Description
In the Linux kernel, the following vulnerability has been resolved:

nfc: llcp: read llcp_sock->local under the socket lock in getsockopt

nfc_llcp_getsockopt() read llcp_sock->local before lock_sock(sk) and
then dereferenced the cached pointer inside the locked region.
llcp_sock_bind() assigns and clears llcp_sock->local under the same
socket lock, dropping the last reference on its error path. A
getsockopt() racing an in-flight bind() can observe the pointer, block
on lock_sock(), and then dereference a freed nfc_llcp_local once bind()
has unwound.

Move the llcp_sock->local read and the NULL check inside the
lock_sock(sk) region so bind() cannot mutate or free the pointer between
the load and the use.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free Exploit
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel’s NFC LLCP socket implementation performs a getsockopt on the socket before acquiring the socket lock. In that window, llcp_sock_bind may free the llcp_sock->local object. A race between getsockopt and bind can therefore cause a use‑after‑free, allowing an attacker to execute arbitrary code or trigger a denial of service. The vulnerability arises from improper synchronization and the dereferencing of a stale pointer.

Affected Systems

This flaw affects the NFC LLCP component of the Linux kernel. No specific kernel versions are named in the advisory, so any kernel build that contains the unpatched code is susceptible until the fix is applied.

Risk and Exploitability

The CVSS score of 7.8 classifies this as a high‑severity flaw, while the EPSS score of less than 1 % indicates a low but non‑zero probability of exploitation. The flaw is not listed in the CISA KEV catalog. The attack vector is local; an adversary must be able to open an NFC LLCP socket and race getsockopt with a bind operation, which requires significant technical skill and kernel‑level access.

Generated by OpenCVE AI on September 20, 2026 at 02:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the commit correcting the race condition.
  • If an immediate kernel update is not possible, disable the NFC LLCP socket feature, for example by removing or blacklisting the nfc_llcp module or configuring policies that block getsockopt on NFC sockets.
  • Limit privileged users or applications from performing getsockopt on NFC sockets until the kernel is patched.

Generated by OpenCVE AI on September 20, 2026 at 02:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Sat, 19 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: read llcp_sock->local under the socket lock in getsockopt nfc_llcp_getsockopt() read llcp_sock->local before lock_sock(sk) and then dereferenced the cached pointer inside the locked region. llcp_sock_bind() assigns and clears llcp_sock->local under the same socket lock, dropping the last reference on its error path. A getsockopt() racing an in-flight bind() can observe the pointer, block on lock_sock(), and then dereference a freed nfc_llcp_local once bind() has unwound. Move the llcp_sock->local read and the NULL check inside the lock_sock(sk) region so bind() cannot mutate or free the pointer between the load and the use.
Title nfc: llcp: read llcp_sock->local under the socket lock in getsockopt
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:52.374Z

Reserved: 2026-09-11T19:38:34.794Z

Link: CVE-2026-90225

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:18.133

Modified: 2026-09-18T18:17:47.320

Link: CVE-2026-90225

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:45:18Z

Weaknesses

No weakness.