{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-31629","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-03-09T15:48:24.124Z","datePublished":"2026-04-24T14:42:49.849Z","dateUpdated":"2026-08-05T12:23:55.426Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:23:55.426Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: add missing return after LLCP_CLOSED checks\n\nIn nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket\nstate is LLCP_CLOSED, the code correctly calls release_sock() and\nnfc_llcp_sock_put() but fails to return. Execution falls through to\nthe remainder of the function, which calls release_sock() and\nnfc_llcp_sock_put() again. This results in a double release_sock()\nand a refcount underflow via double nfc_llcp_sock_put(), leading to\na use-after-free.\n\nAdd the missing return statements after the LLCP_CLOSED branches\nin both functions to prevent the fall-through."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The vulnerable LLCP receive handlers process NFC DEP/LLCP PDUs supplied by a nearby NFC peer over the NFC radio link. The attacker must be in NFC range, so this is adjacent rather than local or internet-routable network access.\nAC:L - The attacker can drive the required LLCP packet sequence, for example closing a matched LLCP socket with a remote control PDU and then sending DISC or I/RR/RNR for the same SAP pair. No uncontrollable race or special memory layout condition is required to trigger the double put/unlock path.\nPR:N - The triggering input is unauthenticated NFC LLCP traffic from the peer and does not require an account or privileges on the victim. Any local NFC setup or listening service is an environmental prerequisite, not a privilege held by the attacker.\nUI:N - After the victim NFC subsystem/link is active and the attacker is in range, malicious LLCP frames are processed by the kernel receive path without further victim action. Proximity is already captured by AV:A.\nS:U - The vulnerability corrupts kernel socket lifetime state within the same kernel security authority. It does not cross a VM, hypervisor, IOMMU, or separate authorization boundary.\nC:H - The bug causes a refcount imbalance and use-after-free of an NFC LLCP socket object. Kernel UAFs are defensibly treated as enabling memory disclosure primitives under the required high-severity guidance.\nI:H - The freed socket object can potentially be reclaimed and controlled, turning the UAF into kernel memory corruption or control-flow/data-structure modification. Under the required guidance, UAF impact is high for integrity.\nA:H - The double release and double sock_put can produce refcount underflow, use-after-free, warnings, oopses, or crashes in kernel socket handling. A kernel crash or panic is high availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/nfc/llcp_core.c"],"versions":[{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"b2a23529593d011fb433a3d711fc597ed6a6bd2f","status":"affected","versionType":"git"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"665315df9c3486cb213fc44d83cc8bcd47fe0d26","status":"affected","versionType":"git"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"9b49e2a4b8219a2fc5cebf94f4ec34e509aff8a6","status":"affected","versionType":"git"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"0eb1263a3b8c36418c9ba295c9ab3abed664edbf","status":"affected","versionType":"git"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"796e0cac058252d0ad34ebe288e6f7979b5fc9b2","status":"affected","versionType":"git"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"8977fad2b3c6eefd414131168d597c5d1d5e1abf","status":"affected","versionType":"git"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"ff3d9e8f7244293e303f7b6ef70774291c7c27e9","status":"affected","versionType":"git"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"aba4712e8f0381cd5d196534ce2ad082626a5ab6","status":"affected","versionType":"git"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"2b5dd4632966c39da6ba74dbc8689b309065e82c","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/nfc/llcp_core.c"],"versions":[{"version":"3.3","status":"affected"},{"version":"0","lessThan":"3.3","status":"unaffected","versionType":"semver"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.136","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.83","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.24","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"6.19.14","lessThanOrEqual":"6.19.*","status":"unaffected","versionType":"semver"},{"version":"7.0.1","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3","versionEndExcluding":"5.10.258"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3","versionEndExcluding":"5.15.209"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3","versionEndExcluding":"6.1.175"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3","versionEndExcluding":"6.6.136"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3","versionEndExcluding":"6.12.83"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3","versionEndExcluding":"6.18.24"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3","versionEndExcluding":"6.19.14"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3","versionEndExcluding":"7.0.1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b2a23529593d011fb433a3d711fc597ed6a6bd2f"},{"url":"https://git.kernel.org/stable/c/665315df9c3486cb213fc44d83cc8bcd47fe0d26"},{"url":"https://git.kernel.org/stable/c/9b49e2a4b8219a2fc5cebf94f4ec34e509aff8a6"},{"url":"https://git.kernel.org/stable/c/0eb1263a3b8c36418c9ba295c9ab3abed664edbf"},{"url":"https://git.kernel.org/stable/c/796e0cac058252d0ad34ebe288e6f7979b5fc9b2"},{"url":"https://git.kernel.org/stable/c/8977fad2b3c6eefd414131168d597c5d1d5e1abf"},{"url":"https://git.kernel.org/stable/c/ff3d9e8f7244293e303f7b6ef70774291c7c27e9"},{"url":"https://git.kernel.org/stable/c/aba4712e8f0381cd5d196534ce2ad082626a5ab6"},{"url":"https://git.kernel.org/stable/c/2b5dd4632966c39da6ba74dbc8689b309065e82c"}],"title":"nfc: llcp: add missing return after LLCP_CLOSED checks","x_generator":{"engine":"bippy-1.2.0"}}}}