CVE-2026-90224
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-90224, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-17
Last updated on: 2026-09-18
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
nfc: nci: fix double completion race in nci_data_exchange_complete
nci_close_device() and nci_rx_work can both call
nci_data_exchange_complete() concurrently. After commit 4527025d440ce8
("nfc: nci: fix circular locking dependency in nci_close_device") moved
flush_workqueue(ndev->rx_wq) after mutex_unlock(&ndev->req_lock),
rx_work is no longer serialized with the explicit completion call in the
close path. Both callers read the non-NULL callback pointer and invoke
rawsock_data_exchange_complete(), which calls sock_put() -- but only one
sock_hold() was taken, so the second sock_put() underflows the refcount
and frees the socket while it is still in use.
Replace the bare clear_bit(NCI_DATA_EXCHANGE) with
test_and_clear_bit() so that only the first caller proceeds to invoke
the callback.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 7ed00a3edc8597fe2333f524401e2889aa1b5edf |
| Linux | Linux | 5eef9ebec7f5738f12cadede3545c05b34bf5ac3 |
| Linux | Linux | ca54e904a071aa65ef3ad46ba42d51aaac6b73b4 |
| Linux | Linux | eb435d150ca74b4d40f77f1a2266f3636ed64a79 |
| Linux | Linux | 1edc12d2bbcb7a8d0f1088e6fccb9d8c01bb1289 |
| Linux | Linux | d89b74bf08f067b55c03d7f999ba0a0e73177eb3 |
| Linux | Linux | 4527025d440ce84bf56e75ce1df2e84cb8178616 |
| Linux | Linux | 4527025d440ce84bf56e75ce1df2e84cb8178616 |
| Linux | Linux | 09143c0e8f3b03517e6233aad42f45c794d8df8e |
| Linux | Linux | 5.10.253 |
| Linux | Linux | 5.15.203 |
| Linux | Linux | 6.1.168 |
| Linux | Linux | 6.6.131 |
| Linux | Linux | 6.12.80 |
| Linux | Linux | 6.18.21 |
| Linux | Linux | 6.19.11 |
| Linux | Linux | 7.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |