SB20260424212 - Improper locking in Linux kernel nfc nci
Published: April 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper locking (CVE-ID: CVE-2026-31509)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an improper lock handling issue in nci_close_device when flushing rx_wq and tx_wq while holding req_lock. A local user can trigger the vulnerable code path to cause a denial of service.
The issue can result in a circular locking dependency and has been observed during execution of the nci selftest on debug kernels.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/09143c0e8f3b03517e6233aad42f45c794d8df8e
- https://git.kernel.org/stable/c/1edc12d2bbcb7a8d0f1088e6fccb9d8c01bb1289
- https://git.kernel.org/stable/c/4527025d440ce84bf56e75ce1df2e84cb8178616
- https://git.kernel.org/stable/c/5eef9ebec7f5738f12cadede3545c05b34bf5ac3
- https://git.kernel.org/stable/c/7ed00a3edc8597fe2333f524401e2889aa1b5edf
- https://git.kernel.org/stable/c/ca54e904a071aa65ef3ad46ba42d51aaac6b73b4
- https://git.kernel.org/stable/c/d89b74bf08f067b55c03d7f999ba0a0e73177eb3
- https://git.kernel.org/stable/c/eb435d150ca74b4d40f77f1a2266f3636ed64a79