SB20260720228 - Use-after-free in Linux kernel nfc
Published: July 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-64010)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free race condition in nfc_llcp_recv_cc() when processing an NFC LLCP connection acceptance packet concurrently with socket release. A local user can trigger concurrent connection handling and socket release to cause a denial of service.
The issue occurs during a connection state transition when a socket can be moved from the connecting_sockets list to the sockets list after it has already been unlinked and marked for destruction.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0b45c31746e1523d5d482fda8fcf54a35ac417f1
- https://git.kernel.org/stable/c/650bdd8fdfab64a09ee474150313dbc48c374795
- https://git.kernel.org/stable/c/ad8a27d63cac96bac441edd002209ebd996e12fb
- https://git.kernel.org/stable/c/b2a60f7f846faaf5c2cdad4ea6d3a33e5f863183
- https://git.kernel.org/stable/c/b493ea2765cc17cb8aa7e7544a4b6dcb05b6ed77
- https://git.kernel.org/stable/c/bd08bb7443c501d2f2a71d529e4afcf11c9b07d2
- https://git.kernel.org/stable/c/dce85215a6c7b0fd753f577a4c487f647119884c
- https://git.kernel.org/stable/c/ee2d1a8a1833c5e56e9a1745e64b0b4edda732c2