Executive brief
A vulnerability was identified in the Linux kernel's Near Field Communication (NFC) component. This flaw could allow a local attacker to cause a system crash or potentially execute unauthorized code due to improper memory management when closing certain network sockets. This affects systems using NFC functionality, potentially impacting device stability and security.
Technical details
A use-after-free (UAF) vulnerability exists in net/nfc/llcp_sock.c within the llcp_sock_release() function. The root cause is that the function unconditionally unlinks sockets from the local sockets list, even if the socket is currently in the LLCP_CONNECTING state and resides on the connecting_sockets list. This mismatch leads to memory corruption or use-after-free scenarios. A local attacker can trigger this by initiating and then quickly releasing a non-blocking NFC LLCP connection. Patches have been released across multiple Linux stable branches (e.g., 5.10.y, 5.15.y, 6.x) to ensure the socket is unlinked from the correct list based on its state.
Affected products
- Linux Linux 3.11 to 5.10.259, 5.15.210, and other stable branches
Timeline
- 2026-07-19: disclosed: CVE published by NVD
- 2026-04-29: patched: Initial fix authored by Lee Jones
References
- https://git.kernel.org/stable/c/2dfdaaf7d933b676124aadec6698825e95f94fe9
- https://git.kernel.org/stable/c/89ba026747019ee643d29407435ddc118e6ca908
- https://git.kernel.org/stable/c/912ebc49d4406a17fe73e5671d674fbc2f6b2634
- https://git.kernel.org/stable/c/bc421d0826dedbba37580a25405eafb599e76d42
- https://git.kernel.org/stable/c/cdc17e09a636c7f936f771902535a7515a7608fc
- https://git.kernel.org/stable/c/e00f50f8697724a6f1d2d35744c1332c9912dac5
- https://git.kernel.org/stable/c/f4268b466190dae95a7585f69b4f1f8ad097632c