st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/anonymous-1113/CPE_verify
- https://github.com/evdenis/cvehound