbe2f70a4f
- affected>= 8b8d2e08bf0d50193931afd27482a59376b66b2b and < b99366d74b535d0cadb1ef73e04639415d9ff3b7
- affected>= 8b8d2e08bf0d50193931afd27482a59376b66b2b and < 37382293f174b82a0616c8295e32b1fc8e13d1ed
- affected>= 8b8d2e08bf0d50193931afd27482a59376b66b2b and < c4cc6b3b0013acb3ed0b2b60e57dfae98647fe98
- affected>= 8b8d2e08bf0d50193931afd27482a59376b66b2b and < 1905f5ec3641b2b234bb63549c8ca11ab85466eb
- affected>= 8b8d2e08bf0d50193931afd27482a59376b66b2b and < 22d41b176b9989efd21c3b2d3abf6728f05b9d9a
- affected>= 8b8d2e08bf0d50193931afd27482a59376b66b2b and < 83b1362edc9d6ae376c6f36da116e2c70f2e70a6
- affected>= 8b8d2e08bf0d50193931afd27482a59376b66b2b and < f040e590c035bfd9553fe79ee9585caf1b14d67b
- affected3.5
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.