CVE-2026-23330

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/03/2026
Last modified:
27/04/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfc: nci: complete pending data exchange on device close<br /> <br /> In nci_close_device(), complete any pending data exchange before<br /> closing. The data exchange callback (e.g.<br /> rawsock_data_exchange_complete) holds a socket reference.<br /> <br /> NIPA occasionally hits this leak:<br /> <br /> unreferenced object 0xff1100000f435000 (size 2048):<br /> comm "nci_dev", pid 3954, jiffies 4295441245<br /> hex dump (first 32 bytes):<br /> 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................<br /> 27 00 01 40 00 00 00 00 00 00 00 00 00 00 00 00 &amp;#39;..@............<br /> backtrace (crc ec2b3c5):<br /> __kmalloc_noprof+0x4db/0x730<br /> sk_prot_alloc.isra.0+0xe4/0x1d0<br /> sk_alloc+0x36/0x760<br /> rawsock_create+0xd1/0x540<br /> nfc_sock_create+0x11f/0x280<br /> __sock_create+0x22d/0x630<br /> __sys_socket+0x115/0x1d0<br /> __x64_sys_socket+0x72/0xd0<br /> do_syscall_64+0x117/0xfc0<br /> entry_SYSCALL_64_after_hwframe+0x4b/0x53

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 3.2.1 (including) 6.12.82 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.17 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 6.19.7 (excluding)
cpe:2.3:o:linux:linux_kernel:3.2:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*