PT-2026-94572 · Linux · Linux Kernel
CVE-2026-90224
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.5
High
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A race condition exists in the NFC NCI subsystem where
nci close device() and nci rx work can concurrently call the nci data exchange complete() function. This occurs because rx work is no longer serialized with the completion call in the close path. Consequently, both callers may invoke rawsock data exchange complete(), leading to multiple calls of sock put(). Since only one sock hold() was performed, the second sock put() causes a reference count underflow, resulting in the socket being freed while still in use.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel