{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90224","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.794Z","datePublished":"2026-09-17T16:07:34.009Z","dateUpdated":"2026-09-18T17:53:51.131Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:53:51.131Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: fix double completion race in nci_data_exchange_complete\n\nnci_close_device() and nci_rx_work can both call\nnci_data_exchange_complete() concurrently.  After commit 4527025d440ce8\n(\"nfc: nci: fix circular locking dependency in nci_close_device\") moved\nflush_workqueue(ndev->rx_wq) after mutex_unlock(&ndev->req_lock),\nrx_work is no longer serialized with the explicit completion call in the\nclose path.  Both callers read the non-NULL callback pointer and invoke\nrawsock_data_exchange_complete(), which calls sock_put() -- but only one\nsock_hold() was taken, so the second sock_put() underflows the refcount\nand frees the socket while it is still in use.\n\nReplace the bare clear_bit(NCI_DATA_EXCHANGE) with\ntest_and_clear_bit() so that only the first caller proceeds to invoke\nthe callback."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - One completion is nci_rx_work() handling an NCI_MT_DATA_PKT (nci_rx_data_packet()→nci_add_rx_data_frag()→nci_data_exchange_complete()), with that skb queued by nci_recv_frame() from the NFC controller as NFC RF traffic; NFC radio range is Adjacent, not a routable IP transport.\nAC:H - The bug is nci_close_device() and nci_rx_work() both invoking nci_data_exchange_complete() after flush_workqueue(ndev->rx_wq) moved past mutex_unlock(&ndev->req_lock). An NFC peer can drive rx_work but cannot start that close: nfc_dev_down() returns -EBUSY while active_target is set, and nci_unregister_device() is driver teardown the peer cannot initiate.\nPR:N - nci_recv_frame()→nci_rx_work() processes NCI frames with no capability or authentication check, so an in-range NFC peer needs no host account. GENL_ADMIN_PERM on nfc_genl_dev_down()/NFC_CMD_DEV_DOWN is only the victim-side close gate, not a privilege the adjacent attacker must hold.\nUI:N - With NFC already up and nci_transceive() having set NCI_DATA_EXCHANGE (normal for a polling reader or in-progress tag session), the peer's DATA packet completes via nci_rx_work with no further click, mount, or prompt; concurrent nci_close_device() is an AC condition, not a required victim action.\nS:U - The extra sock_put() in rawsock_data_exchange_complete() frees a host kernel struct sock; impact stays in the same kernel authority with no VM escape, IOMMU bypass, or sandbox crossing.\nC:H - nci_close_device() and nci_rx_work() both read conn_info->data_exchange_cb and call rawsock_data_exchange_complete(), which sock_put()s the sk held once by sock_hold() in rawsock_tx_work(); the second put underflows that refcount and frees the socket while still referenced, a UAF read primitive.\nI:H - The same double sock_put() of the PF_NFC SOCK_SEQPACKET socket is a kernel UAF on struct sock, and the second callback runs against that freed object, giving a heap write/control-flow hijack primitive.\nA:H - Refcount underflow and the second rawsock_data_exchange_complete() on the already-freed sk (or __sk_destruct racing the second put, the path that also hit nci_close_device lockdep) cause a kernel oops or panic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/nfc/nci/data.c"],"versions":[{"version":"7ed00a3edc8597fe2333f524401e2889aa1b5edf","lessThan":"3f075832734005310740d148d1cf1c1e792ebdca","status":"affected","versionType":"git"},{"version":"5eef9ebec7f5738f12cadede3545c05b34bf5ac3","lessThan":"588ccd19a6e69eca72d54608c3ab3b45709b2305","status":"affected","versionType":"git"},{"version":"ca54e904a071aa65ef3ad46ba42d51aaac6b73b4","lessThan":"cf646a9f5554bc07d6ccb59c327812b3a0c6a368","status":"affected","versionType":"git"},{"version":"eb435d150ca74b4d40f77f1a2266f3636ed64a79","lessThan":"9030a1bbe2c6b1e3e54cef462d159b5248f09fd2","status":"affected","versionType":"git"},{"version":"1edc12d2bbcb7a8d0f1088e6fccb9d8c01bb1289","lessThan":"bfdf412208fea7fc0d5b32d68a35b25261917393","status":"affected","versionType":"git"},{"version":"d89b74bf08f067b55c03d7f999ba0a0e73177eb3","lessThan":"ba4c776af3dc21ed04e315e6545e99703bb1b53a","status":"affected","versionType":"git"},{"version":"4527025d440ce84bf56e75ce1df2e84cb8178616","lessThan":"ee08414d78b851e3d1856d6e4d631939b01a1bbe","status":"affected","versionType":"git"},{"version":"4527025d440ce84bf56e75ce1df2e84cb8178616","lessThan":"8265a626cc14a48e46e6dc8c47667e72b4232ac2","status":"affected","versionType":"git"},{"version":"09143c0e8f3b03517e6233aad42f45c794d8df8e","status":"affected","versionType":"git"},{"version":"5.10.253","lessThan":"5.10.270","status":"affected","versionType":"semver"},{"version":"5.15.203","lessThan":"5.15.221","status":"affected","versionType":"semver"},{"version":"6.1.168","lessThan":"6.1.188","status":"affected","versionType":"semver"},{"version":"6.6.131","lessThan":"6.6.157","status":"affected","versionType":"semver"},{"version":"6.12.80","lessThan":"6.12.110","status":"affected","versionType":"semver"},{"version":"6.18.21","lessThan":"6.18.52","status":"affected","versionType":"semver"},{"version":"6.19.11","lessThan":"6.20","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/nfc/nci/data.c"],"versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.253","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.203","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.168","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.131","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.80","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18.21","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19.11"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3f075832734005310740d148d1cf1c1e792ebdca"},{"url":"https://git.kernel.org/stable/c/588ccd19a6e69eca72d54608c3ab3b45709b2305"},{"url":"https://git.kernel.org/stable/c/cf646a9f5554bc07d6ccb59c327812b3a0c6a368"},{"url":"https://git.kernel.org/stable/c/9030a1bbe2c6b1e3e54cef462d159b5248f09fd2"},{"url":"https://git.kernel.org/stable/c/bfdf412208fea7fc0d5b32d68a35b25261917393"},{"url":"https://git.kernel.org/stable/c/ba4c776af3dc21ed04e315e6545e99703bb1b53a"},{"url":"https://git.kernel.org/stable/c/ee08414d78b851e3d1856d6e4d631939b01a1bbe"},{"url":"https://git.kernel.org/stable/c/8265a626cc14a48e46e6dc8c47667e72b4232ac2"}],"title":"nfc: nci: fix double completion race in nci_data_exchange_complete","x_generator":{"engine":"bippy-1.2.0"}}}}