In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Add bounds checking in nci_hci_create_pipe() The "pipe" variable is a u8 which comes from the network. If it's more than 127, then it results in memory corruption in the caller, nci_hci_connect_gate().
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025022658-CVE-2025-21735-259b@gregkh/T