Impact
This vulnerability arises when the NFC NCI path in the Linux kernel experiences a double completion race between nci_close_device() and nci_rx_work. The race causes the completion callback to be invoked twice, decrementing the socket reference count an extra time and freeing the socket while it remains in use. The double decrement can lead to an underflow and a kernel crash, potentially allowing a local attacker to cause a denial of service or influence subsequent memory usage.
Affected Systems
All Linux kernel releases that include the NFC NCI subsystem are affected until the fix is applied. The problem is not tied to a particular kernel version number but to the presence of the legacy nci_data_exchange_complete implementation.
Risk and Exploitability
The CVSS score of 7.5 indicates a high-level vulnerability. The EPSS score of less than 1 % suggests that active exploitation is currently unlikely. Because the flaw requires concurrent execution of nci_close_device() and nci_rx_work, the attack is limited to an environment where the attacker can trigger NFC operations or affect the NFC device state. The lack of a listing in the CISA KEV catalog further indicates that no widespread exploitation has been reported yet. Nonetheless, an attacker who can influence NFC traffic locally could trigger a crash and cause a denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA