CVE-2026-64010

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
20/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()<br /> <br /> A race condition exists in the NFC LLCP connection state machine where<br /> the connection acceptance packet (CC) can be processed concurrently with<br /> socket release. This can lead to a use-after-free of the socket object.<br /> <br /> When nfc_llcp_recv_cc() moves the socket from the connecting_sockets<br /> list to the sockets list, it does so without holding the socket lock.<br /> If llcp_sock_release() is executing concurrently, it might have already<br /> unlinked the socket and dropped its references, which can result in<br /> nfc_llcp_recv_cc() linking a freed socket into the live list.<br /> <br /> Fix this by holding lock_sock() during the state transition and list<br /> movement in nfc_llcp_recv_cc(). After acquiring the lock, check if<br /> the socket is still hashed to ensure it hasn&amp;#39;t already been unlinked<br /> and marked for destruction by the release path. This aligns the locking<br /> pattern with recv_hdlc() and recv_disc().