Impact
The Linux kernel NFC pn533 driver contains a race condition that can cause a socket buffer (skb) to be freed while still in use by the transport layer. This premature release leads to a use‑after‑free error, potentially allowing an attacker with control over the NFC device to corrupt memory, crash the kernel, or gain elevated privileges.
Affected Systems
All Linux kernel builds that include the pn533 NFC driver before the applied fix are affected. The issue was resolved in a commit that added a temporary reference to the request skb during send_frame. Systems running kernel versions that have not incorporated this change are vulnerable; the specific affected version list was not provided, so any installation containing the default533 driver prior to the patch should be considered at risk.
Risk and Exploitability
The EPSS score is reported as <1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation probability in the wild. The nature of the flaw requires an attacker to interact with the physical NFC device, which limits the likelihood of remote exploitation. However, because the flaw can induce a kernel crash or privilege escalation, it should be regarded as a moderate risk when the device is present and exposed to potential attacker control.
OpenCVE Enrichment
Debian DLA
Debian DSA