Impact
The Linux kernel’s NFC LLCP socket implementation performs a getsockopt on the socket before acquiring the socket lock. In that window, llcp_sock_bind may free the llcp_sock->local object. A race between getsockopt and bind can therefore cause a use‑after‑free, allowing an attacker to execute arbitrary code or trigger a denial of service. The vulnerability arises from improper synchronization and the dereferencing of a stale pointer.
Affected Systems
This flaw affects the NFC LLCP component of the Linux kernel. No specific kernel versions are named in the advisory, so any kernel build that contains the unpatched code is susceptible until the fix is applied.
Risk and Exploitability
The CVSS score of 7.8 classifies this as a high‑severity flaw, while the EPSS score of less than 1 % indicates a low but non‑zero probability of exploitation. The flaw is not listed in the CISA KEV catalog. The attack vector is local; an adversary must be able to open an NFC LLCP socket and race getsockopt with a bind operation, which requires significant technical skill and kernel‑level access.
OpenCVE Enrichment
Debian DLA
Debian DSA