Description
In the Linux kernel, the following vulnerability has been resolved:

nfc: nci: fix double completion race in nci_data_exchange_complete

nci_close_device() and nci_rx_work can both call
nci_data_exchange_complete() concurrently. After commit 4527025d440ce8
("nfc: nci: fix circular locking dependency in nci_close_device") moved
flush_workqueue(ndev->rx_wq) after mutex_unlock(&ndev->req_lock),
rx_work is no longer serialized with the explicit completion call in the
close path. Both callers read the non-NULL callback pointer and invoke
rawsock_data_exchange_complete(), which calls sock_put() -- but only one
sock_hold() was taken, so the second sock_put() underflows the refcount
and frees the socket while it is still in use.

Replace the bare clear_bit(NCI_DATA_EXCHANGE) with
test_and_clear_bit() so that only the first caller proceeds to invoke
the callback.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash due to socket reference underflow
Action: Patch ASAP
AI Analysis

Impact

This vulnerability arises when the NFC NCI path in the Linux kernel experiences a double completion race between nci_close_device() and nci_rx_work. The race causes the completion callback to be invoked twice, decrementing the socket reference count an extra time and freeing the socket while it remains in use. The double decrement can lead to an underflow and a kernel crash, potentially allowing a local attacker to cause a denial of service or influence subsequent memory usage.

Affected Systems

All Linux kernel releases that include the NFC NCI subsystem are affected until the fix is applied. The problem is not tied to a particular kernel version number but to the presence of the legacy nci_data_exchange_complete implementation.

Risk and Exploitability

The CVSS score of 7.5 indicates a high-level vulnerability. The EPSS score of less than 1 % suggests that active exploitation is currently unlikely. Because the flaw requires concurrent execution of nci_close_device() and nci_rx_work, the attack is limited to an environment where the attacker can trigger NFC operations or affect the NFC device state. The lack of a listing in the CISA KEV catalog further indicates that no widespread exploitation has been reported yet. Nonetheless, an attacker who can influence NFC traffic locally could trigger a crash and cause a denial of service.

Generated by OpenCVE AI on September 19, 2026 at 15:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the 4527025d440ce8 commit, which replaces the double completion with a test_and_clear_bit guard.
  • If a kernel upgrade is not immediately possible, disable the NFC NCI kernel module or turn off NFC hardware to eliminate the race condition from the running system.
  • Continuously monitor system logs for NFC‑related panics or crashes that may indicate regression or unpatched instances.

Generated by OpenCVE AI on September 19, 2026 at 15:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix double completion race in nci_data_exchange_complete nci_close_device() and nci_rx_work can both call nci_data_exchange_complete() concurrently. After commit 4527025d440ce8 ("nfc: nci: fix circular locking dependency in nci_close_device") moved flush_workqueue(ndev->rx_wq) after mutex_unlock(&ndev->req_lock), rx_work is no longer serialized with the explicit completion call in the close path. Both callers read the non-NULL callback pointer and invoke rawsock_data_exchange_complete(), which calls sock_put() -- but only one sock_hold() was taken, so the second sock_put() underflows the refcount and frees the socket while it is still in use. Replace the bare clear_bit(NCI_DATA_EXCHANGE) with test_and_clear_bit() so that only the first caller proceeds to invoke the callback.
Title nfc: nci: fix double completion race in nci_data_exchange_complete
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:51.131Z

Reserved: 2026-09-11T19:38:34.794Z

Link: CVE-2026-90224

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:17.997

Modified: 2026-09-18T18:17:47.140

Link: CVE-2026-90224

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:30:06Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')