ThreatCluster

Multiple CVEs Addressed in NFC Protocol Vulnerabilities

First seen 18 Feb 2026, 13:23 UTC Api.Msrc.Microsoft 45

Article Content

Browse articles
ThreatCluster

Two vulnerabilities in the NFC protocol have been addressed, affecting systems utilizing the nci component. CVE-2024-38381, published on June 21, 2024, fixes an uninitialized value issue in nci_rx_work. CVE-2025-21735, published on February 27, 2025, adds bounds checking in nci_hci_create_pipe().

Timeline

2024-06-21
CVE-2024-38381 published
2025-02-27
CVE-2025-21735 published
2026-02-18
Information published regarding both CVEs