Executive brief
A vulnerability was identified in the Linux kernel's Near Field Communication (NFC) component. A race condition in how the system handles NFC connections could allow a local attacker to cause a system crash or potentially execute unauthorized code by exploiting a 'use-after-free' memory error. This occurs when the system attempts to use a network socket that has already been closed and cleared from memory.
Technical details
A race condition exists in the NFC LLCP connection state machine within net/nfc/llcp_core.c. Specifically, the function nfc_llcp_recv_cc() moves a socket from the connecting_sockets list to the sockets list without holding the required socket lock. If llcp_sock_release() is executed concurrently, it may unlink the socket and drop its references before nfc_llcp_recv_cc() completes its transition, resulting in a use-after-free (UAF) when the freed socket is linked back into the live list. The fix involves implementing lock_sock() during the state transition and verifying the socket is still hashed (sk_hashed) before proceeding. This vulnerability requires local access to the NFC subsystem.
Affected products
- Linux Linux a69f32af86e389dd232b1bb2269e202c1bfcc60f
Timeline
- 2026-04-29: other: Patch authored
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0b45c31746e1523d5d482fda8fcf54a35ac417f1
- https://git.kernel.org/stable/c/650bdd8fdfab64a09ee474150313dbc48c374795
- https://git.kernel.org/stable/c/ad8a27d63cac96bac441edd002209ebd996e12fb
- https://git.kernel.org/stable/c/b2a60f7f846faaf5c2cdad4ea6d3a33e5f863183
- https://git.kernel.org/stable/c/b493ea2765cc17cb8aa7e7544a4b6dcb05b6ed77
- https://git.kernel.org/stable/c/bd08bb7443c501d2f2a71d529e4afcf11c9b07d2
- https://git.kernel.org/stable/c/dce85215a6c7b0fd753f577a4c487f647119884c