Description
In the Linux kernel, the following vulnerability has been resolved:

nfc: pn533: hold a reference to the request skb during send_frame

__pn533_send_async() publishes the command and then calls
dev->phy_ops->send_frame(). Once dev->cmd is set, an incoming frame
can be matched to this command: the I2C threaded IRQ runs
pn533_recv_frame(), which queues cmd_complete_work, and
pn533_send_async_complete() frees cmd->req with consume_skb().

On the I2C transport, pn533_i2c_send_frame() still dereferences the same
skb after i2c_master_send() returns, so a completion that races the
send can free the skb while the transport is still using it.

The request skb is owned by the command object and may be freed by
command completion at any time after dev->cmd is published, so the
transport send path must not assume it stays alive. Hold a temporary
reference to the request skb across the send_frame() call so the
transport always sees a live skb even if completion races the send.
Add a pn533_send_cmd_frame() helper and use it from all three send
paths.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free
Action: Apply Patch
AI Analysis

Impact

The Linux kernel NFC pn533 driver contains a race condition that can cause a socket buffer (skb) to be freed while still in use by the transport layer. This premature release leads to a use‑after‑free error, potentially allowing an attacker with control over the NFC device to corrupt memory, crash the kernel, or gain elevated privileges.

Affected Systems

All Linux kernel builds that include the pn533 NFC driver before the applied fix are affected. The issue was resolved in a commit that added a temporary reference to the request skb during send_frame. Systems running kernel versions that have not incorporated this change are vulnerable; the specific affected version list was not provided, so any installation containing the default533 driver prior to the patch should be considered at risk.

Risk and Exploitability

The EPSS score is reported as <1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation probability in the wild. The nature of the flaw requires an attacker to interact with the physical NFC device, which limits the likelihood of remote exploitation. However, because the flaw can induce a kernel crash or privilege escalation, it should be regarded as a moderate risk when the device is present and exposed to potential attacker control.

Generated by OpenCVE AI on September 19, 2026 at 03:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the pn533_send_cmd_frame fix
  • If the NFC pn533 functionality is not required, disable or remove the driver to eliminate the attack surface
  • Restrict physical access to the NFC hardware to prevent unauthorized users from interacting with the device

Generated by OpenCVE AI on September 19, 2026 at 03:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: hold a reference to the request skb during send_frame __pn533_send_async() publishes the command and then calls dev->phy_ops->send_frame(). Once dev->cmd is set, an incoming frame can be matched to this command: the I2C threaded IRQ runs pn533_recv_frame(), which queues cmd_complete_work, and pn533_send_async_complete() frees cmd->req with consume_skb(). On the I2C transport, pn533_i2c_send_frame() still dereferences the same skb after i2c_master_send() returns, so a completion that races the send can free the skb while the transport is still using it. The request skb is owned by the command object and may be freed by command completion at any time after dev->cmd is published, so the transport send path must not assume it stays alive. Hold a temporary reference to the request skb across the send_frame() call so the transport always sees a live skb even if completion races the send. Add a pn533_send_cmd_frame() helper and use it from all three send paths.
Title nfc: pn533: hold a reference to the request skb during send_frame
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:32.717Z

Reserved: 2026-09-11T19:38:34.794Z

Link: CVE-2026-90222

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:17.687

Modified: 2026-09-17T17:17:17.687

Link: CVE-2026-90222

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T04:00:07Z

Weaknesses

No weakness.