Junglewise Threat Intelligence

CVE-2026-64010: Linux Kernel use-after-free in nfc_llcp_recv_cc

CVE-2026-64010 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Near Field Communication (NFC) component. A race condition in how the system handles NFC connections could allow a local attacker to cause a system crash or potentially execute unauthorized code by exploiting a 'use-after-free' memory error. This occurs when the system attempts to use a network socket that has already been closed and cleared from memory.

Technical details

A race condition exists in the NFC LLCP connection state machine within net/nfc/llcp_core.c. Specifically, the function nfc_llcp_recv_cc() moves a socket from the connecting_sockets list to the sockets list without holding the required socket lock. If llcp_sock_release() is executed concurrently, it may unlink the socket and drop its references before nfc_llcp_recv_cc() completes its transition, resulting in a use-after-free (UAF) when the freed socket is linked back into the live list. The fix involves implementing lock_sock() during the state transition and verifying the socket is still hashed (sk_hashed) before proceeding. This vulnerability requires local access to the NFC subsystem.

Affected products

  • Linux Linux a69f32af86e389dd232b1bb2269e202c1bfcc60f

Timeline

  • 2026-04-29: other: Patch authored
  • 2026-07-19: disclosed: CVE published

References