CVE-2026-90225

Summary

In the Linux kernel, the following vulnerability has been resolved:

nfc: llcp: read llcp_sock->local under the socket lock in getsockopt

nfc_llcp_getsockopt() read llcp_sock->local before lock_sock(sk) and then dereferenced the cached pointer inside the locked region. llcp_sock_bind() assigns and clears llcp_sock->local under the same socket lock, dropping the last reference on its error path. A getsockopt() racing an in-flight bind() can observe the pointer, block on lock_sock(), and then dereference a freed nfc_llcp_local once bind() has unwound.

Move the llcp_sock->local read and the NULL check inside the lock_sock(sk) region so bind() cannot mutate or free the pointer between the load and the use.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < 56fd158fef20268f48db6cdfe5d722e930134edaaffected
LinuxLinux26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < 8ba8cec0586727cc135ca4827921fc7b52946d71affected
LinuxLinux26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < ed5240bab3468988077fe8bf29b935eaecc9ff89affected
LinuxLinux26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < fe65727a4a21b11c18eebae1338482767a897b76affected
LinuxLinux26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < 2d8ac24565be85bf56580b87bf1b874d35625eb5affected
LinuxLinux26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < 156e65bd29307f5053835bff60bc1ba342fa010faffected
LinuxLinux26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < d1b73962675cdc5a58e2707e25b548d8b495fde0affected
LinuxLinux26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < 36812527052c5bfb1ec6c1e292d67a5bf76b750faffected
LinuxLinux3.10affected
LinuxLinux0 < 3.10unaffected
LinuxLinux5.10.270 <= 5.10.*unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References